Heard of drive-by hacking? Meet drive-by spamming

By Graeme Wearden
06 September 2002 09:50 AM
Tags: driveby, warspammers, hacking, networking, wireless, networks, lan, wright
'Warspammers' are taking advantage of unprotected wireless LANs to send out millions of junk e-mails.

The proliferation of insecure corporate wireless networks is fuelling the growth of drive-by spamming, a security expert warned this week.

Speaking at the First International Security Users Conference in London, Adrian Wright, managing director of Secoda Risk Management, warned that junk e-mailers are taking advantage of unprotected wireless local area networks to bombard e-mail users with unsolicited and unwelcome messages.

"These people simply drive up to a building armed with their pornographic e-mail, log into the insecure wireless network, send the message to 10 million e-mail addresses and then just drive away," said Wright.

A drive-by spammer would send spam by finding an unprotected SMTP port on a company's server and then sending e-mail as if they were a legitimate user of the company's network. The mail server wouldn't be able to tell otherwise.

The ability to send spam through a company's network without its knowledge could allow the spammer to avoid bandwidth costs--which can be substantial for tens or hundreds of thousands of e-mails. It also make sit much more difficult to trace the spam back to the spammer--a useful tactic for those who send spam as a service for other companies and who may have been in trouble with the law.

The US Federal Trade Commission has said that it has busted dozens of alleged Web scammers in conjunction with law enforcement from six US states and Canada. And in July, six Korean Web sites were fined for bombarding Internet users with spam e-mail.

In Europe, a new directive that bans the sending of unsolicited commercial e-mail should be in place some time next year.

What's more, many ISPs have no-spamming rules, which the drive-by spammer will be trying to avoid. A company that falls victim to a drive-by spammer could find itself cut off--any messages sent by the spammer will appear to come from within the company's network, and the ISP will have no compunction closing down the connection until the problem is resolved.

Between 60 and 80 percent of corporate wireless networks are insecure, Wright warned, often because IT managers fail to change default settings when they install a wireless LAN. This has already led to the practice of wardriving, where people drive around cities looking for insecure wireless LANs, and warchalking, where hackers drawing a chalk symbol on a wall or pavement to indicate the presence of a wireless networking node.

Warchalking signals have been springing up in areas such as London and Silicon Valley over recent months. Opinion is split over how ethical the practice is.

Matt Jones, who invented warchalking, told ZDNet UK News recently that one advantage is that it alerts sysadmins to the fact their wireless network is insecure. "I have already had e-mails from some sysadmins who said they love the idea. Several even said they will print the symbols on a card and put it in their office windows," Jones said.

Detractors, though, have warned that warchalking could encourage malicious hackers to break into a company's wireless LAN with the intention of stealing or damaging corporate data. Wright's revelation about the existence of drive-by spammers has flagged up a new downside to warchalking.

Wright illustrated that warchalking is alive in remote locations as well as cities by producing a photo of a warchalking signal drawn on a buoy floating at sea. Wright explained that it is possible to get access to a wireless network at that point, because an ISP's point-to-point transmitter onshore is transmitting a high-speed wireless connection overhead.

Several wardriving exponents have been pictured using a Pringles carton to detect Wireless LANs. Wright told his audience that a recent competition to find the best wardriving antenna had been won by a can of meat stew.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • Array Can the Telco Reform Act be win-win?
    In the second of our two programs looking at the Senate Inquiry into the Telecommunications Legislation Amendment Bill, we hear from shareholders, bureaucrats and industry groups.
  • Array Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • More blogs »

Tags

Back to top

Featured