'WiPhishing' Said To Threaten Wi-Fi Users
2005-02-04 16:53:00
Network security vendor Cirond said Friday that a new danger, which it calls "WiPhishing" threatens users of laptops equipped with Wi-Fi and the companies that employ those users.
The threat is a variation of the "Evil Twin" gambit that was in the news in the last month, the company said.
"We call WiPhishing the act of covertly setting up a wireless-enabled laptop or access point for the purpose of getting wireless laptops to associate with it," Cirond CEO Nicholas Miller said in a statement. "Hackers who are on a 'WiFishing expedition' may set the name of their rogue wireless access point (or laptop) to an SSID that is commonly used by wireless laptop users."
For example, a WiPhisher could set the SSID of an access point or laptop to be the same as the default settings for widely-sold access points or hotspot services offered by vendors such as T-Mobile and Wayport, Miller said.
"Hackers are also likely to increasingly post common SSID names on their Web sites as this practice gains momentum," Miller said.
Miller said he will outline solutions to this problem -- including solutions offered by Cirond -- at a security conference next week in Victoria, British Columbia. He said he has been working with the researcher, Dr. Phil Nobles, who was vocal about the 'Evil Twin' threat in the last month. That threat jams access to legitimate access points and guides users into logging on to what they think is a legitimate wireless network that, in fact, set up by hackers.
In both cases, the threat is that hackers can intercept keystrokes or gain unauthorized access to enterprise networks, according to Miller.
|
|
Sun plugin gives MS Office users ODF support
Ubuntu Hardy beta released
IBM to invest in open source EnterpriseDB
Likewise opens Windows networks to Linux and Macs users
Oracle offers clustering for Linux
CrossOver Games adds firepower to Linux
Photoshop goes online, free
Sun plans to fully open source Java
Linux guru found guilty of murder
|