Email Delivery

Receive new posts as email.

Email address

Syndicate WNN sites

Single feed for all sites

Syndicate this site

RSS 0.91 | RSS 2.0
RDF | Atom
Podcast only feed (RSS 2.0 format)
Get an RSS reader
Get a Podcast receiver

Contact

About This Site
Contact Us
Privacy Policy

Search

Google

Web this site

May 2007
Sun Mon Tues Wed Thurs Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

Stories by Category

Basics :: Basics
Casting :: Casting Listen In Podcasts Videocasts
Culture :: Culture Hacking
Future :: Future
Hardware :: Hardware Adapters Appliances Chips Consumer Electronics Gaming Home Entertainment Music Photography Video Gadgets Mesh Monitoring and Testing PDAs Phones Smartphones
Industry :: Industry Conferences Financial Deals Free Health Legal Research Vendor analysis
International :: International
Media :: Media IPTV Locally cached Streaming
Metro-Scale Networks :: Metro-Scale Networks Community Networking Municipal Public Safety
Network Types :: Network Types Broadband Wireless Cellular 2.5G and 3G 4G UMTS Power Line Satellite
News :: News Mainstream Media
Politics :: Politics Regulation Sock Puppets
Schedules :: Schedules
Security :: Security 802.1X
Site Specific :: Site Specific Administrative Detail April Fool's Blogging Book review Cluelessness Guest Commentary History Humor Self-Promotion Unique Wee-Fi Who's Hot Today?
Software :: Software Open Source
Spectrum :: Spectrum
Standards :: Standards 802.11a 802.11e 802.11g 802.11n 802.20 Bluetooth MIMO UWB WiMAX ZigBee
Transportation and Lodging :: Transportation and Lodging Air Travel Aquatic Commuting Hotels Rails
Unclassified :: Unclassified
Vertical Markets :: Vertical Markets Academia Enterprise WLAN Switches Home Hot Spot Aggregators Hot Spot Advertising Road Warrior Roaming Libraries Location Medical Residential Rural SOHO Small-Medium Sized Business Universities Utilities wISP
Voice :: Voice

Archives

May 2007 | April 2007 | March 2007 | February 2007 | January 2007 | December 2006 | November 2006 | October 2006 | September 2006 | August 2006 | July 2006 | June 2006 | May 2006 | April 2006 | March 2006 | February 2006 | January 2006 | December 2005 | November 2005 | October 2005 | September 2005 | August 2005 | July 2005 | June 2005 | May 2005 | April 2005 | March 2005 | February 2005 | January 2005 | December 2004 | November 2004 | October 2004 | September 2004 | August 2004 | July 2004 | June 2004 | May 2004 | April 2004 | March 2004 | February 2004 | January 2004 | December 2003 | November 2003 | October 2003 | September 2003 | August 2003 | July 2003 | June 2003 | May 2003 | April 2003 | March 2003 | February 2003 | January 2003 | December 2002 | November 2002 | October 2002 | September 2002 | August 2002 | July 2002 | June 2002 | May 2002 | April 2002 | March 2002 | February 2002 | January 2002 | December 2001 | November 2001 | October 2001 | September 2001 | August 2001 | July 2001 | June 2001 | May 2001 | April 2001 |

Recent Entries

Sensible Take on the Municipal Part of Muni-Fi
Times Online Misreads UK Starbucks Evil Twin Attacks
Marshalls Use of WEP Leads to 200m Stolen Credit Card Numbers
Wee-Fi for May 3: St. Louis Wi-Fi, LA Bus-Fi, European Free-Fi
New Wi-Fi Protected Setup Firmware, Devices Due Next Month
T-Mobile to Extend Converged Wi-Fi Calling Nationwide
Wee-Fi for May 1: Solar Panels Offend, More BPL, Best Wi-Fi Hotels, Apple Update
Wee-Fi for April 30: WSJ on Muni-Fi, Iridium Pricing, Heathrow Express
Why Wi-Fi Isn't the New Asbestos
Metro Wi-Fi Firms Want Guarantees

Site Philosophy

This site operates as an independent editorial operation. Advertising, sponsorships, and other non-editorial materials represent the opinions and messages of their respective origins, and not of the site operator or JiWire, Inc.

Copyright

Entire site and all contents except otherwise noted © Copyright 2001-2006 by Glenn Fleishman. Some images ©2006 Jupiterimages Corporation. All rights reserved. Please contact us for reprint rights. Linking is, of course, free and encouraged.

Powered by
Movable Type

« Marshalls Use of WEP Leads to 200m Stolen Credit Card Numbers | Main | Sensible Take on the Municipal Part of Muni-Fi »

May 5, 2007

Times Online Misreads UK Starbucks Evil Twin Attacks

By Glenn Fleishman

The Times mades a big blooper, mistaking a login bypass for an attack: The Times Online has this story about how Starbucks in the UK are being targeted by hackers (phishers and simply criminals, really) who are setting up evil twins, which are computer-based hotspots that masquerade as the legitimate local network. The evil twin itself connects to the legitimate network to provide backhaul. Evil twins are useful at harvesting information sent in the clear, as well as providing fake DNS coupled with locally hosted phishing Web sites that might convince a user to enter private data.

Unfortunately, the Times’s information, uncovered in a chat room, points to a method by which hackers are bypassing paying for T-Mobile’s Starbucks-based service. The chatroom discourse begins with someone asking about man-in-the-middle (MitM). In classic MitM, an intruder inserts themselves between two parties, relaying information while listening in. In cryptographic circles, MitM is defeated by using effective key exchange with out-of-band confirmation through certificate authorities, reading a fingerprint to one another, or other methods.

The next chatroom messages the Times discusses, however, are about tunneling Internet traffic from DNS (domain name service). DNS is used to take a domain name and retrieve the associated Internet Protocol (IP) address. Because the login process for a hotspot requires DNS to work, DNS requests are generally passed through without restriction. However, DNS requests can return loads of other information in special resource record types. With the right kind of software on both ends—on your laptop and a remote server—you could perform an end run around authentication and tunnel your traffic over DNS just like a virtual private network connection tunnels all its traffic via the VPN connection. Devicescape uses DNS to retrieve authentication information in its lightweight device-oriented hotspot login environment.

The chatroom participants pretty much state this outright: “I am now able to tunnel my way around public hotspot logins…It works GREAT. The dns method now seems to work pass starbucks login.” In fact, there are two popular DNS tunneling packages available.

Hotspots can throttle DNS traffic, or filter queries, but there are clever ways around this, including returning data as part of the alias for a domain name that’s requested (a CNAME or canonical name record). So much of DNS requires passthrough of arbitrary data that I don’t know how large a problem this is. One of the quoted chatroom messages in the Times article notes that the user was only able to get a few kilobits per second, which could be a result of either throttling or overhead. It’s possible T-Mobile has throttled DNS traffic to a very low speed, which would make sense.

Posted by Glennf at May 5, 2007 2:11 PM

Categories: Security

Trackback Pings

TrackBack URL for this entry:
https://db.isbn.nu/mt3/mt-tb.pl/4549

Comments

Post a comment




Remember Me?