Archive for the ‘Wireless Security’ Category

Don’t bank over public WiFi.

March 31st, 2008

It’s pretty simple, isn’t it?

Too many times I’ve seen people who connect to their local hot spot, at the coffee shop, log into their bank, and conduct important personal business.

Now, don’t get me wrong, I’m all for the convenience of ubiquitous wireless internet access. I think that there’s nothing quite as cool as looking something up in google while sipping on my grande-latté-2-pumps-of-vanilla, but online banking credentials have a definite value in the eyes of unscrupulous criminals, and when they are flying through the air, anyone with the necessary knowledge can snatch them.
Admittedly, my paranoia knob “security dial” is set pretty high. Perhaps this is as a direct result of working in the security field. Let me elaborate and provide a concrete example in the process. A common ploy, one that is not that technically difficult to achieve, is to sit at a location that has public wireless access with a laptop that has been configured to act as a wireless router, and relay the traffic to the legitimate wireless router. This is often referred as a rogue access point.

Say for example that this location is a coffee shop. In this fictitious example, we’ll call the wireless router: Coffee_Free. The malicious criminal would then create a Coffee_free2 router, and simply wait for unsuspecting patrons of the coffee shop to connect to his laptop. He would then intercept all their traffic. Once you have intercepted the traffic generated during a banking transaction, you can dissect it at your leisure, and extract the information needed to acquire said banking credentials. The rogue access point is even more effective if the wifi web access at the coffee shop is a paid service, as the rogue access is free, and will probably attract more patrons than the legitimate one!

rogue access point

Remember, this method of stealing credentials applies for any web based exchange that involves some form of authentication. Is your favorite instant messenger automatically logging you on? Your credentials are involved in that process. Checking you g-mail? That information is intercepted too…

 

On the subject of e-mail credentials, don’t think that just because it’s a web based email, it does not hold value to criminals. If they own your email, they can get access to any other services where you used that email address to register. The g-mail search features makes finding this information even easier. Users also have the bad habit of using the same password for several different services. A skillful attacker will attempt logging in other services using the same credentials in a bid to gain further information. We have even seen black hat tools in the wild that help automate this process…

 

So what should the average user take from this? Don’t bank over public WiFi.

 

There’s no point in looking for a dodgy looking fellow with a “got root” t-shirt, rubbing his hands together with glee at the very far end of the coffee shop either. His laptop is in his car, in the trunk It’s parked besides the coffee shop, and he’s gone shopping. Possibly with your money.

 

Don’t bank over public WiFi.

  • Posted in Wireless Security
  • |
  • (0) comments
  • |
  • Add your comments




Location

You are currently browsing the archives for the Wireless Security category.




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.