On BNET: IE users envy Firefox no more

Search:
Go!


See video that entertains and explains the latest in tech

Click Here
advertisement

Security Watch : Don't get burned by viruses and hackers
Wireless identity thieves
By Robert Vamosi 
Senior editor, CNET Reviews
May 11, 2007

According to an article in the Wall Street Journal (subscription required), the seeds of the nation's largest identity theft operation involving customers of TJX Companies (owners of TJ Maxx, Marshalls, and other discount stores) began in the parking lot outside a Marshalls discount clothing store in St. Paul, Minnesota. Criminal hackers, using a directional antenna, sat in their car and eavesdropped on wireless communications within the store. Over an unspecified period of time, the thieves were able to capture everything from the use of wireless handheld price-checking devices to wireless cash register transactions. But it was the wireless network for the store's main computers that ultimately allowed the criminal hackers into TJX. Once inside that network they were able to download millions of credit card numbers, some which have shown up on carder networks in eight different countries.

Credit data out the window
Over a period of two years, the hackers, still unknown, were able to download 45.7 million credit card numbers, with estimates in the Wall Street Journal article suggesting it might reach 200 million, spanning a period of more than four years. Clearly this is a big deal. Whether we shopped at these stores or not, we are all paying for this credit theft. Banks are having to reissue credit cards (this costs the banks), and investigators in eight countries are pursuing the use of these numbers (this diminishes the law enforcement available to fight other cybercrimes).

According to Secure Computing Magazine, the Marshalls store was using WEP encryption, but this form of encryption has shown to be weak against a targeted attack. German security researchers recently broke 802.11g-based WEP in just under 20 seconds. (The TJX attack occurred sometime ago, possibly starting as early as 2003.) WPA or WPA2 encryption is now recommended for home or corporate use.

Over a period of two years, the hackers, still unknown, were able to download 45.7 million credit card numbers, with estimates in the Wall Street Journal article suggesting it might reach 200 million, spanning a period of more than four years. Clearly this is a big deal.

Not the first time
But TJX Co is not alone. I wrote previously about a similar hack at Lowe's, the nationwide hardware store in the spring of 2003. At the time, Paul Timmins, then 23, and Adam Botbyl, then 20, were members of Michigan 2600, a group of local hackers that discourages its members from illegally accessing networks or committing any crimes in general and who meet periodically over Coke and pizza to share new techniques and skills. While out wardriving, that is looking for open wireless networks, in Southfield, Michigan, they came upon a Lowe's hardware store with an open wireless network. Timmins later admitted to Kevin Poulsen at Security Focus that what he did next was technically illegal: he used Lowe's wireless network to check his e-mail. When he realized it was Lowe's private network, however, Timmins says, he disconnected.

On November 5, 2003, in a parking lot of a Lowe's in Southfield, Michigan, a third person, Brian Salcedo, and Adam Botbyl returned to the wireless network, and this time attempted to load an unspecified malicious program created by Salcedo on several computers in a Long Beach, California, store. It might have been an early attempt to capture credit card transactions, but the app crashed several point-of-sale machines at the store. Two days later, the FBI arrested the group.

In the United Kingdom, there have been a few recent arrests and sentences of individuals caught using a laptop to secure the wireless networks of others.

Watch your neighbors
It's not just big business that are getting hacked, homes are as well. In the United Kingdom there have been a few recent arrests and sentences of individuals caught using a laptop to secure the wireless networks of others. According to the BBC, Gregory Straszkiewicz used the Wi-Fi services of an Ealing resident while sitting in his parked car. It wasn't Straszkiewicz's first time. Neighbors had phoned the police before regarding suspicious activity, having seen Straszkiewicz on and off over a period of three months. Prosecuted under the Communications Act, part of the Computer Misuse Act, for dishonestly obtaining an electronic communications service, Straszkiewicz was ordered to pay 500 pounds and also had to forfeit his laptop and wireless card. That sentence seems light compared with Salcedo, the first person sentenced for a wireless attack in the United States. He was sentenced to nine years for hacking into Lowe's (Timmins and Botbyl received lesser sentences).

Bottom line, you should encrypt your wireless network, home, or office, and if possible restrict your wireless network to only work with the MAC addresses of devices you own. Layering WEP, WPA, or WPA2 with MAC address permissions and stealthing one's SSID can further keep your home network safe. For more details, see my slide show on how to secure your home wireless network.

This column was updated on 05/15/07 to clarify the involvement of those involved in the Lowes wireless attack.

Is your home wireless network secure? Do you even know? Talk back to me
Security Bites Podcast
CNET News.com's Joris Evers and CNET.com's Robert Vamosi tell you about the latest security threats, what's coming, and how to protect your system. Listen now


CNET's free newsletters
Rob Vamosi's
award-winning
column on Internet threats and how to counter them 
Delivered Mondays


TalkBack
19 messages

Article discussion: Wireless identity thieves


Latest post:

"Safety since my wireless connection"
by slamina (See profile) - June 16, 2007 1:45 PM PDT
I've always had either a dialup or cable internet until I went to wireless 2 months ago. Since then I have had floods of spam I've sent to ftc.gov. These are all concerning money i... (Read more).
Sort by: Title |
Date
| Most helpful

Sercurity Advisors

I thought big stores like this had "security advisors" People that set up the ne... (Read more)
by jjennings2510 (See profile) - June 7, 2007 10:53 AM PDT

Recommendations wrong by ZDnet blogger

So your idea is right to secure your wireless network, however MAC filtering, SS... (Read more)
by smileyj (See profile) - May 15, 2007 10:34 PM PDT
0 out of 5 users found this comment helpful

cNET is smart!!

Yeah use WEP security! It only takes 10 mins to break with KnopixSTD which every... (Read more)
by LaVaism (See profile) - May 15, 2007 7:54 PM PDT

These aren't true hacks.

These are simply foolish people/organizations that didn't protect their network.... (Read more)
by qprize (See profile) - May 15, 2007 6:01 PM PDT

Poor research does a disservice

The facts of the case above involving Lowes are not accurate. Paul Timmins did ... (Read more)
by atlas.shrugged (See profile) - May 15, 2007 3:28 PM PDT
5 out of 5 users found this comment helpful | 2 comments

WIRELESS IDENTITY THIEVES ASSOCIATED WITH TJX

I'm eager to find out how long is this going to continue. Ironically, I received... (Read more)
by Miz KoKo H-T (See profile) - May 14, 2007 11:26 PM PDT
10 out of 10 users found this comment helpful

WIRELESS IDENTITY THIEVES ASSOCIATED WITH TJX

I'm eager to find out how long is this going to continue. Ironically, I received... (Read more)
by Miz KoKo H-T (See profile) - May 14, 2007 11:26 PM PDT

Wardriving and bluesnarfing

See this aricle from 2004

http://tinyurl.com/ywyuj9

(Read more)
by zizzzzzzz (See profile) - May 14, 2007 1:43 AM PDT
5 out of 5 users found this comment helpful

Robert, I know it's a slow news day, but...

Come on, man... A little *information* would be nice. We've known about the TJ... (Read more)
by John McGhie (See profile) - May 14, 2007 1:41 AM PDT
5 out of 5 users found this comment helpful | 4 comments


Copyright ©2008 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use