Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow From the Duh Dept: Study Shows Hotel Wireless Insecure
Ethical Hacker Community Forums
December 01, 2008, 09:03:09 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: From the Duh Dept: Study Shows Hotel Wireless Insecure  (Read 1843 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: October 07, 2008, 11:36:48 AM »

So is it just me, or does this fit into one of those categories of useless spending on studies to prove what is common knowledge? Or is the general computing public really that naive about security still?

Quote

Study: Hotel network security lacking

Most U.S hotels are vulnerable to malicious attacks and are "ill prepared" to protect their guests from internet security problems, claims a study published by Cornell University.

The study, “Hotel Network Security: A Study of Computer Networks in U.S. Hotels” examined the security of 147  hotels through surveys, interviews and on-site testing.

“Many hotels have flaws in their network topology that allow for exploitation by malicious users, thereby resulting in the loss of privacy for guests,” the study says.

One of the study authors, Josh Ogle, a Cornell University graduate and founder of IT services company TriVesta, performed on-site testing at 46 hotels in Virginia, North Carolina, Texas, Maryland, Tennessee and Pennsylvania - making sure to hit both tourist and business travel destinations.

Ogle tested wireless networks at 38 hotels and wired networks at eight.  He found the majority were vulnerable to attacks.

“Out of the 38  wireless, I was able to break into 33,” Ogle told SCMagazineUS.com Monday. “And by break into I mean, accept data from someone else's computer that wasn't meant to be on mine.”

Ogle used the Linux distribution BackTrack, meant for network testing. In addition, following recommendations of hackers on vulnerability mailing list Full Disclosure, Ogle used a high-power wireless card and high-gain omnidirectional antenna to crack the networks. The setup cost less than $100, he said.

Ogle said using this method a hacker can see all unencrypted information coming into and leaving the network -- including passwords, email messages and any web pages people are viewing.

Of the hotels compromised, each took about 10 minutes to breach. Some hotel employees inadvertently assisted in the breach by providing passwords and access instructions.

“They are extremely unsecure,” Ogle said of hotel wireless security. “I was very disheartened by what I saw. I wasn't surprised, but I was disheartened.”

Ogle recommended that all hotels use Wi-Fi Protected Access (WPA) encryption, which requires a password to get on the network and encrypts all data transmitted. Of the hotel networks that Ogle was not able to crack, the majority used WPA encryption

For guests, Ogle recommended connecting to the internet using a Virtual Private Network (VPN), having updated anti-virus and firewall software and making sure each secured website starts with “https://” rather than “http://”.

The danger of not securing a hotel's network is that a malicious user could gain access to guest information or other confidential files, Domenic Carmona, director of IT at the W Dallas-Victory hotel, told SCMagazineUS.com Monday.

Carmona recommended hotels use WPA encryption as the minimum standard. He also stressed the importance of having a robust set of firewalls that are managed and properly configured, splitting networks, and educating staff of the importance of security standards.


Original story:
http://www.scmagazineus.com/Study-Hotel-network-security-lacking/article/118819/

Don
« Last Edit: October 07, 2008, 11:38:44 AM by don » Logged

CISSP, MCSE, CEH, Security+ SME
KrisTeason
Full Member
***
Offline Offline

Posts: 112


View Profile
« Reply #1 on: October 07, 2008, 12:32:04 PM »

Good post don & I've got to state it's all true. A buddy of mine sits takes his Alfa USB 500mW WiFI Adapter with him each time he goes on vacation, runs his aircrack tool and free internet. Despite people who actually pay for internet services in hotels, it's pretty crazy just to imagine what an attacker can do passively on the network(consider dns spoofing, sniffing, etc). Hotels need to start "beefing" up their security. It's honestly gotten to the point where mere script kiddies can show up to a hotel and run automated tools like Spoon WEP or Wesside-ng to get keys and then a lot of peoples privacy can be invaded. I think it's good he made this widely known and the article is posted maybe it'll serve as a wake up call. Thanks for the good read don.
Logged
jason
Sr. Member
****
Offline Offline

Posts: 264


Aut Viam Inveniam Aut Faciam


View Profile
« Reply #2 on: November 01, 2008, 06:58:58 PM »

Or is the general computing public really that naive about security still?

I'm afraid so. Not only do hotels almost universally have poor wireless security, but they also provide one of the single best hunting grounds that someone looking to snare sensitive information could ever wish for. Even worse than many people being naive about security is that they are wilfully so.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.049 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.