Wireless Access Control
Home > Ask the Security Experts > Information Security Threats Questions & Answers > What is WiPhishing?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What is WiPhishing?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 October 2006
WiPhishing is something I've heard a lot about lately. Can you please explain this new phishing tactic and detail why WiPhishing should be seen as a threat?

>
EXPERT RESPONSE
WiPhishing involves a bad guy configuring a laptop to impersonate a trusted wireless access point. For example, an attacker may set up a machine with an SSID (a wireless LAN name) of "Linksys" or "T-Mobile," in an effort to get users to access the Internet through the attacker's own machine. If someone falls for the trap, the attacker can monitor all clear-text traffic that passes through the attacker's system, possibly including email, Web content and other data.

There are two factors that can make this type of threat worse. First, many wireless client packages are configured to automatically associate with an SSID that they've used in the past, based merely on the name of the access point. Future connections often happen automatically, regardless of the hardware address or any other characteristic. Thus, a user may not know that his or her software has associated with an access point, let alone an impersonated one. Secondly, there are tools that can automate WiPhishing attacks, namely Hotspotter and Karma. These tools respond to any SSID requests that a wireless client detects. They can then pretend to be that access point, offering services like Web, email and file sharing to the victim's machine. This scheme dupes a user into revealing passwords and other sensitive information.

To foil these attacks, I recommend deploying encrypted VPN access for wireless traffic. Also, instruct users to trust wireless if and only if they've made a VPN connection across it; otherwise, attackers can monitor their traffic.

More information:

  • Learn the best practice for detecting wireless devices.
  • Build a secure wireless connection.

  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Information Security Threats
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    Defining mobile device security concerns
    What security measures can be taken to stop crimeware kits?
    What software development best practices can prevent input validation attacks?
    What is the most secure way for application developers to manage cookies?
    Is there a market for standalone antivirus products?
    Can 'herd intelligence' effectively stop malware?

    Endpoint Security
    Hidden endpoints: Mitigating the threat of non-traditional network devices
    Symantec launches Endpoint Management Suite
    Symantec to offer Endpoint Management Suite
    Sophos finds patching issues through endpoint NAC tool
    Websense, Reconnex top Forrester ranking of DLP vendors
    Cisco, EMC to partner on data protection, PCI
    Product review: Promisec's Spectator
    Will Lockdown customers be left in the lurch?
    NAC, disk encryption gaining attention, survey shows
    Symantec fills gap with whole disk storage encryption

    Wireless Access Control
    Lessons learned from TJX: Best practices for enterprise wireless encryption
    Should the enterprise be concerned with the Apple iPhone's automatic connection to Wi-Fi networks?
    Is it possible to identify a fake wireless access point?
    How 'evil twins' and multipots seek to bypass enterprise Wi-Fi defenses
    Wi-Fi simplicity edging out Wi-Fi security
    Should an enterprise network be regularly checked for rogue access points?
    Aruba bolsters mobile suite with security acquisition
    Cafe Wi-Fi
    VeriSign, AirMagnet team up for wireless IPS
    Check Point promises more VoIP security, fewer slowdowns
    Wireless Access Control Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    brute force cracking  (SearchSecurity.com)
    buffer overflow  (SearchSecurity.com)
    Crash Course: Spyware  (SearchSecurity.com)
    email spoofing  (SearchSecurity.com)
    endpoint security  (SearchSecurity.com)
    phishing  (SearchSecurity.com)
    rootkit  (SearchSecurity.com)
    social engineering  (SearchSecurity.com)
    tunneling  (SearchSecurity.com)
    Wired Equivalent Privacy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts