Web attacks can find where you live

Geo location data from Google can be used to pinpoint a victim's precise location

PTI | August 5, 2010



Visiting a booby-trapped website, the bogus webpage designed for phishing, means inviting cyber attackers to your home, a hacker turned security researcher has warned.

The attacker exploits the shortcomings in many routers -- the device which forwards data packets to their destinations -- to find out a key identification number that can reveal the victim's whereabout in minutes, noted hacker Samy Kamkar said.

Demonstrating such an attack at the recently concluded Black Hat hacker conference in Las Vegas, Kamkar described how web attacks that begin with making contact with the target (user) can be used to find a person's physical location.

After making contact, the target is convinced to visit a booby-trapped website designed by the attacker. Once the victim clicks the attacker's link, Kamkar showed how the attacker can manipulate geo location data from Google to pinpoint a victim's precise location, the BBC reported.

Many people go online via a router and typically only the computer directly connected to the device can interrogate it for ID information.

However, Kamkar found a way to booby-trap a webpage via a browser so the request for the ID information looks like it is coming from the PC on which that page is being viewed.

He then coupled the ID information, known as a MAC address, with a geo-location feature of the Firefox web browser. This interrogates a Google database created when its cars were carrying out surveys for its Street View service.

This database links Mac addresses of routers with GPS co-ordinates to help locate them.

"This is geo-location gone terrible," said Kamkar during his presentation. "Privacy is dead, people. I'm sorry."

Mikko Hypponen, senior researcher at security firm F Secure, attended the presentation and said it was "very interesting research".

"The thought that someone, somewhere on the net can find where you are is pretty creepy," he said.

"Scenarios where an attack like this would be used would be stalking or targeted attacks against an individual," he added.

"The fact that databases like Google Streetview's Mac-to-Location database or the Skyhook database can be used in these attacks just underlines how much responsibility companies that collect such data have to safeguard it correctly," said Mr Hypponen.

In 2005, Mr Kamkar created a worm that exploited security failings in web browsers to garner more than one million "friends" on the MySpace social network in one day.

Prosecuted for the hacking, Kamkar was given three years' probation and 90 days of community service and paid damages.

He was also banned from using the net for personal purposes for an undisclosed amount of time.




 

Comments

 

Other News

Mofussils: Musings from the Margins

Provincials: Postcards from the Peripheries By Sumana Roy Aleph Book Company, 320 pages, Rs 899 Sumana Roy’s latest work, like its p

How to promote local participation in knowledge sharing

Knowledge is a powerful weapon to help people and improve their lives. Knowledge provides the tools to understand society, solve problems, and empower people to overcome challenges and experience personal growth. Limited sources were available to attain information on the events in and arou

‘The Civil Servant and Super Cop: Modesty, Security and the State in Punjab’

Punjabi Centuries: Tracing Histories of Punjab Edited by Anshu Malhotra Orient BlackSwan, 404 pages, Rs. 2,150

What really happened in ‘The Scam That Shook a Nation’?

The Scam That Shook a Nation By Prakash Patra and Rasheed Kidwai HarperCollins, 276 pages, Rs 399 The 1970s were a

Report of India’s G20 Task Force on Digital Public Infrastructure released

The final ‘Report of India’s G20 Task Force on Digital Public Infrastructure’ by ‘India’s G20 Task Force on Digital Public Infrastructure for Economic Transformation, Financial Inclusion and Development’ was released in New Delhi on Monday. The Task Force was led by the

How the Great War of Mahabharata was actually a world war

Mahabharata: A World War By Gaurang Damani Sanganak Prakashan, 317 pages, Rs 300 Gaurang Damani, a Mumbai-based el

Visionary Talk: Amitabh Gupta, Pune Police Commissioner with Kailashnath Adhikari, MD, Governance Now


Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter