Hacking into email over Wi-Fi 'easy'

The convention took place at Ceasars Palace in Las Vegas

A hacking expert has demonstrated just how easy it is to intercept email over a Wi-Fi connection. The demo happened at the Black Hat security convention taking place at Ceasars Palace in Las Vegas.

Robert Graham, CEO of Errata Security, accessed the Gmail of a 'victim' in front of the press. According to TGDaily , Graham even took over another reporter's Gmail and sent messages between the accounts.

What's worrying is that the methodology really is very simple. First, Graham ran Ferret to sniff out the packets of data on the open Wi-Fi network set up for the expo. This software copies the cookies being sent across the access point. Graham then copied these into his browser with a tool called Hamster.

And, because he had the cookie, he could then gain password-less access to mail accounts. Graham demonstrated the methodology against different webmail providers. OK, so using any type of encryption in the process will disrupt the process. So what's the advice here? If you're on a public, open network, you should use a VPN or some other type of encryption (SSL-encrypted sites will stop the sniffing).

"You're an idiot if you use T-Mobile hotspot," Graham told TGDaily. "I see ten people's cookies on my screen, I just need to click on the guy's IP address and I'm in. Once you get someone's Google account, you'd be surprised at the stuff you'd find."

More here .

Contributor

Dan (Twitter, Google+) is TechRadar's Former Deputy Editor and is now in charge at our sister site T3.com. Covering all things computing, internet and mobile he's a seasoned regular at major tech shows such as CES, IFA and Mobile World Congress. Dan has also been a tech expert for many outlets including BBC Radio 4, 5Live and the World Service, The Sun and ITV News.

Latest in Wi-Fi & Broadband
Eero 7 mesh Wi-Fi system on a wooden table
I tested the affordable Eero 7 mesh Wi-Fi system, and as long as you don't need 6.0GHz Wi-Fi, it's great for bringing those dead spots back to life
Eero 7 on a nightstand
Amazon's new Eero 7 and Pro 7 complete a 'comprehensive lineup' for its customers – here's everything you need to know
A hacker wearing a hoodie sitting at a computer, his face hidden.
I just learned something awful about my home Wi-Fi setup thanks to iFixit’s ‘worst of CES 2025’ awards
Extendable WiFi 7 KV
Don't buy a router, buy a fast and secure ASUS WiFi 7 extendable router
Netgear Nighthawk router next to its box on a table
Netgear Nighthawk RS200 review: Netgear’s latest Wi-Fi 7 router is competitively priced – but makes compromises to get there
Netgear Orbi 770 router system resting on a table
Netgear Orbi 770 review: fast speeds, low Wi-Fi 7 prices
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does