• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Ham And Scam Attack?

Joined
May 16, 2010
Messages
16
Is it possible for someone to jam a set of frequencies of certain network (or a set of ssids/networks they represent) yet allow others to connect to a rogue router, and then when a system does connect, listen as programs try to authenticate, giving up user names/passwords (possibly other important data)? Eg a man in the middle attack brought on by jamming or otherwise disabling a set if home networks? If go what is the risk to data loss?

Real life background: I had an old dentist office with an open network of Linksys and against password. I changed dentists in about a month ago. I never did disconnect this network. I woke up this morning about 4 AM with all my wireless networks on my xoom tablet in a 'disabled state' and could not force it to reconnect to any of 4 networks inn the house base on two separate routers, they all said 'disabled'. They run wpa2 on 2.4 and 5Ghz.

However it was connected to a fair single Linksys network, From of course a different Linksys Router but one with the same SSID and password. Of course after to see this I deleted the Linksys network and read tried to connect to my own networks, unsuccessfully. I even tried turning xoom wireless off and on. No dice.

About five minutes after disconnecting the Linksys network my own networks came back online, and I reconnected. The linksys network then disappeared. We live in a mid higher-class to middle-class tech savvy gated community (many networks, fiber optics, guards at gates 24/7.

What is the chance that this was an actual attack and they were able to somehow disable my network and default me on to the linksys where data was compromised (eg autologon to mail etc?) I have noticed this two times, the first I dismissed it. Is the consensus believe this was an actual attack, what data could have been compromised, Considering what they have on the wireless network Are two computers and two cell phone's and a tablet?

Is it even possible teaching somebody else's network, within reasonable time/effort constraints for a nobody target like me? What changes to other data and passwords is it worthwhile implementing?

Thank you. Detailed helpful responses are welcome.

HP
 
Last edited:
Well, if they were able to obtain your network's WPA key, then they could easily setup a 2nd AP, with the same SSID, password and network info. Your client would connect to whatever signal is best. This would not be difficult, if you had no password or were using an obvious password, it wouldn't even be hard to do.

Harder to do would be to jam your wireless signal. If we assume you have a dumb AP, which only operates on a single channel and doesn't change channels in response to interference, they could use some fairly expensive RF gear to send garbage on that channel, or easier, just setup their own AP on the same channel, and constantly transmit data, making your AP somewhat useless. That might make your client join their AP all the time.

At the point at which they could see your wireless traffic, they could sniff anything sent in clear text. Virtually 100% of banks and online shopping web sites are SSL protected, so they can't sniff data there. But if you're connecting to email via POP3 and sending clear text passwords, or other non-encrypted services, then this could work. If your email password or password for, lets say this forum, is the same as your amazon.com password, then you're in trouble.

WPA2 is difficult to crack, though there is a vulnerability in the WPS protocol, if you have that enabled.

How likely is all this? It is unlikely that someone targeted you specifically for financial gain. It is more likely that someone has a laptop with a yagi antenna and a set of scripts that looks for that WPS vulnerability, exploits it, and sets up a dummy network. Then they could drive around looking for places to exploit.

If I had to guess, I'd say your tablet is just messed up and you're jumping to conclusions..

But lets assume something like this is going on. How would you detect it or at least harden your network against this type of attack?
- Examine your existing APs
-- update to current firmware, check manufacturers web site for any known vulnerabilities, as previously mentioned, turn off WPS.
-- change your WPA2 password, and the password on your router and AP. WPA2 password should be random, NOT an english word or phrase, even if you substitute a digit for a letter.
- See what channels your APs are running under, record this information
- See what MAC address and BSSIDs your APs are using, use something like vistastumbler, again, write it down.
- Record your signal levels at various places around the house, make sure they make sense (higher signal closer to actual AP location, etc...) draw a map and write down signal levels.

Now wait, see if the problem reoccurs. If it does, verify everything you previously recorded. That's about it. If you suddenly see different BSSIDs or have fantastic signal close by to a public parking lot or something to that effect, then maybe something is really going on.

In a larger environment, you have multiple layers of protection. Passwords should never be sent in clear text over the network. If you have service you access that doesn't have SSL, ask them why, anything business related that deals with money or dentist data (hello HIPAA) really should be encrypted. Passwords should be different between various services. This is a pain, but necessary. Check your PCs for viruses or other malware which might be logging keystrokes or extracting WPA passkeys from the registry. It goes without saying that all your devices should be up to date on firmware, drivers, windows patches, firewall enabled and properly configured and anti-virus.

And FYI a gated community with 24/7 guards is not middle class. You're rich, and maybe that does make you a target, but again, I find this unlikely.
 
Back
Top