WiFi users feel the sting of 'evil twins'
Hackers setting up near hot spots trick wireless PC users into revealing data
by Jerry Langton
Cheryl was suckered by a wireless hacker.
''I feel like such an idiot,'' says the IT technologist for a London-based banking company, who refused to let her surname be published. ''Considering what happened and what I do for a living, I just can't let people know that I was fooled like this.''
Working on her laptop in a park near her office, Cheryl thought she was logging onto the Internet using a public WiFi access point. From what happened next, she believes she inadvertently exposed herself to criminals bent on identity theft, despite the fact that she's something of a technology security expert and the would-be thieves were using a very simple trick.
"I noticed the log-on was slightly different, but thought nothing of it," she said. "It wasn't until they asked for my credit card number that I noticed something was up."
Realizing that a service she had used every day for months really shouldn't need her information again, she shut down her computer. "They didn't get my Visa number, but I did give them a couple of passwords, including the ones I use for Amazon and Hotmail."
Cheryl was the target of a new type of attack by a hacker using a fraudulent WiFi hot spot. Commonly known as "evil twins," the fake hot spots are set up close to legitimate public wireless access points in an attempt to trick users into logging onto the rogue site while believing they're using the trustworthy site.
"Users think they've logged on to a wireless hot-spot connection, when in fact they've been tricked to connect to the attacker's unauthorized base station," said Dr. Phil Nobles, a cybercrime expert from the Royal Military College of Science at Cranfield University in Shrivenham, England. "The latter jams the connection to a legitimate base station by sending a stronger signal within close proximity to the wireless client -- thereby turning itself into an 'evil twin.' "
They are referred to as "evil" by security experts because the purpose behind twins usually appears to be profit through identity theft rather than mere nuisance.
"Unwitting Web users are invited to log into the attacker's server with bogus log-in prompts, and can pass sensitive data such as user names and passwords, which can then be used by unauthorized third parties," Dr. Nobles said. "This type of cybercrime goes largely undetected because users are unaware that this is taking place until well after the incident has occurred."
Although Dr. Nobles says evil twins have quickly become a fairly common occurrence in Britain, there have been no official reports thus far of evil twins at any of the roughly 1,000 public hot spots in Canada or the 22,000 in the United States. But experts warn that it's an easy hack, so wireless network users should be wary.
"It's a real nasty attack and there's no effective defence against it," said Minneapolis-based network security expert Bruce Schneier. "It's so simple -- what a great scam. It hasn't happened here yet, but it will."
Perhaps the most alarming thing is how easy it is to set up an evil twin.
"Cybercriminals don't have to be all that clever to carry out such an attack," Dr. Nobles said . "Because wireless networks are based on radio signals, they can be easily detected by unauthorized users tuning into the same frequency."
Hackers drown out the existing hot-spot signal simply by duplicating its settings and putting out a stronger signal. Special high-powered access point hardware can be used, but in some cases it can even be done with a simple WiFi-equipped notebook.
"Think of it as having your radio tuned in between two stations," said Mike Johnson of WebFargo, an Internet security company based in Raleigh, N.C. "Adjust your tuner just a bit or move a few feet either way and one of the stations takes over; but if they're on exactly the same frequency, the stronger one will dominate."
Then the hacker monitors the data transferred between users and the rogue access point, or directs people to fake versions of popular commercial websites, with the aim of recording things such as logins, passwords and credit card numbers.
Although it's difficult to tell if you've logged onto an evil twin, there are precautions users can employ to protect themselves, such as noting any unexpected changes to the log-on routine for public hot spots used in the past.
"Before you send any potentially sensitive or valuable material over the Web, look for a logo that shows the site has SSL encryption or make sure the URL begins with 'https,'" Mr. Johnson adds. "The extra 's' indicates a secure server," he said, and the lack of one can help people identify a bogus website.
"We advise that customers should change all default [network] settings, and make sure that their security settings on all equipment are configured correctly," added Chris Clark, chief executive officer for British Telecom's wireless broadband products group. "We also advocate the use of personal firewalls to ensure that only authorized users can have access [to a PC] and that data cannot be intercepted."
