Download Going the Distance Movie Download R U There Movie Download The River Murders Movie Download Detective Dee and the Mystery of the Phantom Flame Movie Download Beer Wars Movie Download Mother and Child Movie Download Love at First Hiccup Movie Download When in Rome Movie Download Valentine's Day Movie Download Airline Disaster Movie Download Monogamy Movie Download Lucky Fritz Movie Download Autograph Movie Download Eddie Izzard: Live from Wembley Movie Download Gentlemen Broncos Movie Download Beautiful Boy Movie Download Burke and Hare Movie Download Dear Mr. Gacy Movie Download Armless Movie Download Life During Wartime Movie Download Red Riding: In the Year of Our Lord 1974 Movie Download Halloween II Movie Download Au revoir Taipei Movie Download Letters to Juliet Movie Download Larry Crowne Movie Download 7 Aum Arivu Movie Download The Man Next Door Movie Download Neighbor Movie Download Hitting the Nuts Movie Download The Human Resources Manager Movie Download Hurricane in the Rose Garden Movie Download How to Train Your Dragon Movie Download Yeh Saali Zindagi Movie Download You to Me Are Everything Movie Download Little Sparrows Movie Download Taken in Broad Daylight Movie Download Blessed and Cursed Movie Download Stock Shock Movie Download GasHole Movie Download Stay Cool Movie Download Cropsey Movie Download Kicking the Dog Movie Download This Is It Movie Download The House of Branching Love Movie Download Bass Ackwards Movie Download Brighton Rock Movie Download (Untitled) Movie Download The Killing Room Movie Download Hit Parade Movie Download Help Movie Download Waste Land Movie Download 15 Till Midnight Movie Download Immigration Tango Movie Download Shadows & Lies Movie

On iPhone, beware of that AT&T Wi-Fi hot spot

A security researcher has discovered that any wireless network can pretend to be an AT&T Wi-Fi hot spot and thus lure unsuspecting iPhone users to an untrusted network connection.

Samy Kamkar, who created a worm that garnered him a million friends on MySpace overnight in 2005, said in an interview this week that he can hijack any iPhone within Wi-Fi range in what is often dubbed a “man-in-the-middle” attack because of the way the devices are configured to recognize AT&T Wi-Fi connections merely by the name “attwifi.”

Typically, an iPhone will look for a specific MAC address–the unique identifier for the router–to verify that the wireless network is a device a user agreed to join previously. However, if the iPhone has previously connected to any one of the numerous free AT&T Wi-Fi hot spots (offered at virtually every Starbucks in the U.S., for example) the device will ignore what the MAC address says and simply connect to the network if it has “AT&T Wifi” attached, Kamkar said.

“The iPhone joins the network by name with no other form of authentication,” he said.

Kamkar said he made this discovery recently when he was at a Starbucks and disconnected from the AT&T Wi-Fi network.

“I went into the settings to disconnect and the prompt was different from normal,” he said. “I went home and had my computer pretend to be an AT&T hot spot just by the name and my iPhone continued to connect to it. I saw one or two other iPhones hop onto the network, too, going through my laptop computer. I could redirect them, steal credentials as they go to Web sites,” among other stealth moves, if he had wanted to.

To prove that a hijack is possible, Kamkar wrote a program that displays messages and can make other modifications when someone is attempting to use the Google Maps program on an iPhone that has been intercepted. He will be releasing his hijacking program via his Twitter account: http://twitter.com/samykamkar.

Kamkar hasn’t attempted the hijack on an iPod Touch, but plans to determine whether it has the same vulnerability.

iPhone users can protect themselves by disabling their Wi-Fi, or they can turn off the automatic joining of the AT&T Wi-Fi network, but only if the device is within range of an existing AT&T hot spot, Kamkar said.

Asked for comment an Apple spokeswoman said: “iPhone performs properly as a Wi-Fi device to automatically join known networks. Customers can also choose to select to ‘Forget This Network’ after using a hot spot so the iPhone doesn’t join another network of the same name automatically.”

Kamkar, an independent researcher based in Los Angeles, first made a name for himself by launching what was called the “Samy” worm on MySpace in order to see how quickly he could get friends on the social-networking site. The cross-site scripting (XSS) worm displayed the words “Samy is my hero” on a victim’s profile and when others viewed the page they were infected.

He served three years of probation under a plea agreement reached in early 2007 for releasing the worm.

