On The Insider: Nicole Richie Home from the Hospital
BNET Business Network:
BNET
TechRepublic
ZDNet

August 2nd, 2007

Hamster plus Hotspot equals Web 2.0 meltdown!

Posted by George Ou @ 2:03 pm

Categories: Browsers, Desktop, Infrastructure, Mobile/Wireless, Networking, News, Security, Servers

Tags: Web, Google Gmail, HotSpot, Web 2.0, Attacker, Wi-Fi Hotspot, Wi-Fi, Tool, George Ou

In Focus » See more posts on: Black Hat

Robert Graham (CEO Errata Security) gave his Web 2.0 hijacking presentation to a packed audience at Black Hat 2007 today. The audience erupted with applause and laughter when Graham used his tools to hijack someone’s Gmail account during an unscripted demo. The victim in this case was using a typical unprotected Wi-Fi Hotspot and his Gmail account just popped on the large projection screen for 500 or so audience members to see. Of course had the poor chap read my blog about email security last week he might have avoided this embarrassment. But for the vast majority of people using Gmail or any other browser or “Web 2.0″ application, they’re all just a bunch of sheep waiting to be jacked by Graham’s latest exploit.

I caught up with Graham after the show and we went over more of the details of this Web hijacking exploit. First he captures the Wi-Fi signals using his laptop and a tool called Ferret which he wrote earlier this year. The tool grabs Cookies and Session IDs from your Web Browser session sent over the air and stores it.

Next, Graham fires up his new tool called Hamster (which he will post within the next week) which will process those Session IDs and Cookies so that they’re ready to clone.

Captured Session IDs and Cookies

Hamster hosts a local proxy server that allows point-n-click hijacking

The attacker can then go to his local Hamster proxy server to clone other people’s Web identities and hijack their Web accounts.=

Once the identity is cloned, the attacker is able to jump on to online services like Gmail masquerading as the victim with full access to read and send email on behalf of the victim. Furthermore, the attacker can go to maps.google.com and find the victim’s personal information like home address if it’s saved in to Google Maps.

I volunteered to set up an account on Gmail called “GetMeHacked” and allowed Graham to perform the attack. I then got a test email to Humphrey Cheung (Sr. Editor TGDaily) who was also watching the attack. Cheung posted his story here.

Before I knew it, I got hijacked and Graham sent an email on behalf of me.

What makes this even scarier is that Graham can go back in to my Gmail account for at least several more days using the same hijacked Session ID and Cookies. In fact he doesn’t even need to perform the hijacking immediately because he can record all the Wi-Fi Hotspot data and process it with Hamster at anytime before the Cookies expire. In one fell swoop the attacker can steal the identities of every Wi-Fi Hotspot user within a few hundred feet or a lot more if a larger antenna is used.