The situation is somewhat more dire for businesses. "For our clients with the most secure information -- pharmaceutical companies, for example -- we recommend that they never use wireless access," Mr. Johnson said. "When that's not realistic, we recommend that companies configure with secure Web [encryption] keys and change them often. . . . Anything anybody can offer at this point would be just a stopgap measure to keep us inches ahead of the bad guys," he said.
"Until they redesign the entire protocol with something entirely new, there's no way to stay truly secure from this type of attack."
[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20050331.gttwwifi31/BNStory/Technology/\"]source: Globe & Mail Technology[/url]
WiFi users feel the sting of 'evil twins'
Moderators: Moderator, Global Moderator
Jump to
- General Category
- ↳ KillaNet Country
- ↳ 2D Graphics
- ↳ KillaNet News
- ↳ 3D & Animation
- ↳ Chatroom
- ↳ Flash
- ↳ Help & Suggestions
- ↳ Game Dev
- ↳ Audio & Video
- ↳ Introductions
- ↳ Journalism
- ↳ Phoenix Lounge
- ↳ Application Dev
- ↳ Toga Toga Toga!!!
- ↳ Photography
- ↳ Main Street Archives
- ↳ Web Design
- ↳ Fonts Icons Cursors & Screensavers
- ↳ Book Reviews
- ↳ General
- ↳ Tech Industry News
- ↳ Legal Resources
- ↳ Industry Contests
- ↳ Graphix Battle Arena
- ↳ KillaNet Contests
- ↳ Competition Archives
- ↳ Education Information
- ↳ Careers
- ↳ Game Studies
- ↳ Motivation
- ↳ Conferences & Seminars
- ↳ KillaDesign
- ↳ Animation & Film
- ↳ The Studio
- ↳ Game Development
- ↳ 2D Graphics
- ↳ Audio & Video
- ↳ 3D Graphics
- ↳ Flash
- ↳ Fonts, Icons & Emoticons
- ↳ Design Requests
- ↳ PhotoShop
- ↳ Cinema 4D
- ↳ Bryce
- ↳ Flash
- ↳ Paint Shop Pro
- ↳ Blender
- ↳ Poser
- ↳ The Darkroom
- ↳ Photo & Camera Discussion
- ↳ Photo Journalism
- ↳ Web Design Principles
- ↳ PHP & MySQL
- ↳ Designing For Print
- ↳ Writer\'s Desk
- ↳ Fiction Writing
- ↳ News Journalism
- ↳ Poetry
- ↳ Technical Writing
- ↳ Biographical Writing
- ↳ General Writing Resources
- ↳ Promotional Writing
- ↳ Film & Television
- ↳ VideoGames
- ↳ Computer Department
- ↳ General Discussion
- ↳ Windows Help
- ↳ Linux Help
- ↳ Builds & Mods
- ↳ Geek Gadgets
- ↳ Security
- ↳ Dev Discussion
- ↳ C++
- ↳ Visual Basic
- ↳ Java
- ↳ Application Skinning
- ↳ IRC Scripting
- ↳ Gaming Centre
- ↳ Guild Wars
- ↳ Aion
- ↳ Computer
- ↳ World of Warcraft
- ↳ Nintendo
- ↳ General RPG & MMORPG
- ↳ PlayStation
- ↳ XBox
- ↳ Other Consoles
- ↳ All Action
- ↳ Racers
- ↳ Sports
- ↳ FPS
- ↳ RTS
- ↳ Sim
- ↳ Casual Games
- ↳ Kids' Games
- ↳ Mobile Games
- ↳ Retro Games
- ↳ Challenges, Friendly Taunts & Discussion
- ↳ Game Requests & Bug Reports
- ↳ Open Source Games
- ↳ Puzzle Games
- ↳ HeadQuarters
- ↳ Uber Coffee Room
- ↳ KillaNet
- ↳ Coffee Room
- ↳ KillaNet
- ↳ KillaGraphix
- ↳ KillaHosting
- ↳ Marketing etc.
- ↳ Staff Issues
- ↳ Reference & Software
- ↳ Archives
- ↳ KillaBlogs
- ↳ Journalism
- ↳ Trash Can

