Showing posts with label Wi-FI Network. Show all posts
Showing posts with label Wi-FI Network. Show all posts

Wednesday, 18 November 2015

Public Wifi Especially Risky In Airports And Hotels



Most of unsafe open Wi-Fi networks can be found in airports and hotels. There is the chance that you log in to a hotspot of a malicious greatest. That's Janne Pirttilahti, Director of Product Management Next Gen Security at F-Secure, said Tuesday.

Pirttilahti demonstrated during Wifi Now in Amsterdam how easy it is to create a fake hotspot and people in the area to let the network use with the aim to steal private information from them.

Hotels And Airports

Hotels and airports are the easiest locations to set up fake hotspots around because there are a lot of businessmen or people who have to spend money, says Pirttilahti talking. "There are interesting targets, while falls in those locations do not like someone pops open a laptop with antennas. Sometimes it can even from a hotel room. But in a coffee shop is much faster suspicious."

Research by F-Secure among UK consumers also shows that many consumers are well aware of the risks they run if they use public Wi-Fi networks. A whopping 52 percent of consumers surveyed avoid using public Wi-Fi networks because they are afraid that their personal information into the hands of hackers.

VPN Connection

59 percent says open Wi-Fi networks not to use it because they are afraid of viruses or malware. Still, says nearly one in every three month to use at least once and sometimes daily public wifi networks. The advice is to at public Wi-Fi networks in any event using a VPN connection.

Sunday, 25 October 2015

German Government Gives Safety Tips For Cloud Use


More and more people are making use of cloud services, which both benefits and risks entails. The reason for the German Federal Office for Information Security (BSI), part of the German Ministry of the Interior, to various tips to give.

While cloud providers are responsible for the safety and the use of cloud services is easy, data should not simply be placed in the cloud, says the BSI. So data can be sent unencrypted through which others can intercept and it is not always clear where the data is stored. Following several recommendations, however, can be made safely use the cloud, says the BSI. The department recommends that only access the cloud via a secure system.

It should be a secure password for cloud services and set login to the cloud via an unsecured Wi-Fi network can be avoided. In addition, operators must read the terms and conditions of the cloud service and figure out the location of the data centers used. In the case of sensitive or important information which should only be stored encrypted in the cloud.Finally, users must check how their data is deleted from the cloud. Some cloud providers store backups namely in different data centers.

Tuesday, 20 October 2015

Smart Kettle iKettle 2.0 Leaking WiFi Key


A smart kettle which it is possible to cook over the local Wi-Fi network water seems to leak the WiFi key. This has security researcher Ken Munro of the British Pen Test Partners discovered. The iKettle 2.0 is developed by Smarter kettle which is operated via the smartphone.

In the first version of the kettle was found that the device is vulnerable to an attack where the malicious attacker a Wi-Fi network setup. The kettle simply showed the SSID to use for authentication. Once the kettle with the malicious Wi-Fi network connection allows an attacker can retrieve via Telnet the WPA key of the original Wi-Fi network in plain text and connect with this.

Munro since the problems with the first iKettle in June demonstrated there is a new version appeared on the market, the iKettle 2.0. This version, despite the new version number with the same problems to worry, says Munro. Ascertaining the WiFi key would be especially easy when the Android app is used for operating the kettle, but the attack is also to perform in users of the iPhone app.

The researcher advises owners of smart kettle to turn it on only when water should be boiled and then off again.Furthermore, any update from the manufacturer must be installed directly. Also advised is not nonsensical 'Internet of Things' devices being connected to the home network, unless the security of the manufacturer has been tested and proven.

Thursday, 6 August 2015

Businesses Warned Of The Risk Of NetBIOS


An interface that has existed for over 30 years and is present in all versions of Windows, is still a serious security risk for businesses and users. Before warns security expert Perry Mertens . It involves the NetBIOS interface from 1983. NetBIOS stands for Network Basic Input Output System and is an interface that allows systems to communicate within a local network.

Over the years, several vulnerabilities in the protocol discovers and also abused, including spoofing attacks. The protocol does not use authentication and is therefore particularly vulnerable to spoofing. According to Mertens it is quite easy to perform NetBIOS spoofing attacks. An attacker only needs to connect to the local network or an open Wi-Fi network. Then catch his user ID and password hashes through all sorts of readily available tools on. These hashes are often crack again through other tools.

"This is the easiest way for an attacker to steal user data, just wait," Mertens says. Using the stolen data can allow an attacker access to personal data, applications and systems. Because of the risk of NetBIOS Mertens puts it even as a "30 year old forgotten backdoor in Windows". He advises organizations and suppliers alike to NetBIOS disable . Warning for NetBIOS is not new. Three years ago, the Internet Storm Center hole a similar warning off.

Wednesday, 29 July 2015

Wifi System Skoda Cars Vulnerable To Attackers


Several vehicles carmaker Skoda has a wifi system so that it can be read on a tablet or smartphone information from the car, but according to researchers is inadequate security. The SmartGate system lets users create through wifi to connect to the car.

