Showing posts with label Wi-Fi. Show all posts
Showing posts with label Wi-Fi. Show all posts

Friday, July 11, 2014

Keylogger Malware Found in Hotel Business Centers

The NCCIC and the USSS North Texas Electronic Crimes Task Force recommend that hotel managers, owners and other hospitality industry stakeholders consider the following.
 

Contacting your network administrator to request that:
• A banner be displayed to users when logging onto business center computers; this should include warnings that highlight the risks of using publicly accessible machines.

• Individual unique log on credentials be generated for access to both business center computers and Wi-Fi; this may deter individuals who are not guests from logging in.
• All accounts be given least privilege accesses; for example, guests logging in with the supplied user ID and password should not be able to download, install, uninstall, or save files whereas one authorized employee may have a need for those privileges to carry out daily duties. 

• Virtual local area networks (VLANs) are made available for all users, which will inhibit attackers from using their computer to imitate the hotel’s main server.
• All new devices are scanned (e.g. USB drives and other removable media) before they are attached to the computer and network; disabling the Auto run feature will also prevent removable media from opening automatically.
• Predetermined time limits are established for active and non-active guest and employee sessions.
• Safe defaults are selected in the browsers available on the business center desktops (e.g. Internet Explorer, Mozilla Firefox). Options such as private browsing and ‘do not track’ for passwords and websites are some of the many available.

Any questions regarding this advisory can be directed to the United States Secret Service North Texas Electronic Crimes Task Force at (972) 868-3200

Wednesday, April 23, 2014

Conversnitch Brings New Meaning to... "A little bird told me."

As former NSA director Michael Hayden learned on an Amtrak train last year, anyone with a smartphone instantly can become a livetweeting snoop. Now a whole crowd of amateur eavesdroppers could be as close as the nearest light fixture.



Two artists have revealed Conversnitch, a device they built for less than $100 that resembles a lightbulb or lamp and surreptitiously listens in on nearby conversations and posts snippets of transcribed audio to Twitter. Kyle McDonald and Brian House say they hope to raise questions about the nature of public and private spaces in an era when anything can be broadcast by ubiquitous, Internet-connected listening devices...

The surveillance gadget they unveiled Wednesday is constructed from little more than a Raspberry Pi miniature computer, a microphone, an LED and a plastic flower pot. It screws into and draws power from any standard bulb socket. Then it uploads captured audio via the nearest open Wi-Fi network to Amazon’s Mechanical Turk crowdsourcing platform, which McDonald and House pay small fees to transcribe the audio and post lines of conversation to Conversnitch’s Twitter account. “This is stuff you can buy and have running in a few hours,” says McDonald, a 28-year-old adjunct professor at the Interactive Telecommunications Program at the Tisch School of the Arts. (more)

Saturday, April 12, 2014

In-Flight Wi-Fi: Privacy Going GoGoing Gone

The NSA is harvesting the online data of millions of airline passengers who use inflight WiFi across the U.S., a secret letter has revealed.

Gogo, the main supplier of WiFi to airlines in the U.S., are among a host of network providers that have been handing over information gleaned from air travelers' browsing history.


The news has enraged privacy campaigners who say the data exchange may be in violation of U.S. law.

A letter, leaked to Wired, Gogo admitted violating the Communications Assistance for Law Enforcement Act (CALEA) - a 1994 wiretapping law that gave a backdoor to government agencies to monitor telecom and broadband activity.

But Gogo states in the letter that it added a raft of new measures to its service that made spying on users easier for the authorities. (more)

Saturday, February 22, 2014

Security Director Alert - New Audio & Video Bug. Records and Stores 24-hours. Blasts it out via Wi-Fi in 5-minutes.

This is the new eavesdropping technology you are up against. 


