ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Wi-Fi 'Evil Twin' to become troublemaker

Dan Ilet ZDNet.co.uk

Published: 20 Jan 2005 17:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Wi-Fi hot-spot users should be on their guard for malicious wireless access points that steal data.

Researchers at Cranfield University, are claiming "Evil Twin" hot spots, networks set up by hackers to resemble legitimate hot-spots, present the "latest security threat" to Web users.

The hacker's wireless network jams the connection to the legitimate network by sending a stronger signal within close proximity to the wireless client and turns itself into an "Evil Twin".

"Evil twin hot spots present a hidden danger for Web users," explained Dr Phil Nobles, wireless Internet and cybercrime academic. "Because wireless networks are based on radio signals they can be easily detected by unauthorised users tuning into the same frequency."

Once an unknowing user has connected to an evil twin, a hacker can intercept transmitted data. Users are invited to log into the evil twin with bogus login prompts and can be lured into passing sensitive data such as user names and passwords.

"Users can also protect themselves by ensuring that their Wi-Fi device has its security measures activated because in the vast majority of cases base stations taken out of the box direct from the manufacturer are automatically configured in the least secure mode possible," said head of information systems professor Brian Collins.

Cranfield University believes this is a new area of cyber crime where more research is required. However, in October 2002, security company ISS published details of base-station cloning, otherwise known as an evil twin traffic interception. If true, this would mean that the idea is almost two-and-a-half years old.

In its 2002 document, ISS defines the technique as:

"BaseStation Clone (Evil Twin) intercept traffic -- An attacker can trick legitimate wireless clients to connect to the attacker's honeypot network by placing an unauthorised base station with a stronger signal within close proximity of the wireless clients that mimic a legitimate base station. This may cause unaware users to attempt to log into the attacker's honeypot servers. With false login prompts, the user unknowingly can give away sensitive data like passwords."

Nobles and Collins are set to give a talk on evil twins tonight at London's Science Museum.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 181 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Support Analyst

The position is based full time at our offices in the centre of Reading (right by the train station giving easy access to London and the M4 Corridor) ...

E-Science Centre, Science & Technology Facilities Council, Oxfordshire

The STFC e-Science Centre (http://www.escience.stfc.ac.uk/ ) focuses on the exploitation of e-Science technologies throughout STFCs programmes ...

SAP FICO OPPORTUNITY, UXBRIDGE

They have a base of 180 SAP FI Consultants throughout Scandinavia and continental Europe. With a team of 8 FI Consultants currently based in the UK, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment