Hacking public Wi-Fi

1 February 2018 Editor's Choice, Information Security, Infrastructure

Public Wi-Fi is great in so many ways. It costs nothing, saves on mobile data, and is often faster when it comes to downloading. However, as much as we love the convenience, hackers love public Wi-Fi too, and for different reasons.

Nastassja Poorter, enterprise sales director at DRS, a Cognosec AB company, says there are several ways cyber crooks can access an individual’s private information and even steal their identity or capture their banking logins through public Wi-Fi.

One of the ways in which they can do this, is through Man-in-the-Middle (MITM) attacks, during which a hacker intercepts communications between two parties. While they may think their communications are private and that data is being shared directly between the server and the client, the link is, in fact, being intercepted by a third-party. The attacker can then alter the communication and display, for example, a fake or phishing website or send a message of his own.

“Public Wi-Fi is particularly susceptible to attacks of this nature due to the fact that any HTTP site data being transmitted is unencrypted, effectively rendering your data public. Through compromised routers, attackers can steal reams of personal information and give them access to financial logins, private messages, user names and passwords. People should never, under any circumstances, do online banking transactions or share any personal information with others while using public Wi-Fi.”

So what can users do? Check for secure sites, ones that have https:// instead of just http in front of them. “Certificates denoted by the ’s’ mean the website is more secure, and offers a decent level of encryption, so only use such sites when accessing personal information,” says Poorter.

The next thing users of public Wi-Fi need to be aware of are ‘Evil Twin’, or fake, Wi-Fi connections. In these attacks, a cyber criminal sets their service identifier (SSID) to be the same as an access point (AP) at the local hotspot or wireless network. He can then disrupt or disable the genuine AP by disconnecting it, directing a denial of service attack against it, or creating radio frequency interference around it. This is particularly cunning, as it bypasses any security systems a public Wi-Fi hotspot might have in place.

She advises users to be very suspicious should two network connections show up that have a similar name, and if possible, make use of a virtual private network (VPN). This will establish a level of encryption between the user and a website, so any data that could potentially be intercepted is unreadable to a cyber criminal unless they have the decryption key, which they don’t.

According to Poorter, the next danger associated with public Wi-Fi is packet sniffing. “Every time there is data transmitted over the Internet, irrespective of whether it’s an email, Google search or retail transaction, the data is broken down into digital information that is sent in data packets. The packets are labelled and addressed with instructions explaining where they are going to. Millions of data packets move between destinations all the time, uninterrupted,” she explains.

“However, and here’s the caveat: If someone has installed sniffing hardware or software somewhere on the network, they can eavesdrop, snatch that data in mid-transmission just long enough to ‘sniff’ or inspect it, and if found to be interesting or valuable, quickly capture and copy it before sending it on its way. This is done without anyone being the wiser. Packet sniffing is like wiretapping for the Internet.”

Packet sniffers can read emails, see passwords, view your Web history and, more alarmingly, capture account information such as logins and credit card numbers in detail. “Again, I recommend turning to strong encryption, in the form of a VPN to avoid this,” says Poorter.

Another danger of public Wi-Fi is sidejacking, or session hijacking. In these instances, an attacker will essentially steal a user’s access to a website by using a packet sniffer to get their hands on an unencrypted cookie that grants access to the site in question. This technique allows the cyber crook to impersonate the user, as the session cookie is already providing access to the website’s content. Alarmingly, sidejacking bypasses encryption to some degree.

Poorter says although attackers can’t read a password through this technique, they could still download malicious software that could, and get their hands on enough information to make stealing your identity a breeze. “Again, make use of https:// and VPNs to secure against this type of threat.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Surveillance & AI roundtable
DeepAlert Lytehouse Refraime SMART Security Solutions Technews Publishing Editor's Choice Surveillance Integrated Solutions AI & Data Analytics
SMART Security Solutions held an online roundtable with a few surveillance experts to explore the intersection of surveillance and AI, gaining insights into the market and how control rooms are evolving.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Securing your access hardware and software
SMART Security Solutions Technews Publishing RBH Access Technologies Access Control & Identity Management Information Security
Securing access control technology is critical for physical and digital security. Every interaction between readers, controllers, and host systems creates a potential attack point for those with nefarious intent.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.