• Do you conduct regular information security surveys (TSCM)? 
• Are your current current TSCM bug sweeps capable of detecting new technologies like the device shown?
If the answer to either question is no, contact me.

via Acustek...
The concept of the GEM AUDIO/VIDEO is... storing audio and video files on micro-SD card up to 32 GB and then forward, ultra-fast download, through protected WiFi connection.

DESIGNED FOR COVERT USE 

The GEM WiFi A/V is a small device integrating a small powerful audio-video recorder, external miniature video camera and concealed built-in Wifi antenna for transmission together. This allows the user ultra fast download of large volumes of high quality audio and video without the need of direct connection with the recorder. It can be set up to record with multiple advanced timers or by voice activation mode. The supplied video camera is capable to provide good quality picture at very low light conditions, with sensitivity of .3lux.

HIGH AUTONOMY AND CAPACITY All audio records are stored to micro SD memory (up-to 32Gb) and can be downloaded at any time, or listened to "Live".

ULTRA FAST DOWNLOAD SPEED Downloading over WiFi is very fast and takes approx. 5 minutes for every 24 hours stored audio record.

DEDICATED FOR CONCEALED OPERATION All records are exported or reviewed securely via the included software. GEM WiFi doesn't transmit anything on air when disconnected from the host computer. It searches for the WiFi signal only from user host computer; this makes this device very confidential and makes it virtually impossible to find by any WiFi wireless spy detection technology such as RF Analysers. (We know how to find it.) 


SECURITY The audio data transfer is encrypted, each record has a precision timeline and can only be reviewed using the supplied software, the records may also be password protected. If the recorder is intercepted then the micro SD card is unusable. (more)

Sunday, February 9, 2014

TSCM Find - Police Ombudsman Headquarters' Conference Room & Wi-Fi Bugged

Ireland - The headquarters of the Garda Ombudsman Commission has reportedly been targeted by a secret bugging operation. 

According to a report in today's Sunday Times, the watchdog's phone and internet were compromised in a highly sophisticated hacking incident...

The spying operation was uncovered when the Ombudsman hired security consultants to investigate whether its office had been bugged.
The investigation found that a phone in a meeting room had been rigged to eavesdrop on confidential conversations.

The room was used to hold case conferences related to investigations being carried out by the commission.

The Wi-Fi network at the Garda Ombudsman office had also been hacked - allowing emails and confidential material to be intercepted. (more)


UPDATE:
Mr Shatter has asked the Commission for a report on its decision to hire a British Security company last year to investigate if it had been placed under electronic surveillance.

A source within GSOC has confirmed to RTÉ that the company told it that it had found evidence of electronic surveillance in one of its meeting rooms and that its wi-fi system may have been compromised. (more)

Sunday, November 10, 2013

Seattle, where a java junkie hanging on a light pole won't be alone.

If you're walking around downtown Seattle, look up: You'll see off-white boxes, each one about a foot tall with vertical antennae, attached to utility poles. If you're walking around downtown while looking at a smartphone, you will probably see at least one—and more likely two or three—Wi-Fi networks named after intersections: "4th&Seneca," "4th&Union," "4th&University," and so on.

That is how you can see the Seattle Police Department's new wireless mesh network, bought from a California-based company called Aruba Networks, whose clients include the Department of Defense, school districts in Canada, oil-mining interests in China, and telecommunications companies in Saudi Arabia.

The question is: How well can this mesh network see you? (more)

Sunday, November 3, 2013

When Paranoids Collide they Blow the Whistle on Tea Kettles

Customs agents in Russia found tea kettles and irons bugged with tiny Spyware chips that exploit WiFi connections, reports a local news outlet coming out of St. Petersburg.

According to Gizmodo, the microchips are capable of spreading spam and malware to WiFi-enabled devices within 200 meters.  Specific details of the dodgy shipments remain shady...

Simon Sharwood of The Register reports that it is indeed possible to build a spambot small enough to fit inside of a kettle, as the necessary components are small and cheap enough...


One question remains unanswered, however: why would China send bugged tea kettles to spy on the ordinary tea-drinkers of Russia?

