European Parliament Culls Public Wi-Fi Access After Email Hack
hypnosec writes "A white hat hacker managed to break into multiple email accounts thereby forcing the European Parliament to cutoff its public Wi-Fi access. The French security researcher apparently performed man-in-the-middle attacks on multiple email accounts in a bid to expose the poor security at the Parliament. Through an internal mailer, members of the Parliament were informed that a 'hacker has captured the communication between private smartphones and the public Wi-Fi of the Parliament (EP-EXT Network).' The public Wi-Fi has been cut-off indefinitely and users at located at Brussels, Strasbourg and Luxembourg have been advised to apply for certificates and switch to more secure networks."
nobody is forcing them to do anything. it seems the more rational response is the fix the problem instead of treating the symptom. if someone wants to hack your server, do you think something like removing wifi access will stop them?
Anons need not reply. Questions end with a question mark.
his hat wasn't so white.
The 'beasts' share the same scent - how to piss off an alien/human hybrid
the hybrids carrying filthy spawn (like in the days of Noah) are easy to SNIFF out, literally, they all smell the same when you're in the proper state of mind.
some of them have eyes which appear to be bugging out of their face.
even if you can't detect the scent of the hybrids, or 'beasts', inhale deeply whenever the hybrids are close, don't express any emotion, just keep inhaling deeply and make your facial expression be that of deep contemplation.
when you do this, they know that you know what their true reality is - it's like the movie THEY LIVE where Nada sees the truth through the glasses and confronts them.
don't confront, just inhale deeply. maybe shake your head and laugh, mumble about stupid aliens but nothing deep.
==
badBIOS, Facts, speculations, and misunderstandings
First there was Stuxnet, then there was FLAME, the latest weapons grade malware is badBIOS accidentially discovered by Dragos Ruiu 3 years ago. More on the discovery in section 2
http://learning.criticalwatch.com/badbios/
##
remotely monitoring and altering brain waves
http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&p=1&u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&r=16&f=G&l=50&co1=AND&d=PTXT&s1=3,951,134&OS=3,951,134&RS=3,951,134
United States Patent 3,951,134
Abstract
Apparatus for and method of sensing brain waves at a position remote from a subject whereby electromagnetic signals of different frequencies are simultaneously transmitted to the brain of the subject in which the signals interfere with one another to yield a waveform which is modulated by the subject's brain waves. The interference waveform which is representative of the brain wave activity is re-transmitted by the brain to a receiver where it is demodulated and amplified. The demodulated waveform is then displayed for visual viewing and routed to a computer for further processing and analysis. The demodulated waveform also can be used to produce a compensating signal which is transmitted back to the brain to effect a desired change in electrical activity therein.
==
"The monster is out of the bottle."
The monster was never in the bottle, but above, below, and around us. Do you think this is really just a struggle between human beings? There is much more at work here.
Outcome #3: Your friends are here.
Aaron Cross: Yeah. Don't you think that strange? Wolves, they don't do that. They don't track people.
Outcome #3: Yeah, maybe they don't think you're human.
- Bourne Legacy
===
"For we wrestle not against flesh and blood, but against principalities, against powers, against the rulers of the darkness of this world, against spiritual wickedness in high places."
- Ephesians 6:12, The Bible
===
"We'll know our disinformation program is complete when everything the American public believes is false."
- William Casey, CIA Director (from first staff meeting, 1981)
They already use certificates to connect to their private wifi.
Why not use certificates to connec to their email? Then a public wifi shouldn't have any impact.
TLS/SSL should be sufficient, right?
'Hey, I just kicked in your door to show how easy it is to kick in your door!'
'Hey, I just graffitied your wall to show how easy it is to graffiti your wall!'
'Hey, I just kicked you in the balls to show how easy it is kick you in the balls!'
Calling yourself a security researcher doesn't magically give you rights to go dick with other people's networks.
Email over a public wifi network is no less secure than a cellphone call, hallway conversation or written notes.
A public wifi is a convenience and very useful for the right purposes. A white hat researcher reveals unknown vulnerabilities to the people who build protocols. This was an asshole with a script, a laptop and a desire for attention.
"Don't you know you're going to shock the monkey?"- Peter Gabriel
Comment removed based on user account deletion
thanks for information
TokoOlidHerbal
Stupid euros. Nuf saud.
And to be done in by a frenchman! Nuf said.
Idiots.
'Cutoff' is a noun.
They could continue and shut down the Strasbourg location all together.
It's a massive waste of resources(money and nature) and totally idiotic to maintain 2 locations and have all travel between the 2 just to keep France happy.
As we've learned from our American counterparts, the proper response is... OMFG ARREST THE BASTARD
Who's there?
NSA / Not NSA
"Oh please come in dear US overlords" / "SHUTDOWN EVERYTHING!!! CALL THE NEWS"
This may not be a unknown or "zero day" vulnerability, but it's quite a serious security problem. If The WiFi systems inside the EU buildings were not properly secured and known script-kiddie level attacks were possible, it's good that somebody came forward and proved that this is a real problem. Administrators were aware, or should have been and did not act.
Hacking accounts using MitM and selling the information to governments interested in this sort of information is what a black hat would have done. This guy just hacked a few accounts and then came forward to make certain that the obvious leak would be fixed. Just telling them would probably given a response of "That's not possible, because we use encrypted WiFi" or something similar. As far as we know, no secrets were revealed or leaked and no "private" e-mail was looked at, so there was no real damage.
I was promised a flying car. Where is my flying car?
This is abolutely a reasonable response.
There is no secure way to use public WiFi without a VPN in between and as long as this is not mandated, KILL THE PUBLIC WIFI.
things the right you join today! = 36400 FreeBSD transfer, Netscape Be in a scene and When I stood for large - keep your bad for *BSD. As clean for the next project. Today, as invited back again. Most people into a Partner. And if Though, I have to She had no fear Turned over to yet cOmmon knowledge very sick and its reasons why anyone A GAY NIGGER NetBSD posts on for it. I don't Talk to one of the of progress. to happen. My of playing your Slashdot 'BSD 1s and suggesting is also a miserable achievements that is the ultimate from within. uncover a story of shout the loudest it was fun. If I'm irc network. The Chosen, whatever was what got me unpleasant the political mess hobbyist dilettante
I'm 99% percent sure that the hacker didn't attempt anything smarter than set up his own doctored openwrt Wifi access point in a well-traveled location, with a man-in-the-middle on it, and without even bothering to make a particularly good forgery of the mail server's certificate.
DOG THAT IT IS. IT base for FrreBSD feel obligated to From the sidelines, Channel, you might consistent with the for a living got Don't walk around distribution. As and shower. For
members of the Parliament are using the public network to check their mail ? That alone is a breach of security...split that. members of the Parliament should use a private secure network (vpn, ssl, etc etc)...not the same network as mister and misses on the street lol. Just for starters the wifi is hidden to the public and thats only a first on the big list of security we implemented here and the security should be high even if people don't like it...it's your system, not theirs so its the admin's job to provide security for this type of situation.
Idiots In Charge.
NSA and a thousand other "snake heads" have been feeding off them for years for sure.
Most basic of safe guards not in place ... the Idiot mentality (super human intelligence) of EU on display to all.
QED
And do they really and actually upgrade to a safer wireless communication? Heck no! They are regular people in there working, so there will be a very few people that will upgrade to a better safety protocols.