On CHOW: How to avoid dirty looks at cafes
BNET Business Network:
BNET
TechRepublic
ZDNet

August 6th, 2007

DEFCON 2007 - Wall of Sheep (shame)

Posted by George Ou @ 11:38 pm

Categories: Infrastructure, Mobile/Wireless, Networking, News, Security

Tags: Google Gmail, Wall, George Ou

It’s time to count sheep again and I don’t mean the ones in your sleep.  I’m talking about the ones on the Wi-Fi Hotspot that are using insecure protocols and getting their online accounts compromised.  What you’re looking at below is the DEFCON 15 Wall of Sheep.

What do I mean by compromised?  Usually that means username and passwords are being transmitted in the clear for anyone to see or it means your account can be hijacked such that an attacker can get in to your account anytime they want after they copy your online Web session.  In the above screen shot, a VERY large number of Gmail accounts that failed to use secure HTTPS (https://mail.google.com) were hijacked.  This is despite the fact that they logged in using HTTPS because Gmail by default automatically kicks you back in to HTTP mode.

The Wall of Sheep team hunts down the sheep in their command bunker

Robert Graham and David Maynor side-jacking sheep with Hamster

Learn how to protect your online privacy here.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 9 Talkback(s)
Already posted (link)
I think this is it:

http://www.erratasec.com/sidejacking.zip

I wasn't doubting that Robert had done this. I was say... (Read the rest)
Posted by: GW Mahoney Posted on: 08/09/07 You are currently: a Guest | | Terms of Use
Not good  GW Mahoney | 08/07/07
They were just doing their job of sploitin'  nucrash | 08/07/07
GMail, and millions will bennefit  TripleII | 08/07/07
Your obsession has to end  georgeou | 08/07/07
We're still waiting  Robert Crocker | 08/08/07
That was released back in March  georgeou | 08/08/07
You may not agree  GW Mahoney | 08/08/07
Again, this post has nothing to do with Maynor  georgeou | 08/08/07
Already posted (link)  GW Mahoney | 08/09/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here