Gizmodo suggests that perhaps local authorities were mistaken about their findings, pointing out that WiFi tea kettles already exist.

Business Insider speculates that if the kettles are bugged, it could very well be a test for larger operations to plant such microchips.

We'll let you weave your own intricate conspiracy theory. (more)

Thursday, July 4, 2013

How to Use Public Wi-Fi More Securely

via Eric Geier, PCWorld
  • Every time you log in to a website, make sure that your connection is encrypted. The URL address should start with https instead of http.
  • You also need to make sure that the connection stays encrypted for all of your online session. Some websites, including Facebook, will encrypt your log-in and then return you to an unsecured session—leaving you vulnerable to hijacking, as discussed earlier.
  • Many sites give you the option of encrypting your entire session. You can do this with Facebook by enabling Secure Browsing in the Security settings.
  • When you check your email, try to login via the Web browser and ensure that your connection is encrypted (again, look for https at the beginning of the URL). If you use an email client such as Outlook, make sure your POP3 or IMAP and SMTP accounts are configured with encryption turned on.
  • Never use FTP or other services that aren’t encrypted.
  • To encrypt your Web browsing and all other online activity, use a VPN, or virtual private network (this article will show you how).
  • Keep in mind that private networks have similar vulnerabilities: Anyone nearby can eavesdrop on the network. Enabling WPA or WPA2 security will encrypt the Wi-Fi traffic, obscuring the actual communications, but anyone who also has that password will be able to snoop on the packets traveling over the network. This is particularly important for small businesses that don’t use the enterprise (802.1X) mode of WPA or WPA2 security that prevents user-to-user eavesdropping. (more)

Monday, July 1, 2013

Wi-Vi Sees Movement Behind Walls Using Cheap Wi-Fi Tech

A new system allows researchers to track up to three separate people through a wall, solely with the help of low-power Wi-Fi signals.

The Wi-Vi system relies on two antennas to broadcast Wi-Fi signals and a receiver to read them, according to the researchers’ paper. The Wi-Fi signals degrade in quality each time they pass through a wall, so the receiver must be prepared to pick up on very weak signals. It is also quickly overwhelmed if there are too many to sort through...


 
Researchers think the Wi-Vi system could also be used to find survivors in destroyed buildings or count and track criminals. Compared to previous military-oriented tracking systems, Wi-Vi is cheap, compact and lightweight, which makes it practical for consumer uses such as personal safety. (more)

Thursday, May 16, 2013

Retailers sniffing cell phone Wi-Fi signals at the mall... and future uses.

Technology that allows retailers to track the movement of shoppers by harvesting Wi-Fi signals within their stores is spreading rapidly. 

Giant U.S. retailers including Nordstrom and Home Depot are already using it, as does one of the most popular malls in Singapore. Indeed, Euclid Analytics, one of the better-known companies selling the technology, boasts that it has tracked some 50 million devices in 4,000 locations. (more)

Also, check out Y-Find and TheRetailHQ.

So who cares if Home Depot knows what aisle you are in?

Think ahead...

"We are excited to be working with YFind to help them realize their vision of creating Location-Intelligent cities..." Pete Bonee, Partner at Innosight Ventures


Cities!?!?  
WTF? 
Oh, right. 
The government marketplace is huge, worldwide even.

Sunday, March 31, 2013

Digital Cameras Easily Turned into Spying Devices

Newer cameras increasingly sport built-in Wi-Fi capabilities or allow users to add SD cards to achieve them in order to be able to upload and share photos and videos as soon as they take them.

But, as proven by Daniel Mende and Pascal Turbing, security researchers... these capabilities also have security flaws that can be easily exploited for turning these cameras into spying devices.

Mende and Turbing chose to compromise Canon's EOS-1D X DSLR camera an exploit each of the four ways it can communicate with a network. Not only have they been able to hijack the information sent from the camera, but have also managed to gain complete control of it. ...like uploading porn to the camera, or turning it into a surveillance device. (more) (video presentation - long and boring)


Solution in a nutshell... Before purchasing any Wi-Fi enabled device, make sure it supports encryption.

