Study shows firewalls used to hack into FB, Twitter accounts
|
by Anuradha Shetty
|
|
A computer science associate professor at the University of Michigan, and a doctoral student using an Android phone revealed just how it is possible for one to misuse the otherwise useful Firewall technology to hack into Facebook and Twitter accounts. Reports coming in bring to light a study by Z. Morley Mao, a computer science associate professor at the University of Michigan, and a doctoral student, Zhiyun Qian. They explained how it was possible for someone to hijack a TCP (transmission control protocol) Internet connection by misusing publicly available information on smartphones. The researchers, reportedly presented their findings at the IEEE Symposium on Security and Privacy in San Francisco, US. The report further went on to add that these hackers also took advantage of gullible users with willingness to download suspicious apps and network firewall middleboxes that block the data bundles, which are not included in the flow of information traffic. ![]() Misusing firewalls
In their research, wherein they tested some 150 networks, the researchers found that 32 percent of those networks contained these middleboxes. Qian was further quoted as saying, "Firewall middleboxes are supposed to protect against this kind of attack, but it turns out they do the opposite. Most vendors and carriers that deploy such firewall middleboxes still believe they are safe and we want them to be aware of this design flaw." How this works is that middleboxes essentially monitor the "sequence numbers" of data packets that are on their way to mobile devices. When a user shares an image with a friend, it further gets chopped into several packets, before it is sent across the network.
Explaining the mode further, the report states that the user's friend's smartphone will refer to the sequence numbers to decipher the picture. "Middleboxes could help hackers use the process of elimination to home in on a number in the right range," it added. Qian was quoted as saying, "An attacker can try to guess at sequence numbers. It's usually hard to get feedback on whether a guessed number is correct, but the firewall middlebox makes this possible. The attacker can try a range of sequence numbers. The firewall will only allow one through if it is in the valid range."
Interestingly, the report further adds that for the spyware to work neither privileged information was required, nor special administrator or root access. "It would just read a couple of the phone's publicly available incoming packet counters and let the attacker know when the counters -advanced. Armed with a valid sequence number, the hacker could spoof Facebook or Twitter's HTTP (as opposed to the more secure HTTPS) web login page and gain the user's passwords."
News Sources |
Tags: Firewalls , IEEE Symposium on Security and Privacy , transmission control protocol , Internet connection , data packets , Android smartphones , smartphones
SPOTLIGHT
BBM and Google Hangouts can't fix the...
17 May, 2013, 04:30 PM
4.3-inch, Intel-based, Xolo X910 smartphone
18 May, 2013, 01:10 PM
6 Things to look for when buying a...
18 May, 2013, 01:07 PM
Is Samsung 'mentally enslaving' Indian smartphone buyers...
17 May, 2013, 07:51 PM IST
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
17 May, 2013, 01:09 PM IST
tech2 live: The latest from Google I/O 2013
16 May, 2013, 01:56 PM IST
MouthShut.com petitions SC to protect freedom of expression and quash
09 May, 2013, 07:01 PM IST
No arrests over objectionable posts on social sites without senior...
16 May, 2013, 03:17 PM IST
Flickr update may be unveiled at May 20 event
18 May, 2013, 01:46 PM
iTunes security loophole lets users download Daft Punk stream for free
18 May, 2013, 01:09 PM
Microsoft shows Internet Explorer can be cool using Vine
18 May, 2013, 11:27 AM
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
To avoid all the hassle and with a view to make it convenient for...
We have 5 tech gift ideas that will help you find a gift that will...
5 Websites to create custom t-shirts
If you are bored of wearing the run-of-the-mill t-shirts, then you can...
Karbonn launches Smart Tab TA Fone A 37 Kommunicate 3G for Rs 9,490
Md Tanim
Sat May 18, 15:19:54
Augustine Danquah
Sat May 18, 14:59:26
HCL Learning launches MyEduWorld tablet, drives with pre-loaded content
Srivastava Deepak
Sat May 18, 14:58:55
Hands-on with the quad-core Panasonic P51
ZTE to launch devices ranging from Rs...
Microsoft reportedly launching 7.9-inch...
HP unveils SlateBook x2 convertible...
Metal Gear Rising: Revengeance will be...
Microsoft planning dashboard update with...


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace



















