<DOC>
<DOCID>Wireless_Phishing.doc.txt</DOCID>
<AUTHOR>Doug Anger</AUTHOR>
<TEXT>
At the beginning of last semester, the Compass ran an article about how configuring your WiFi (Wireless Access Point) insecurely could get you kicked off the LSSU campus network. This week, a relatively new reason to secure your WiFi has emerged and it has to do with Phishing and Pharming.

Phishing is a technique hackers use to convince an unsuspecting user to hand over passwords, credit card numbers, or other personal information. The most common method is by sending an email message that claims to come from some legitimate website asking for the user to verify his or her data. When the user clicks on the link, they are not taken to the legitimate site, but a fake, a different site designed to look like what the user expects to see. When the user enters his or her information, it doesn't go to the legitimate site the email claimed to have come from, but to the hacker who sent the email.

Last December, a Phishing attack was launched on the social networking site MySpace that directed users to a fake login page. This is particularly disturbing because the attack only required the user to visit an infected profile page. Similar attacks have been used to change the content of another webpage the user is visiting at the same time. Visiting an untrusted (i.e. infected) page at the same time as a trusted one (Amazon, PayPal, online banking, etc.) ends up changing the content of the trusted page or even handing your password over to the hacker. In August, a fake news story was posted claiming that President Bush had appointed a 9-year old head of the Information Security Department. Clicking the link from the fake story sent the user to CBS or BBC and at the same time modified the appearance of those sites inside the browser so that it appeared that the story was coming from those sources.



Most phishing attacks can be avoided by using good sense when clicking on email links and using FireFox with the NoScript extension available at http://noscript.net/.

Pharming is not so easy to detect. When you want to visit a website, LSSU's for instance, you type the web address into the address bar of your web browser or click on a bookmark to do this for you. The problem is, of the billions of servers on the Internet, your computer needs to decide which one is LSSU.edu. To do this, it goes out to a Domain Name Server (there are thousands of these out there) and asks for the IP address of www.lssu.edu. That server tells your computer that the correct address is 198.110.216.3. (Yeah, be glad you don't have to remember all your favorite websites that way.) Your computer then connects to 198.110.216.3 and downloads the content of the homepage to show on your screen. All of this is great until someone devious decides to set up his own Domain Name Server (DNS) that is going to lie to your computer. Supposing he can convince your computer to talk to his Domain Name Server, he can make you see any website he wants when you type www.lssu.edu.

That's where the WiFi comes in. If you have not changed the default password on your wireless router, simply viewing a webpage with a malicious JavaScript embedded in it can set your router to use the bogus DNS created by the hacker. Now when you type a web address into your browser, you aren't necessarily using that web site. You may be using a lookalike, a forgery intended to steal your passwords and other personal information. You aren't necessarily the only person affected either. When someone else comes into range of your WiFi and their computer automatically connects, they are going to the same bogus page. (By that same principle, you can't trust a public WiFi.)

For more information on this attack, visit http://www.symantec.com/avcenter/reference/drive-by-pharming-animation.html. 

So what can you do to protect yourself? First, secure your WiFi. A quick Google search on your particular brand of router should get you instructions for changing the password. Choose WPA (preferred) or WEP (if you must) instead of an unsecured connection. Be sure to read Safe Surfing online at http://compass.lssu.edu/content/view/394/51/ to learn more ways to stay safe online.

</TEXT></DOC>
