Go Back   Singapore's Online Community - Singapore Forums > Current Affairs > Local Affairs
Register FAQ Member List Calendar Mark Forums Read

Local Affairs
Discussion of current events and issues around us.


Reply
 
Thread Tools Display Modes
Old 04-08-2007, 02:37 AM   #1 (permalink)
shm
Cool SGClubber
shm is on a distinguished road
 
shm's Avatar

Join Date: Jul 2007
Posts: 955
iTrader: (0)
Gender:
Location: sinagpore
Total SGC$: 1,891.70
Default Warning of webmail wi-fi hijack

Using public wi-fi hotspots has got much riskier as security experts unveil tools that nab login data over the air.
Demonstrated at the Black Hat hacker conference in Las Vegas, the tools make it far easier to steal account details, said Robert Graham of Errata Security.

Identifying files called cookies are stolen in the attack which let hackers pose as their victim.

This gives attackers access to mail messages or the page someone maintains on sites such as MySpace or Facebook.

Hacker gathering

Prior to the demonstration, which involved the live hijacking of a Google mail account (GMail), many sites were thought to be safe because they encrypted the data swapped back and forth when people login.

However, Mr Graham carried out his attack on the unencrypted cookies, tiny text files, many sites use to identify people that regularly return.

The tools created by Mr Graham, called "Hamster" and "Ferret", watch the traffic flowing in and out of public wi-fi hotspots and let attackers grab cookies as they are passed back to people logging in to their webmail or social network account.

Using the cookie an attacker could pose as a victim and enjoy almost the same level of access to an account as its rightful owner.

There were some defences against the attack, said Mr Graham.

Attackers would be unable to change a password and take over an account as most sites ask people to re-enter their old password before letting them make changes.

Also, said Mr Graham, some webmail services, such as GMail, let people encrypt all the data passed back and forth as they deal with their mail.


Malicious hackers are turning to popular video sites

Mr Graham revealed his findings during a presentation at the four-day Black Hat conference held in Las Vegas. The conference brings together security professionals around the world who swap information about the latest exploits and future vulnerabilities.

He said Errata would make the attack tools publicly available via the company's website for anyone to download.

Also at the conference David Thiel, of security firm iSec Partners, revealed that PC media players have significant vulnerabilities that could be exploited by hi-tech criminals.

The loopholes could be used to attach malicious programs to music or video downloads in order to hijack a PC.

He suggested that popular pages on social networking sites could be subverted by malicious hackers to add the booby-trapped media files.

"The potential for attack is pretty severe," he said.

Mr Thiel said the makers of the media players had been told about the problems and were working on fixes for them.
shm is offline   Reply With Quote
Sponsored links
Your Ad Here
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

SGC$ Per Thread View: 0
SGC$ Per Thread: 2.00
SGC$ Per Reply: 1.00

Similar Threads
Thread Thread Starter Forum Replies Last Post
Australia upgrades travel warning for Britain lkarren Foreign Affairs 2 02-07-2007 01:14 AM
Couple duped by rogue lawyer ignored 'warning signs' lkarren Local Affairs 7 28-06-2007 02:43 AM
Dumb and Funny Warning Labels On Products Terry Laugh Out Loud 11 18-05-2007 01:50 AM
Public Warning System sirens to sound on Feb 15 across Singapore djchris Local Affairs 30 16-02-2007 02:36 PM

» Current Poll
If You Had Only One Wish, Which would You Choose?
$100 Million Dollars - 38.74%
203 Votes
Perfect Health - 11.26%
59 Votes
Perfect Life Partner - 16.03%
84 Votes
Perfect Body - 5.73%
30 Votes
Perfect Family - 7.06%
37 Votes
No More Global Warming - 9.73%
51 Votes
World Peace - 11.45%
60 Votes
Total Votes: 524
You may not vote on this poll.
» Friends
Funny Videos
Free Wallpapers
Singapore Christian
Start Your Website
Copyright© 2004-2008 SGClub.com. All rights reserved.
Ad Management by RedTyger & Powered by vBadvanced CMPS v3.0.1

        All times are GMT +8. The time now is 06:39 AM.


SEO by vBSEO 3.0.0 ©2007, Crawlability, Inc.