If you weren’t already scared of using public Wi-Fi Hotspots before, this should drive the point home. Graham even mentioned the dangers of Municipal Wi-Fi the use of Anonymous Secure Hotspots to solve this problem which I wrote about a few weeks ago. For the time being however, there isn’t much that can be done on the vast majority of Web 2.0 services. Gmail fortunately allows the user to manually force SSL mode which would solve this problem but unfortunately they don’t turn it on automatically for all users so the vast majority of users are wide open to session hijacking. For now, a user’s only effective solution is to use some sort of VPN gateway to encrypt all of their data but most people won’t do that. Tools like Hamster and Ferret will hopefully raise awareness and get the public to demand more secure Hotspots and SSL-enabled online services.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 74 Talkback(s)
RE: Hamster plus Hotspot equals Web 2.0 meltdown!
hey there bud, i really really need to hack into my girlfriends gmail account because i think she is cheating on me please i need your help!!!???
her gmail address is jhereas@gmail.com thank you... (Read the rest)
Posted by: quintin1989 Posted on: 07/12/08 You are currently: a Guest | | Terms of Use
This is why Windows sucks  NonZealot | 08/02/07
Do you have a brain?  croberts | 08/02/07
He forgot his sarcasm symbol  georgeou | 08/02/07
Huh?  Mikael_z | 08/03/07
That's why I used quotes for Web 2.0  georgeou | 08/03/07
You mean "Web 2.00" (as in Oh-Oh!")  critic-at-arms | 08/03/07
buzzwords  JetJaguar | 08/03/07
Buwahahaha.. you made my day.  kraterz | 08/03/07
Already ahead of you on that one  nucrash | 08/03/07
You need to read one of George Ou's earlier posts  maldain | 08/03/07
Thanks for that bit of information  nucrash | 08/03/07
You're kidding right?  Furiousrog | 08/03/07
Just noticed the IP  Furiousrog | 08/03/07
I could have been a little more obvious  nucrash | 08/03/07
RE: Already ahead of you on that one  joe6pack_z | 08/03/07
If you can exploit me at that IP  nucrash | 08/03/07
What's the...  zach.winchester | 08/06/07
re: Buwahahaha.. you made my day.  rregier@... | 08/03/07
How dare you force me to spit out my coffee  nucrash | 08/03/07
LOL, nice straw man, ZealotBoy  RealNonZealot | 08/03/07
Must have had his Dolt Cola today...  Marty R. Milette | 08/03/07
That was totally awesome NonZealot . I give you a 7 .  MythBuster | 08/04/07
They should be paying you  GW Mahoney | 08/02/07
There were 500 or so people packing that room  georgeou | 08/03/07
It was a Black Hat convention  GW Mahoney | 08/03/07
Ha!  GW Mahoney | 08/04/07
I dont have WI-FI router happy  mark.holman@... | 08/03/07
SSL Mode in Gmail  Mwendo | 08/03/07
Simple  nucrash | 08/03/07
Even simpler  aep528 | 08/03/07
Not so sure!  Martinraymond.qc | 08/03/07
You aren't forced to accept the certificate  nucrash | 08/03/07
Ha!Ha!  Martinraymond.qc | 08/03/07
Double Doh  nucrash | 08/03/07
Careful  Früv | 08/05/07
Yes! How?  theslaw | 08/05/07
Go to https://mail.google.com  georgeou | 08/05/07
what's wrong with VPN over wifi?  tecexec | 08/03/07
Er...  bmerc | 08/03/07
Actually, George addresses  Real World | 08/03/07
VPN is a good solution for Hotspots, but not practical for everyone  georgeou | 08/05/07
Windows Sucks?  TN-Limey | 08/03/07
Solution  TN-Limey | 08/03/07
Encryption  Xtien | 08/03/07
Isn't it funny ?  vbp1 | 08/03/07
I'm walking down the street...  schmutz@... | 08/03/07
Your confused. Its sad... i cried for you.  Been_Done_Before | 08/03/07
Funny, but it doesn't make windows suck less  comp_indiana | 08/03/07
It doesn't make Windows suck more either  nucrash | 08/03/07
sssh Now you can't say that...  fr0thy2. | 08/03/07
If Windows is so bad..  nucrash | 08/03/07
I'm not so sure about that  clb1017 | 08/03/07
Maybe/maybe not time and market will tell...  fr0thy2. | 08/03/07
a few questions  JetJaguar | 08/03/07
are my questions THAT stupid, really?  JetJaguar | 08/03/07
All browser apps that don't use SSL and all Hotspots  georgeou | 08/03/07
You are right, the problem is the mix...  MV_z | 08/03/07
on the 'Hamster'  dawgit | 08/03/07
You just need an end-to-end solution  Old Timer 8080 | 08/03/07
Here's a potential solution  drahardja | 08/03/07
SERVER HACKED AT BLACKHAT! by Matrix Systems & Technologies Inc.  help@... | 08/03/07
"Looks like a Prom Date" -oversite '08  RobeTirm@... | 08/04/07
This is not a game this is criminal intent and should be prosecuted  ralphrides | 08/04/07
Criminal Intent  jjmcdonald7911@... | 08/07/07
Wow, how Conservative of you  Grausam | 08/07/07
Wireless Network Design Problem  wwwsupport | 08/06/07
There's that SSL requires hardware myth again  georgeou | 08/06/07
Wi-Fi Hotspots should use Anonymous Link-layer security  georgeou | 08/06/07
Wondered how long it would take for a WiFi data snarf  shoktai@... | 08/09/07
EMail Security via Wi-Fi  RayG314 | 08/10/07
Free Wi-Fi security for Public Wi-Fi Access  wifi | 08/13/07
Amazingports  sankalp1234 | 08/29/07
Go ahead and look at my gmail account  John Musbach | 01/31/08
RE: Hamster plus Hotspot equals Web 2.0 meltdown!  quintin1989 | 07/12/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    Meet Doc