Viruses to infect Wi-Fi networks in 2008?

Researchers at Indiana University have warned of the increased opportunity for hackers resulting from the spread of Wi-Fi. The researchers were specifically talking about the new breed of city-wide Wi-Fi networks where thousands can be logged on simultaneously, but the principle can also be applied to smaller-scale public hotspots.

What's more, the researchers think such a threat could piggyback across multiple Wi-Fi networks too, taking over thousands of networks in one fell swoop. The researchers think such an attack would easily spread by guessing admin passwords that simply haven't been changed. In fact, they estimate that 36 per cent of passwords could be guessed.

"The issue is that most of these routers are installed out of the box very insecurely," said Steven Myers, an assistant professor at Indiana University told the IDG News Service. He's got a point; most manufacturer's instructions don't even tell you how to change the admin username and password from the default settings, meaning anybody who can access your wireless network can change your settings. And if you don't have security enabled, that's bad news. Even if you have, it might not stop such an attack: WEP encryption is old news to hackers.

The potential attack could install new firmware on routers, meaning they could in turn attack other networks. However, there is one caveat to this - to the knowledge of the researchers, no code has yet been written to carry out such an attack.

Wi-Fi hacking has been in the news at various points over the past year or two, most notably when a hacking expert demonstrated how easy it is to intercept email over a Wi-Fi connection at last year's Black Hat security convention.

At the time, Robert Graham, CEO of Errata Security, accessed the Gmail of a 'victim' in front of the press. What was worrying about the demonstration was just how simple it was. First, Graham ran Ferret to sniff out the packets of data on the open Wi-Fi network set up for the expo. It copied the cookies being sent across the access point. Graham then copied these into his browser with a tool called Hamster.

As he had the cookie, he could then gain password-less access to mail accounts. Graham demonstrated the methodology against different webmail providers. At that rate, we might all be using VPNs on public networks in a few years time.

Contributor

Dan (Twitter, Google+) is TechRadar's Former Deputy Editor and is now in charge at our sister site T3.com. Covering all things computing, internet and mobile he's a seasoned regular at major tech shows such as CES, IFA and Mobile World Congress. Dan has also been a tech expert for many outlets including BBC Radio 4, 5Live and the World Service, The Sun and ITV News.

Latest in Wi-Fi & Broadband
Eero 7 mesh Wi-Fi system on a wooden table
I tested the affordable Eero 7 mesh Wi-Fi system, and as long as you don't need 6.0GHz Wi-Fi, it's great for bringing those dead spots back to life
Eero 7 on a nightstand
Amazon's new Eero 7 and Pro 7 complete a 'comprehensive lineup' for its customers – here's everything you need to know
A hacker wearing a hoodie sitting at a computer, his face hidden.
I just learned something awful about my home Wi-Fi setup thanks to iFixit’s ‘worst of CES 2025’ awards
Extendable WiFi 7 KV
Don't buy a router, buy a fast and secure ASUS WiFi 7 extendable router
Netgear Nighthawk router next to its box on a table
Netgear Nighthawk RS200 review: Netgear’s latest Wi-Fi 7 router is competitively priced – but makes compromises to get there
Netgear Orbi 770 router system resting on a table
Netgear Orbi 770 review: fast speeds, low Wi-Fi 7 prices
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale