mailing list archives
HHU #1: "It's secure, it's reliable, it's Swiss"
From: deepquest <adf () code511 com>
Date: Fri, 28 Oct 2005 20:47:56 +0200
___ ___ ___
/__/\ /__/\ /__/\
\ \:\ \ \:\ \ \:\
\__\:\ \__\:\ \ \:\
___ / /::\ ___ / /::\ ___ \ \:\
/__/\ /:/\:\ /__/\ /:/\:\ /__/\ \__\:\
\ \:\/:/__\/ \ \:\/:/__\/ \ \:\ / /:/
\ \::/ \ \::/ \ \:\ /:/
\ \:\ \ \:\ \ \:\/:/
\ \:\ \ \:\ \ \::/
\__\/ \__\/ \__\/
"It's secure, it's reliable, it's Swiss"
Homeless Hackers United is a small group of homeless hackers from
North America. We can't afford paying for Internet access or hotel
Our only crime is to have a laptop and wireless card, and few knowledge.
Homeless state give us the freedom to access and use various open
accessible from public places. The following has been tested in UK,
Swisscom EuroSpot is a wireless service offered in airports, hotels and
other public places. Customers buy certain amount of time online and
to the wireless network. The login page is of course open in order to
subscribe to the service.
HHU has been able to access, and validate around several hotels and
XSS, URL evasion
Swisscom access point seems to use radius servers to provide internet
their customers. We also noticed issues on the radius
that may be published later. After joining the network you will have
buy access time or login. The following has been tested in UK,
Proof of Concept
Change, spoof and fool end-users on login page or paiement page. With
a bit on
imagination it can be worst.
Discovered: august 14th 2005
Disclosure: october 28th 2005
Service Provider: no
HHU can't even afford food, and we're are not paid to debug softwares
We discover, then publish what we find. Will route tcp/ip packets for
"Fool me once, shame on — shame on you. Fool me — you can't get
— George W. Bush
deepquest for discovering and POC, Mescalito for more POC.
original post http://deepquest.code511.com/blog/more.php?id=319_0_1_0_M
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- HHU #1: "It's secure, it's reliable, it's Swiss" deepquest (Oct 28)