Black Hat hears of data leak dangers

01.03.2007

In addition to data related to Web connectivity or operating systems, such tools can be used to detect what types of anti-virus applications users are running when the software programs attempt to automatically download updates. With the wide number of known vulnerabilities existing in anti-virus programs, a hacker could easily take that information and use it to craft a targeted attack, the experts said.

The tools can even be used to garner similar data from smartphones and other data-centric handhelds, according to the researchers.

The experts contend that when the U.S. government was piecing together information about suspected terrorists after the Sept. 11 attacks, investigators likely relied on the same types of data to figure out where various people had traveled, who they communicated with, and what they might have been looking at on the Internet.

Consumers may be upset about retailers who collect and expose sensitive information or unchecked government wiretaps, but they are unknowingly handing over a range of data that could be used to track their movements, steal their money, or penetrate their employers' networks.

"Just by going to a lounge in an airport with a sniffer like this, you can easily develop a profile that can be used to exploit any weaknesses," Graham said. "You can move from [intercepting] a low-level MAC address to capturing high-level information in a very short amount of time."