Here’s an interesting new scam: Hackers are setting up “evil twin” wireless hotspots in public places, hoping to dupe users into connecting through them.
The trick is simple: A hacker just creates a hotspot with the same name (or a very similar one) as a legitimate hotspot nearby, hoping to dupe web surfers into connecting to the hacker hotspot instead of the legitimate one. The goal is the usual fare: Collect user names, passwords, credit card numbers.
As the cost of sophisticated electronics falls, I expect we’ll see a lot more scams that will make us long for the days of simple phishing.
One response to “Beware the Hotspot Hackers”
If nothing else, one can employ Airpwn for some impromptu street theater/comedy. (Great ghost of Allen Funt, it’s teh Airpwn!1eleven)
Here’s the page that details the use of Airpwn at DefCon: http://www.evilscheme.org/defcon/
“Warning! Here there be Goatse! Yaar.”
(Source code for Airpwn available at SourceForge.)