Thursday, March 14, 2013

Pwn Pad - Use it IT, Before it is used against IT

The folks at security tools company Pwnie Express have built a tablet that can bash the heck out of corporate networks. - Wired Magazine

The Pwn Pad - a commercial grade penetration testing tablet which provides professionals an unprecedented ease of use in evaluating wired and wireless networks.

The sleek form factor of the Pwn Pad makes it an ideal product choice when on the road or conducting a company or agency walk-through. This highspeed, lightweight device, featuring extended battery life and 7” of screen real estate offers pentesters an alternative never known before. (more)

TOOLKIT INCLUDES:
Wireless Tools
Aircrack-ng
Kismet
Wifite-2
Reaver
MDK3
EAPeak
Asleap-2.2
FreeRADIUS-WPE
Hostapd
Bluetooth Tools:
bluez-utils
btscanner
bluelog
Ubertooth tools Web Tools
Nikto
Wa3f Network Tools
NET-SNMP
Nmap
Netcat
Cryptcat
Hping3
Macchanger
Tcpdump
Tshark
Ngrep
Dsniff
Ettercap-ng 7.5.3
SSLstrip v9
Hamster and Ferret
Metasploit 4
SET
Easy-Creds v3.7.3
John (JTR)
Hydra
Medusa 2.1.1
Pyrit
Scapy


Tuesday, December 18, 2012

Top 5 Wireless Tips for IT Pros

via Altius IT Information Security...

Listed below are the top 5 tips IT professionals should take to enhance wireless network security.

1. Encryption. There are many different types of encryption methods used to secure wireless networks. Wired Equivalent Privacy (WEP) is the oldest and least preferred. Wi-Fi Protected Access (WPA) is newer and offers better protection. WPA2 is the newest and should be used if possible. Configure Virtual Private Network (VPN) access for users connecting to corporate systems.

2. Firewalls. Segment the wireless network from your in-house wired network. Use firewalls to restrict traffic to and from the internal network. Configure user devices so firewalls are turned on and actively protect applications and data.

3. Manual connection. Configure portable devices such as laptops and handhelds so that they do not automatically connect to wireless networks. A manual process helps ensure that the device connects to the appropriate wireless network.

4. Patch management.
Ensure device operating system, application, and security protection software is patched and up-to-date. Ensure browsers and updates to third party software packages are applied in a timely manner. Critical updates should be tested and applied as soon as possible.

5. Incident management. Prepare a formal Incident Response Plan and educate users to inform the appropriate personnel if they believe they logged into the wrong network, sensitive information such as their ID/password was compromised, their device was lost or stolen, etc. (more)

Thursday, November 15, 2012

Scientific Breakthrough Gives Paranoids Another Thing to Worry About

Click to enlarge.
A tiny ear-powered device extracts energy from an ear and transmits information wirelessly to a nearby radio. (more)

Sunday, October 21, 2012

$89.99 Wi-Fi Bug You Control With Your iPhone... from anywhere!

"WeMo Baby conveniently turns your iPad, iPhone, or iPod touch into a baby monitor so you don't have to carry an extra device to keep in touch with your baby. 

It works with your existing Wi-Fi router to wirelessly stream audio from your baby's room to your mobile device." (more)

Why is this scary?
• It will be repackaged into a covert listening device.
• Unlike previous baby-mon mods, this one is digital.
• Its signal hides among legitimate Wi-Fi signals.
• Listen in from anywhere via the Internet.
• Digitally clear audio.
• Pair with a voice activated recorder for "TiVO" spying.
• It can send text messages when it hears audio.

