« Gumball 3000 Rally: Live Loc Tracking |
Main
| Jon Stewart/Daily Show on Watching The Watchers »
May 14, 2005
WiPhishing - phishing to wireless LAN users
Posted by Arieanna Foley
Phishing is more ubiquitous than ever, it would seem. I saw a report on Mobile Pipeline of yet another phishing variant - that of attacking wireless LAN users. It would seem that no vulnerability is left open to chance - nor, for that matter, any opportunity left untapped. This is a sophisticated model of phishing, and one that could easily catch many people, knowledgeable or not.
Basically, the new phishing model will start with a log-in page for a public WiFi network. What you'd expect at any hotspot, really. That is why this is so sneaky.
Without realizing it, the user will enter personal information to the logon page, whereupon the hacker will proceed to put 45 or so viruses onto the computer.
The attack is specifically targetted at business people - it will typically take place at a tradeshow, airport or conference.
What can you do? Use a firewall. Use only those websites that have SSL security (watch for the logo and click on it). Try to use a VPN (virtual private network). Don't stay connected to the wireless network if you don't need to be.
Makes me a little wary about taking my laptop to unknown destinations and playing with it over 'free' wireless networks. After all, I've only had it a couple of days now. Loving it. PowerBook G4. My first Mac. Great choice. I've been raving about it on my blog a ton. Sidetracked there. Point is: be careful.
Comments (1)
+ TrackBacks (0) | Category: Technology
- RELATED ENTRIES
- Reminder -- /Message
- /Message - A New Blog
- The Individual Is The New Group -- Part 1
- 1000 Tags: Tag Advertising
- Social Ethics And Technology Design
- Nancy Hass on In Your Facebook.com
- Black and White and Dead All Over: Is Newsprint Dead?
- Anonymous Trolls, Beware: You Are Breaking Federal Laws
1. Brad Bowers on May 15, 2005 05:24 PM writes...
It seems some companies are starting to address such vulnurabilities that you mention.
JiWire.com has a new product that lets subscribers tap into a private VPN account, and ensures that the info coming and going from a user's laptop is encrypted. This gives great protection to a user even if they are logged into a "fake" network.
The product was just beta released.
(Full disclosure: my company represents JiWire for business development partnerships).
Permalink to Comment