Then all kinds of data can be read, such as speed, fuel consumption, number of days until the next service and other information. Researchers at Trend Micro discovered that an attacker more than twenty different parameters can be read out and the owner of the car from the SmartGuard system can exclude. To carry out the attack, an attacker must remain in the vicinity of the Wi-Fi network of the car and then crack the wifi password. That's according to the researchers, however, rather weak. Also, it is no problem to stay close to the Wi-Fi network. With a speed of up to 40 kilometers per hour they managed to crack the Wi-Fi network.

Reading the data even managed a speed of 120 kilometers per hour. The researchers argue that an attacker can modify the wifi settings and the user so can eliminate the system. Then it must return to the dealer to put make back its institutions. The researchers advise owners of a Skoda with SmartGate to put the wif-range at 10% and change the wifi password and network name. Skoda is advised to set the standard signal strong at 10% and an on / off switch SmartGate design. SmartGate would be present at least in the Octavia, Yeti and Superb.

Sunday, 19 July 2015

Hacker Develops Device To Surf The Internet Anonymously


A well-known hacker has developed a device that users can go online anonymously, without their actual location or IP address to give up. The ProxyGambit of Samy Kamkar is an "improvement and reincarnation" of the ProxyHam. The ProxyHam would be demonstrated at the Defcon hacking conference initially, but researcher Benjamin Caudill concluded his lecture for letting off unknown reasons.

Also destroyed it all prototypes of the ProxyHam and announced that the software and blueprints of the device would not be published. The ProxyHam was a device that consisted of a Raspberry Pi computer with Wi-Fi card and three antennas. An antenna connection made ​​with an open Wi-Fi network, for example at a Starbucks or library, and two antennas that sent the data to and from the user via a 900Mhz frequency. A user could be at a position of 4 kilometers.

ProxyGambit

Kamkar, which in recent months regularly with all kinds of hardware hacks in the news came out, decided to develop its own solution based on the idea of ProxyHam. The ProxyGambit however, leave more space between the user and the used Wi-Fi network. The device supports both a radio link as a mobile bridge to connect to a Wi-Fi network. In the case of the GSM network can bridge the thousands of kilometers away there. Is made ​​using a direct link, the distance 10 kilometers.

Like the ProxyHam assigns the IP address that is visible to the outside world to the Wi-Fi network that uses the ProxyGambit. To connect to the mobile bridge, which used 2G, can be used as Kamkar a prepaid SIM card, which can be obtained anonymously. "In both cases, your connection proxied by local Wi-Fi networks in the vicinity of the unit, making it difficult to determine your actual location, IP and identity," Kamkar says.

The hardware for the ProxyGambit consists of an Arduino Nano, Raspberry Pi, GSM Fona, USB hub, wifi adapter, Ubiquiti Nano Station and a Power over Ethernet injector. The cost of the parts amounts include 200 dollars. The software for the device, the hacker on GitHub placed while a Linux image via Dropbox is available for download. Kamkar warns that this is still a "proof of concept" goes and users for whom privacy and anonymity is important to do further research.

Thursday, 2 July 2015

Anonymous Surfing Via Wi-Fi Network In Kilometers


An IP address usually leads to the physical location of an Internet user, but a security researcher has developed a hardware-based solution that makes it possible to surf the Internet anonymously via Wi-Fi networks that are located on kilometers away.

Even if the IP address is traced, the actual location and identity of the user is protected. The solution devised Benjamin Caudill , founder of Rhino Security Labs, the ProxyHam. Anonymity on the Internet is as Caudill under fire, especially for whistleblowers. Although Tor provides some anonymity, there is still a fundamental vulnerability present. Namely, the direct relationship between the IP address and a physical location.

"If your real IP address is detected, the game is over, a big threat if the enemy manages the infrastructure," he tells the notice of the ProxyHam. This device will present at the upcoming Caudill Defcon conference and Internet users must provide more anonymity. The ProxyHam acts as a hardware proxy traffic from the user sends to a Wi-Fi network that is located on kilometers away, says the researcher opposite Vice Magazine.

Hardware

The device consists of a Raspberry Pi computer with Wi-Fi card and three antennas. An antenna that connects to an open Wi-Fi network, for example at a Starbucks or library, and two antennas that send the data to and from the user via a 900Mhz frequency. A user can be located at a position of 4 kilometers. To make the connection ProxyHam the user must connect a 900Mhz antenna on the Ethernet port. An attacker would detect the user will find that only the IP address of the ProxyHam.

The signal emitted by the ProxyHam has such a low frequency that it is difficult to follow. In addition there are in this frequency range of other devices, such as cordless phones, baby monitors and walkie-talkies. Caudill is now working on new features, including an option to destroy the proxy to let themselves be messed with it. The researcher tries to hide the proxy in certain objects like a book. Because of this disguise it can take years before the device according to Caudill is found in a library.