+ Reply to Thread
Results 1 to 1 of 1

Windows 7 Forum

How Wi-Fi attackers poison browsers

Fix and Repair Windows 7

  1. #1
    reghakr's Avatar
    reghakr is online now Tier 2 Moderator Valued Contributor reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute
    Join Date
    Jan 2009
    Posts
    9,338
    My Mood
    Mellow
    Rep Power
    1777


    Did you find this post helpful? Yes | No

    How Wi-Fi attackers poison browsers

    Public Wi-Fi networks such as those in coffee shops and airports present a bigger security threat than ever to computer users because attackers can intercede over wireless to “poison” users’ browser caches in order to present fake Web pages or even steal data at a later time.

    That’s according to a security researcher, developer of the Kismet wireless network detector and intrusion-detection system, who spoke at the Black Hat conference. He said it is simple for an attacker over an 802.11 wireless network to take control of a Web browser cache by hijacking a common JavaScript file, for example.

    "Once you’ve left Starbucks, you’re owned. I own your cache-control header,” he said. “You’re still loading the cache JavaScript when you go back to work.”

    Open networks have no client protection,” said the researcher, who also uses the handle Dragorn. “Nothing stops us from spoofing the [wireless access point] and talking directly to the client,” the user’s Wi-Fi-enabled device. Knowledge gained from researchers over the past year, he said, is showing that browser-cache poisoning over Wi-Fi can be kept in a persistent state unless the user knows how to effectively empty the cache. “Once the cache is poisoned, it’s going to stay there,” the researcher said.

    This means that an attacker can intercede to “poison the URL” of the victim so that he will see a fake Web page when they try to visit a specific Web site or try to insert a “shim” that could “ship your internal pages off to a remote server once you’re in a VPN.”

    More..............http://www.pcworld.com/article/188614/how_wifi_attackers_poison_browsers.html
    Last edited by reghakr; 02-09-2010 at 04:02 PM.
    New gold bowtie with trunk
    release in the glovebox.
    Pinstriping around bowtie is next.



+ Reply to Thread

Similar Threads

  1. How Wi-Fi attackers are poisoning web
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 02-05-2010, 01:01 PM
  2. Attackers conceal exploit sites with Twitter API
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 11-12-2009, 11:43 AM
  3. Replies: 0
    Last Post: 11-02-2009, 11:03 AM
  4. Scareware sellers poison 'iPhone MMS' search results
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 09-29-2009, 10:59 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Microsoft Partner Network