Big Vulnerability In Hotel Wi-Fi Router Puts Guests At Risk
An anonymous reader writes Guests at hundreds of hotels around the world are susceptible to serious hacks because of routers that many hotel chains depend on for their Wi-Fi networks. Researchers have discovered a vulnerability in the systems, which would allow an attacker to distribute malware to guests, monitor and record data sent over the network, and even possibly gain access to the hotel's reservation and keycard systems. The vulnerability, which was discovered by Justin W. Clarke of the security firm Cylance, gives attackers read-write access to the root file system of the ANTlabs devices. The discovery of the vulnerable systems was particularly interesting to them in light of an active hotel hacking campaign uncovered last year by researchers at Kaspersky Lab. In that campaign, which Kaspersky dubbed DarkHotel.
Isn't it sort of obvious that hotel networks are a free-for-all security wise?
Use a VPN and SSL.
RTFA; that won't help.
The problem is that before you can connect out to use your VPN, you first have to get provisioned by the hotel's wifi. This involves at a minimum checking a box that says "I won't try to hack or do bad things," along with either authorizing a charge, giving the webpage your hotel frequent traveler info/name and room number, or authorizing a charge for the Internet access. Those pages are what put you at risk; the attacker hacks the router that serves up the page, adds a nice little bit of extra code to serve up malware (that he also uploads to the router itself, so no need for outside Internet to get it), and boom...everyone with a vulnerable system that connects in that hotel gets pwned.
And that's beyond the risk of the machine serving as a jump-point for deeper penetration into the hotel itself. How is your using a VPN going to protect the hotel's keycard system from being hacked? Or protect your private information that resides in the reservation system?
For your security, this post has been encrypted with ROT-13, twice.