Latest Comments
"They should be hanged"
by surya | Oct 12, 2008 1:34 AM
 
"Democratic Representative Mike Kernell’s son, David Kernell, was caught by authorities. ..."
by Payday Loan Advocate | Oct 11, 2008 7:41 PM
 
"It sounds very good if it lives up to the statements"
by John Williams | Oct 11, 2008 11:57 AM
 
"Any good log system is going to be modular (separate from the web site itself), and more than ..."
by Russ | Oct 9, 2008 7:21 PM
 
"Good"
by Francis Ayitey | Oct 6, 2008 10:48 AM

Black Hat Conf: New tools found for wi-fi hacking

  • Email a Friend
  • Print Page
Black Hat Conf: New tools found for wi-fi hacking
By Fiona Raisbeck
Aug 6, 2007 10:02 AM
Tags: Black | Hat | Conf: | New | tools | found | for | wi-fi | hacking
Members of Errata Security demonstrated the technology at the Black Hat hacker conference in Las Vegas. The devices reportedly allow an attacker to interactively monitor traffic flowing to and from public wi-fi hotspots through laptop computers, PDAs and smartphones. These tools make it much easier for a cyber criminal to steal banking account details, according to Robert Graham of Errata Security.

A malicious user can also use this technology to pinch unencrypted cookies used across wi-fi web sessions, which permits the hacker to take control of the user’s online session.

At the show, officials demonstrated the hijacking of a Google mail session, but said the hacker methodology could also be extended to other popular social networking sites such as Facebook and MySpace.

However, the tools created by Graham and named “Hamster” and “Ferret”, would not allow the hacker to change the user’s password. What’s more, people using encrypted email services, such as GMail, would be protected against such an attack.

“The evolution of wi-fi hacking is quite frightening,” said Geoff Sweeney, chief technology officer at Tier-3. “Public wi-fi users need to be far more aware that their online sessions are highly insecure. Laptop users need to employ every available security system available to them, which means turning to technologies such as SSL, two-factor authentication and behavioural analysis software as standard procedure. Only by using these security technologies can users be reasonably sure that their online sessions are not being intercepted.”

The Black Hat conference is held every year in the Nevada city, and is an event for security professionals around the world to come together and swap information about online threats and hacking.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Mobile Whitepapers