What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Gmail hacked over WiFi HotSpot

Pages: (2): « First [ 1 ] 2 » Last »
Gmail hacked over WiFi HotSpot
Author: Message:
albert
Veteran Member
*****

Avatar

Posts: 2247
Reputation: 42
– / Male / Flag
Joined: Feb 2005
O.P. Undecided  Gmail hacked over WiFi HotSpot
Well, to shorten up the story :

quote:
Originally posted by Zdnet Blog

Robert Graham (CEO Errata Security) gave his Web 2.0 hijacking presentation to a packed audience at Black Hat 2007 today. The audience erupted with applause and laughter when Graham used his tools to hijack someone’s Gmail account during an unscripted demo. The victim in this case was using a typical unprotected Wi-Fi Hotspot and his Gmail account just popped on the large projection screen for 500 or so audience members to see. Of course had the poor chap read my blog about email security last week he might have avoided this embarrassment. But for the vast majority of people using Gmail or any other browser or “Web 2.0″ application, they’re all just a bunch of sheep waiting to be jacked by Graham’s latest exploit.


Full stories and how-to :
http://blogs.zdnet.com/Ou/?p=651

By the way, what do you guys think of this?
It seems that it isn't only Gmail, but online applications with cookies? Is that correct?

This post was edited on 08-09-2007 at 11:19 PM by albert.
08-09-2007 11:19 PM
Profile E-Mail PM Web Find Quote Report
ShawnZ
Veteran Member
*****

Avatar

Posts: 3146
Reputation: 43
32 / Male / Flag
Joined: Jan 2003
RE: Gmail hacked over WiFi HotSpot
this is literally the entire reason people secure their wifi. this type of attack is so well known, its not even a "neat trick" -- its just how its done.
Spoiler:
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
08-09-2007 11:27 PM
Profile PM Web Find Quote Report
albert
Veteran Member
*****

Avatar

Posts: 2247
Reputation: 42
– / Male / Flag
Joined: Feb 2005
O.P. RE: Gmail hacked over WiFi HotSpot
quote:
Originally posted by ShawnZ
so well known, its not even a "neat trick" -- its just how its done.

I secure mine with a WEP 10 characters key, is that enough?
08-09-2007 11:34 PM
Profile E-Mail PM Web Find Quote Report
ShawnZ
Veteran Member
*****

Avatar

Posts: 3146
Reputation: 43
32 / Male / Flag
Joined: Jan 2003
RE: Gmail hacked over WiFi HotSpot
quote:
Originally posted by albert
quote:
Originally posted by ShawnZ
so well known, its not even a "neat trick" -- its just how its done.

I secure mine with a WEP 10 characters key, is that enough?

no :p

in fact, you shouldn't be using WEP at all
Spoiler:
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
08-09-2007 11:37 PM
Profile PM Web Find Quote Report
Supersonicdarky
Veteran Member
*****

Avatar

Posts: 2317
Reputation: 48
– / – / Flag
Joined: Feb 2005
Status: Away
RE: Gmail hacked over WiFi HotSpot
* Supersonicdarky will have fun next time he is stealing wifi (6)
08-10-2007 01:04 AM
Profile E-Mail PM Find Quote Report
Verte
Full Member
***

Avatar

Posts: 272
Reputation: 7
Joined: Apr 2007
RE: Gmail hacked over WiFi HotSpot
I bet it's possible to secure yourself by encrypting all your IP traffic, though you will need a way to decrypt it at the server end. And you know, I bet TOR would work most of the time.
was put impeccably into words at DebianDay for me last Saturday, by Knut Yrvin of Trolltech - adults try something once, fail, and then are like "ffs this doesn't work". Children try, fail, and then try again, and succeed - maybe on the second, or even fifth retry. But the thing is that they keep at it and overcome the problems in the end.

-andrewdodd13
08-10-2007 10:18 AM
Profile E-Mail PM Find Quote Report
M73A
Veteran Member
*****

Avatar


Posts: 3213
Reputation: 37
34 / Male / Flag
Joined: Jul 2004
RE: Gmail hacked over WiFi HotSpot
i have WEP and MAc filtering... is that okay? just my ds only takes wep :(

[Image: lost7ru.gif]
08-10-2007 10:54 AM
Profile E-Mail PM Find Quote Report
andrewdodd13
Senior Member
****

Avatar
Oh so retro

Posts: 870
Reputation: 16
34 / Male / Flag
Joined: Jan 2005
RE: Gmail hacked over WiFi HotSpot
MAC filtering just means they can't steal your connection, but they can decrypt the signal if they're up for it, which means they can do the hack described in the topic.

I can't really be bothered reading this atm, but doesn't G-Mail use SSL?

Edit: Okay, so I went and read it. Cookie snatching is pretty evul. :P

This post was edited on 08-10-2007 at 11:14 AM by andrewdodd13.
[Image: AndrewsStyle.png]
08-10-2007 11:11 AM
Profile E-Mail PM Web Find Quote Report
Steven
Senior Member
****

Avatar
Phillup you little devil you/..

Posts: 616
Reputation: 34
30 / Male / –
Joined: Mar 2005
RE: Gmail hacked over WiFi HotSpot
If there serious about trying to hack into your gmail account, i bet they wouldnt stop when they see WEP. If they would go through that to go into someones account, then why not try to crack WEP? So WEP probably isnt the smartest choice.
[Image: sig2ni2.gif] 
08-10-2007 01:00 PM
Profile E-Mail PM Find Quote Report
ShawnZ
Veteran Member
*****

Avatar

Posts: 3146
Reputation: 43
32 / Male / Flag
Joined: Jan 2003
RE: Gmail hacked over WiFi HotSpot
quote:
Originally posted by andrewdodd13
I can't really be bothered reading this atm, but doesn't G-Mail use SSL?

gmail has ssl capability (if you go to https://gmail.com it'll be ssl) but by default only the logon page uses ssl

This post was edited on 08-10-2007 at 02:28 PM by Tochjo.
Spoiler:
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
08-10-2007 01:28 PM
Profile PM Web Find Quote Report
Pages: (2): « First [ 1 ] 2 » Last »
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On