Warning of webmail wi-fi hijack

by nukegingrich | August 3, 2007 at 04:53 am
893 views | 30 Recommendations | 1 comment

"The potential for attack is pretty severe."

Heard at the Vegas Black Hat conference

Demonstrated at the Black Hat hacker conference in Las Vegas, the tools make it far easier to steal account details, said Robert Graham of Errata Security.

Identifying files called cookies are stolen in the attack which let hackers pose as their victim.

This gives attackers access to mail mesages or the page someone maintains on sites such as MySpace or Facebook

Prior to the demonstration, which involved the live hijacking of a Google mail account (GMail), many sites were thought to be safe because they encrypted the data swapped back and forth when people login.

However, Mr Graham carried out his attack on the unencrypted cookies, tiny text files, many sites use to identify people that regularly return.

Advertisement
recommend This comment thread is now closed
Jordan Yerman
Jordan Yerman
flagged this story as Good Stuff

at 05:25 on August 3rd, 2007

This, incidentally, is the major downside to citywide Wi-Fi efforts: if everyone's on the same network, it's harder to protect your transmissions from "stranger danger". Nice one, Nuke.

This story was created over 3 months ago, the comment thread is now closed.

closeSign in to NowPublic

is reporting from