P.S. Although this product hasn't launched yet, Murray Associates has a detection solution ready. ~Kevin

Saturday, September 8, 2012

Intercepting Unencrypted WiFi Not Wiretapping

A federal judge in Illinois has ruled that intercepting traffic on unencrypted WiFi networks is not wiretapping. The decision runs counter to a 2011 decision that suggested Google may have violated the law when its Street View cars intercepted fragments of traffic from open WiFi networks around the country.


The ruling is a preliminary step in a larger patent trolling case. A company called Innovatio IP Ventures has accused various "hotels, coffee shops, restaurants, supermarkets," and other businesses that offer WiFi service to the public of infringing 17 of its patents. Innovatio wanted to use packet sniffing gear to gather WiFi traffic for use as evidence in the case. It planned to immediately delete the contents of the packets, only keeping the headers. Still, the firm was concerned that doing so might violate federal privacy laws, so it sought a preliminary ruling on the question.

Federal law makes it illegal to intercept electronic communications, but it includes an important exception. It's not illegal to intercept communications "made through an electronic communication system that is configured so that such electronic communication is readily accessible to the general public." (more)

Saturday, July 28, 2012

Outdated Law Clouds Wi-Fi Eavesdropping Privacy Rights

If you don’t protect your Wi-Fi connection with a password, does that mean it’s legal to tap your Internet and monitor what you’re doing?

The key part of the federal anti-wiretap law was written in the 1980s, long before anyone contemplated using Wi-Fi networks, so the answer isn’t clear. In fact, legal experts say, it’s possible that how well you’re protected by the law would depend on what channel your Wi-Fi router is set to. (more) (spybusters link)

Sunday, May 27, 2012

Could this mean that you will never again hear a cellphone go off at a concert?

French researchers have developed wallpaper that would block cellular and wi-fi signals while letting through AM/FM radio waves and emergency transmissions.

Click to enlarge.
Developed by engineers at the Grenoble Institute of Technology and the Centre Technique du Papier—and making use of a conductive ink containing silver particles (it’s a passive block, not a jamming system)—the wallpaper will be marketed to people concerned about outsiders’ snooping on their private networks as well as those who, for health reasons, simply want to shield themselves from as many electromagnetic waves as possible. Researchers say the cost of the product will be in line with what people pay for mid-priced purely decorative wallpaper.

Windows remain a challenge, but even without covering them (and transparent filters do exist), users will enjoy substantial increases in privacy, the researchers say. (more)

Tip: Need a compact VHF/UHF TV antenna? Check out Mohu Leaf, another invention which incorporates fractals into antenna design. We're not entirely sure why, but fractal antennas work. Trust nature's designs.

Thursday, May 24, 2012

Bugs found at Russian cultural center in Estonia

Estonia - A wiretapping device has been found in a cultural center for Russian-speaking Estonian citizens in Tallinn. The NGO is run by the mother of the city’s vice mayor, who is suspected of lobbying for Russian interests in the Baltic country.

The wiretap, discovered Tuesday, is the second such device found in the Lira cultural and sports center, after a thorough inspection carried out by center’s security.

The first eavesdropping device, which was clumsily wired into the facility’s alarm system, was found on May 15. Inspectors believe the bugs were installed between September and December 2011. The police opened an investigation but so far no official statements have been made on the issue. (more)

Sunday, April 1, 2012

Think Your Intellectual Property is not Worth a few Bucks to Protect? Think Again.

Australia - The Federal Government has described a multi-million-dollar legal settlement over CSIRO's wi-fi technology as a major boost for the organisation.

The settlement secures more than $220 million for CSIRO, which invented the technology in the 1990s.

Wi-fi technology is used in more than 3 billion electronic devices worldwide, including personal computers, video games and mobile phones.

The settlement is the second successful litigation to be conducted by the CSIRO, which patented the technology and now has licence agreements with 23 telecommunications companies. (more)

FutureWatch: You may not know now what your ideas will be worth further down the road. Hook up with a good counterespionage consultant today. No matter where in the world you are, we can recommend someone we know personally to you.