No Tags

 

Leave a Reply

 
  • la ink 04x01
  • hp support driver downloads
  • sister
  • vince young jersey texas
  • battleship 3d game
  • mtv 2 schedule
  • bengals new uniforms 2012
  • raven
  • dis quand reviendras-tu
  • la ink price list
  • mtv rivals
  • mtv true life
  • bengals undraftedbengals vs steelers
  • chicago bears 4th phase
  • aegis
  • la ink bam margera
  • cage
  • bengals kids jersey
  • cspan ap government review
  • search engines for jobs
  • chad ochocinco celebrationschad ochocinco dating
  • mtv website
  • hp support error 1005
  • di's hallmark
  • c span youtube obama
  • greg olsen mormon
  • underware
  • trinity
  • toward
  • chicago bears 09 draft
  • hp support venezuela
  • freida pinto miral
  • mtv oddities
  • bengals hard knocks episode 1
  • bear gryllsbea hive dance studio
  • bengals qb situation
  • connecticut quarry
  • dis boards cruise
  • mtv 5 cover
  • greg olsen university of miami
  • auditions
  • chad ochocinco sisterchad ochocinco twitter
  • heaven
  • stimulation
  • battleship yamato wreck
  • chicago bears football club
  • freida pinto boyfriend
  • nickel
  • hp support contact number
  • greg olsen combine
  • la ink jabberwocky
  • new england patriots espn blog
  • new england patriots 07
  • hp support number united states
  • search engines 9
  • freida pinto can't act
  • chicago bears 2009 roster
  • zara phillips and the queen
  • chicago bears garter
  • chicago bears 61
  • bikes
  • measurements
  • chasis
  • bea zuberbühler
  • hp support chat
  • la ink bob tyrrell
  • armrest
  • 1975
  • chad ochocinco to patriots
  • search xml file
  • chad ochocinco height and weight
  • hp support quick test pro
  • connecticut education
  • suisse
  • dis poem
  • bengals record 2010
  • randy moss wonderlic
  • search vim
  • chad ochocinco traded
  • bea luna
  • moments
  • chad ochocinco stats
  • search and seizure
  • greg olsen puzzles
  • search google cache
  • environment
  • chad ochocinco quotes video
  • bea 71 16
  • performer
  • trunk
  • bea oracle
  • gt500
  • cspan hosts
  • hp support helpline
  • fairing
  • connecticut juvenile training schoolconnecticut kids
  • battleship hacked
  • new england patriots 50
  • objects
  • la ink book an appointment
  • tea party for kids
  • chad ochocinco career stats
  • reagan
  • chad ochocinco ultimate catch cast
  • dis pater
  • search engines no follow
  • discjuggler
  • search chuck norris
  • randy moss college
  • chad ochocinco wedding date
  • stanton
  • bengals forum
  • la ink season 6
  • dis x
  • la ink phone number
  • vince young usc
  • innovations
  • mtv 90s music videos
  • connecticut 97.7connecticut attorney general
  • search engines and flash
  • tea party ribbons
  • battleship wilmington nc
  • bea 71 series staples
  • randy moss arrested
  • bengals youth jerseys
  • difficult
  • zara phillips wedding date
  • tuesdays
  • 1978
  • searchbugsearch engines
  • tea party birthday
  • search domains
  • brat
  • chicago bears expo 2011
  • hartwig
  • method
  • vince young rumors
  • chicago bears tattoos
  • mtv music awards
  • bengals images
  • pendant
  • la ink members
  • hp support error 1005
  • chad ochocinco to detroit
  • search engines of the world
  • bea per capita income
  • chad ochocinco age
  • chad ochocinco 15
  • pentium
  • ruler
  • cspan presidents
  • chicago bears donation request
  • zara phillips wedding hat
  • mtv jams
  • greg olsen vancouver
  • zara phillips wedding plans
  • chicago bears 08 record
  • cspan facebook
  • bea goldfishberg
  • search engines internet
  • bea 00037
  • greater
  • vince young quiz
  • chicago bears media relations
  • bea 4603
  • chad ochocinco quits football
  • connecticut sun
  • zara phillips baby
  • connecticut transit
  • chad ochocinco bears
  • ever
  • hp support greece
  • vince young yahoo stats
  • connecticut lottery
  • vince young endorsementsvince young foundation
  • freida pinto chanel
  • battleship aurora
  • bengals cheerleaders tryouts 2011
  • la ink cast
  • bea binene
  • vince young stats
  • bea taylor
  • vince young drunk
  • mtv 25 lame
  • evaluation
  • bea rims
  • connecticut quarter error
  • la ink 2011 season 5
  • idiot
  • zinc
  • la ink 3rd season
  • connecticut 104.1
  • vince young yahoo stats