Communiversity

Afrikan Liberation Institute => Math and Science (STEM) => Topic started by: Ajamu on Jul 01, 2013, 08:25 PM

Title: Here's what an eavesdropper sees when you use an unsecured Wi-Fi hotspot-gctid86054
Post by: Ajamu on Jul 01, 2013, 08:25 PM
http://www.pcworld.com/article/2043095/heres-what-an-eavesdropper-sees-when-you-use-an-unsecured-wi-fi-hotspot.html

Here's what an eavesdropper sees when you use an unsecured Wi-Fi hotspot


                             You've probably read at least one story with warnings about using unsecure public Wi-Fi hotspots (http://www.pcworld.com/article/244012/lock_down_your_wi_fi_network_8_tips_for_small_businesses.html),  so you know that eavesdroppers can capture information traveling over  those networks. But nothing gets the point across as effectively as  seeing the snooping in action. So I parked myself at my local coffee  shop the other day to soak up the airwaves and see what I could see.

  My intent wasn't to hack anyone's computer or device—that's illegal—but  just to listen. It's similar to listening in on someone's CB or  walkie-talkie radio conversation. Like CBs and walkie-talkies, Wi-Fi  networks operate on public airwaves that anyone nearby can tune into.

  As you'll see, it's relatively easy to capture sensitive communication  at the vast majority of public hotspots—locations like cafes,  restaurants, airports, hotels, and other public places. You can snag  emails, passwords, and unencrypted instant messages, and you can hijack  unsecured logins to popular websites. Fortunately, ways exist to protect  your online activity while you're out-and-about with your laptop,  tablet, and other Wi-Fi gadgets. I'll touch on those, too.

 Capturing webpages

  I opened my laptop at the coffee shop and began capturing Wi-Fi signals,  technically called 802.11 packets, with the help of a free trial of a  wireless network analyzer. The packets appeared on screen in real time  as they were captured—much more quickly than I could read them—so I  stopped capturing after a few minutes to analyze what I had vacuumed up.  Note: You can click on any of these screenshots to view larger versions  that are easier to read.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Fwebpage_captured-100044056-large.png&hash=60b7d304deaf7155a4315043d333aebe176f60df) (http://images.techhive.com/images/article/2013/06/webpage_captured-100044056-orig.png)
My own website, captured via the hotspot packets and reassembled for viewing.  I first searched for packets containing HTML code, to see which websites  other hotspot users were browsing. While I did see activity from other  patrons, I didn't capture anything interesting, so I visited my own  website—www.egeier.com (http://www.egeier.com/)—on my smartphone.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Femail_captured-100044052-medium.png&hash=ee84d823b4923b5410f2c44994415596a140d3ee) (http://images.techhive.com/images/article/2013/06/email_captured-100044052-orig.png)
This is a copy of the email I sent (and subsequently received) using my smartphone connected to the hotspot.
  The raw packets with HTML code looked like gibberish, but as you can see  above, the trial network analyzer I used reassembled the packets and  displayed them as a regular webpage view. The formatting was slightly  off and some of the images were missing, but plenty of information still  came through.

  I didn't find anyone else sending or receiving emails during my visit,  but I did discover the test messages I sent and received via my  smartphone while it was connected to the hotspot. Since I use an app to  connect to my email service via POP3 without encryption, you could have  seen my login credentials along with the message (I've blurred the  username and password in the screenshot).

  This is all the information someone would need to configure their email  client to use my account and start receiving my emails. They might also  be able to send emails from my account.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Fim_captured-100044054-medium.png&hash=9035dfb91be9f5f0a782a2ddeffdc70b42ac3a4f) (http://images.techhive.com/images/article/2013/06/im_captured-100044054-orig.png)
And these are the packets that went over the network when I sent an instant message using Yahoo Instant Messenger.  I also used Yahoo Messenger to send a message while I was capturing  Wi-Fi signals. Sure enough, the tool plucked that information out of the  air, too. You should never use an unencrypted instant-messaging service  with any expectation of privacy.

 Capturing FTP login credentials

  If you still use FTP (File Transfer Protocol) to download, upload, or  share files, you should avoid connecting to them over unsecured  hotspots. Most FTP servers use unencrypted connections, so both login  credentials and content are sent in plain text, where any eavesdropper  can easily capture them.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Fftp_captured-100044053-medium.png&hash=c900f64ef7133978f7fe00e80d78cf01b9eca344) (http://images.techhive.com/images/article/2013/06/ftp_captured-100044053-orig.png)
These captured packets reveal the username and password securing my FTP server (I've blurred them in this screenshot).  While using my laptop to connect to my own Web server's FTP server, I  was able to capture the packets containing my login ID and  password—details that would have enabled any nearby eavesdropper to to  gain unfettered access to my websites.

 Hijacking accounts

  Computers aren't the only devices susceptible to eavesdropping. I also  ran an app called DroidSheep on my spare rooted Android smartphone. This  app can be used to gain access to private accounts on popular Web  services, such as Gmail, LinkedIn, Yahoo, and Facebook.

  DroidSheep looks for and lists any unsecure logins to popular websites.  While it doesn't capture the passwords to those sites, it can  exploit a vulnerability that allows you to open the site using another  person's current session, giving you full access to their account in the  process.

  As you can see from the screenshot below, DroidSheep detected Google,  LinkedIn, and Yahoo logins from other people who were connected to the  hotspot, as well as the Facebook login I made on my other smartphone.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Fdroidsheep-100044049-orig.png&hash=cc2fa3a5f837da2219ce3bc44d59dea722a60fd5) (http://images.techhive.com/images/article/2013/06/droidsheep-100044049-orig.png)
DroidSheep detected other users' log-ins, which means those accounts were vulnerable to hijacking.
.  I couldn't legally access other people's logins, of course, but I did open my own Facebook login.

 (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fimages.techhive.com%2Fimages%2Farticle%2F2013%2F06%2Fdroidsheep_hijacking-100044050-medium.png&hash=5e1da13279402d6ad5d3dac198661e4648625575) (http://images.techhive.com/images/article/2013/06/droidsheep_hijacking-100044050-orig.png)
Using  DroidSheep, I was able to access my own Facebook page without providing  a user ID or password. I could have done the same with any other  patron's accounts if they were logged in.  Once I'd done that, I could magically access my Facebook account on that  rooted Android phone (see the screen at lower right) without ever  providing my username or password from that device.

 How to use Wi-Fi hotspots securely

  Now that you've seen just how easy it is for someone to eavesdrop on  your Wi-Fi, here's how you can use a public hotspot with some degree of  security:

'"').'")."n[/list]"'