Business Services Industry
AirDefense Discovers New Version of ''Evil Twin'' Attack at Interop 2005
Business Wire, May 10, 2005
ATLANTA -- AirDefense, the leader in anywhere, anytime wireless network security and monitoring today announced a mutated, malicious version of the "Evil Twin" attack was discovered last week while monitoring the airwaves of Interop 2005 in Las Vegas.
This newest Wi-Fi phishing attack is a more sophisticated version of an "Evil Twin" attack that propagated over the Internet in January. "Evil Twin", also known as access point (AP) phishing, is a technique whereby an attacker tricks victims into connecting to a laptop or PDA by posing as a legitimate hotspot. Once the user is connected, the user is coerced into downloading a series of custom written Trojans and viruses.
Related Results
As an example of this attack, AirDefense identified people spoofing "free_extreme," the free wireless access sponsored by Extreme Networks. Once unsuspecting attendees made a wireless connection, they received a false page with a mouse-activated web overlay. Any click of the attendees' mouse would trigger a downloading of viruses, regardless of where the attendees clicked on the Web page.
Richard Rushing, chief security officer for AirDefense, suspects the custom scripts were launched with a distinct purpose in mind. "Attackers are most interested in stealing user IDs and passwords to gain access to corporate networks," said Rushing.
Similar to email phishing or pharming, AP phishing is the manipulation of a wireless user. By presenting the user with a familiar scenario such as a login page to a hotspot, the user will readily provide his or her user ID and password. The attacker will then have the ability to exploit vulnerabilities or even add Trojans or viruses to the laptop, often without the user's knowledge.
AirDefense monitored the wireless traffic at Interop 2005 from the AirDefense booth, on the show floor, and at a mobile location inside the convention hall where people congregated at lunch, and before and after the keynotes. AirDefense tracked an overall increase in wireless usage from previous Interops, which coincided with an increase in wireless risks and attacks including:
--1,318 stations were probing for networks that were not represented at the show
--320 cases of MAC spoofing likely used for malicious activity
--172 scanning devices including Netstumbler and probing stations
--63 Denial of Service attacks
--44 authentication errors
--37 brute force attacks
--25 "Evil Twin" attacks
--16 AP phishing attempts
"Wireless has become pervasive and people were eager to get online during breaks in the conference," said Rushing. "However, users continue to neglect securing their devices and do not detect phishing scams or rogues connecting to them. These under the radar attacks are similar to the types of attacks occurring regularly on the enterprise level in government, healthcare, financial services and many other industries."
AirDefense recommends conference attendees register for hotspot use on a secure wired connection prior to using wireless. AirDefense also recommends attendees read all pop up windows in their entirety. AirDefense has made a free version of AirDefense Personal available to all wireless users for their laptops. AirDefense Personal will monitor for a variety of wireless risks, including Wi-Fi phishing and "Evil Twin" attacks. People can download AirDefense Personal at http://www.airdefense.net/products/adpersonal/.
> About AirDefense, Inc.AirDefense is the market leader in wireless network security and monitoring. The company provides the most advanced solutions for rogue wireless detection, policy enforcement and intrusion prevention both inside and outside an organization's four walls. AirDefense's enterprise-class products are the most comprehensive, integrated wireless security solution available, scaling to support single offices to organizations with hundreds of locations. Founded in 2001, AirDefense is based in Alpharetta, GA and services hundreds of government agencies and blue chip corporations. For more information, please visit http://www.airdefense.net or call 770.663.8115.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- LIFO vs. FIFO: a return to the basics
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Design a commission plan that drives sales - Sales Commissions


