BrokeBerry

Attack Computer Wiz

A Security & Technology Weblog
Showing posts with label Wireless. Show all posts

Last week I was working in my yard when the meter reader stopped by to read my power meter. I apologized to him of the excess pile of toys that he had to navigate through to get to my meter. He told me that it was alright and it won’t be much longer and I will be fitted with a ‘Smart Meter’ that will transfer all of my meter data wirelessly.

My security hat immediately came on and I decided I would do some research and try to determine how a ‘Smart Meter’ worked. After about an hour of research it was pretty clear that they keep that information quite guarded, go figure.
Today though I was happy to find a story on Yahoo that addressed the concerns that I had and as it turns out these ‘Smart Meters’ have some gaping security issues, again, go figure.

The meters themselves are supposed to save money. They save the power company money by not having to send people out and read the meter and they save the consumer money by giving you a real time, anytime, view of your power consumption allowing you to adjust accordingly.

But according to Joshua Wright (no relation) a Senior Analyst with InGauardians Inc., there are “egregious” flaws in the meters and the technology that the utility companies are incorporating to handle the data from the meters.

Wright found security issues with five meters, each from different manufacturers. The security holes could lead to a hacker being able to intercept the encryption keys used by the meter to communicate with the access points that collect the meter information.

He discovered that a hacker may be able to change the usage reported to the access points raising a victim’s power bill or lowering it, depending on the shade of hacker. Wright said that while the technology of the meters is new, some of the security vulnerabilities he discovered have been around for 10 years.
While I do look forward to the ability to see my real-time usage I will be keeping tabs on this service in the same manner I do my credit card bill and would encourage everyone else to do the same.

Source: Yahoo!

user Posted by Mike Wright

| More


AT&T announced today that it will be making its MicroCell technology available in mid-April. If you are not familiar, MicroCell is similar to a wireless router for your home that acts like a mini cellular repeater. With this device installed your AT&T signal will be boosted limiting dropped calls and raising the ‘bars’.

You will be able to customize the device to lock in only phones that you authorize and you can make a call within your MicroCell and move to the normal AT&T network. But you cannot move the other direction; making a call on the AT&T network and moving to your MicroCell.

Other downsides to this offering is; the need to purchase additional equipment at the estimated price of $150. There is an additional $20 per month, which is optional for an unlimited MicroCell plan. And the need for a high speed internet connection like DSL and not like satellite.

I wonder if AT&T has hired Steve Jobs as it seems they have taken a page right out of the Apple business model. Why not create a way for a device to use an existing wireless router in an existing wireless network. I know that my Verizon BlackBerry can already connect to my home wireless network so it seems only logical that Voice Over IP (VOIP) is only a simple application away.. Don’t they “have an app for that”?

Yahoo News

user Posted by Mike Wright

| More


Albert Gonzalez, the convicted ring leader of the group of hackers that stole nearly 130 million credit card numbers from T.J. Maxx and other businesses, may be looking at 25 years in federal prison for his deeds.

If imposed, this sentence would be the longest ever for an identity theft case. Some interesting facts about this case are;

  • Gonzalez has been linked to not only the TJX case but also hacks at Office Max, Dave and Busters, 7-Eleven, Heartland, BJ’s Wholesale, DSW, and Hannaford.
  • He was going to use his money to buy a yacht and retire.
  • It took him two years from the time that he hacked 11 million account from Office Max to decrypt and discover the PIN numbers.
  • He was an information for the Secret Service during some of his crimes.
  • He was almost hacked himself by outside consultants during the TJX hacking (reminds me of the Kevin Mitnick story).
This guy is quite a piece of work, I especially love this quote from the document:
    “Gonzalez argues that he should not be held responsible because TJX, and by extension each of eight other corporate victims described in the Indictment, had sufficiently vulnerable computer networks and data protection that he and his organization could break in and steal payment card numbers.”

Government Brief courtesy of Wired

user Posted by Mike Wright

| More


By now most everyone is familiar with the recording breaking data theft that occurred at T.J. Maxx. Hackers used poorly secured wireless access points to intercept customer records. But big business is not the only and not the most common target of wireless hacking.

The hacking technique known as wardriving is the act of scanning for wireless access points, or networks, from a moving vehicle. With the right tools the hacker has the ability to see, record, log, and locate nearly any wireless access point. Once upon a time hackers would mark the curb or street where the access point was located so that they and their cohorts could locate it again, this was known as 'chalking'. However technology has changed this and finding wireless access is a simple mouse click away.

Wigle.net is an online repository of wireless access points located all over the world. From this site anyone can simply browse an interactive Google map and locate millions of wireless access points, according to their site 19,776,866 to be exact. The information from this site does not guarantee that a hacker will be able to gain access to the networks. But is does give the would-be wireless leach a good place to start looking.

In 2004, 100 students in Seattle Washington were able to locate 5,225 wireless access points in the Seattle area. Of those 52% of them were not configured with any security and were ‘open’ for anyone to connect to. (source)

While those numbers are outdated, it is still not uncommon to find a huge number of wireless networks that use no security or poor outdated security. The ‘out of the box’ configuration of most any wireless access points would allow a hacker to not only gain access to the wireless network, but gain access to devices on that network.

Once connected the hacker could be able to intercept any communications and data. They could inject malicious code, reconfigure devices, or deny the network owner access to their own network. They could intercept banking transactions, prescription and medical information, credit card information, Social Security Numbers, and anything else traveling across the network or even stored on computer in the network.

It is important that you not simply unpack that new wireless device and plug it in without reviewing the documentation and configuring the security mechanisms on the device. Stay away from the WEP security as it is outdated and is now easily hacked. WPA or preferably WPA-2 should be your first choice in 'out of the box' configuration of your wireless access points.

Beyond configuration of the devices, think about where you are going to place the device. Things like walls, trees, insulation and other solid objects will reduce the signal of the device making it harder for someone to connect from the street or sidewalk. It may be better to place your access point in the back of your house rather than the front of your house. Some devices come with two antennas, can you remove one antenna to reduce the signal while still getting access, maybe? And it is a great idea to change that administrator password that is printed in the documentation.

Go to Wigle.net and see if your access point is recorded on that site. If you live in a populated area, the odds are, it is.

user Posted by Mike Wright

| More