FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   JetBlue | TrueBlue (https://www.flyertalk.com/forum/jetblue-trueblue-492/)
-   -   Suspicious wi-fi at Long Beach (https://www.flyertalk.com/forum/jetblue-trueblue/541710-suspicious-wi-fi-long-beach.html)

nsx Mar 27, 2006 11:19 pm

Suspicious wi-fi at Long Beach
 
Long Beach has a free wi-fi access point labeled "ColorBroadband_South". It works fine.

However I also saw a "computer to computer network" labeled "Jet Blue hot spot". Note the space: not "JetBlue hot spot".

I suspect that someone with criminal intent has set up a laptop and labeled it "Jet Blue hot spot" in order to lure unsuspecting passengers to connect and then capture their user account and password information. Are my suspicions well founded or not?

justageek Mar 28, 2006 12:02 am


Originally Posted by nsx
Long Beach has a free wi-fi access point labeled "ColorBroadband_South". It works fine.

However I also saw a "computer to computer network" labeled "Jet Blue hot spot". Note the space: not "JetBlue hot spot".

I suspect that someone with criminal intent has set up a laptop and labeled it "Jet Blue hot spot" in order to lure unsuspecting passengers to connect and then capture their user account and password information. Are my suspicions well founded or not?

Sounds very suspicious to me. What you described is definitely doable.

IceTrojan Mar 28, 2006 12:04 am

There have been news reports of these. You might consider informing authorities at LGB.

jetBlueNYFL Mar 28, 2006 12:38 am

Definitely report it...if you see something, say something. JetBlue would make sure their IT people did not use a space on their company name!

JBLUA320 Mar 28, 2006 5:49 am

Report it! B6 has NO Wi-Fi at LGB.. THe person who made this Rogue AP, didn't even consider making it appear semi-legitimate, or cloning a real AP.. geesh (rolls eyes)

Give someone a call if you can.

KenInChicago Mar 28, 2006 12:39 pm

This is also a good time to remind people to be very careful on every Wi-Fi network to closely guard personal information.

enjoystravel Mar 29, 2006 11:32 pm


Originally Posted by KenInChicago
This is also a good time to remind people to be very careful on every Wi-Fi network to closely guard personal information.


There are several measure to take. Most importantly, anytime you transmit private information, make sure it is via SSL. Login only using SSL. If you work for a smaller business, insist on a VPN or Secured access where communication is encrypted on your laptop before reaching the net.

PepsiAddict May 7, 2007 10:18 am

I just flew through JFK on May 4th and there were 2 of these "rogue networks" operating in the terminal ... "Jet Blue hot spot" and "Free Internet Access". I put in a "Speak Up" for it, maybe one of the JetBlue IT Guys can track them down.

I considered turning on Netstumbler and tracking them down to at least see who and/or where they were operating, but figured it might look a little fishy for me to be walking around the terminal in circles with an open laptop.

Interestingly, I got to work this morning and one of my users (I'm an IT Guy) had one of these networks configured on his PC ("Free Public Wi-Fi" was the network name)... he said he used it flying a legacy over the weekend ... thankfully the firewalls and VPN prevented anything back from happening to his PC or his information.

If interesting in the "Free Wifi Scam" there is a pretty good article here: http://www.computerworld.com/action/...icleId=9008399

sbm12 May 7, 2007 11:27 am

Also consider that when people attempt to manually set up wireless access connections they sometimes manually enter the SSID instead of having it auto-connect, which may explain the appearance of the extra network.

And if you're an IT guy you should disable the ability to connect to a peer-to-peer wireless network. That will give you infinitely better protection than hoping you can find the guys planning on stealing your data. Otherwise, connecting to any public wireless network is about the same level of (non-)security.

PepsiAddict May 7, 2007 12:49 pm


Originally Posted by sbm12 (Post 7700973)
Also consider that when people attempt to manually set up wireless access connections they sometimes manually enter the SSID instead of having it auto-connect, which may explain the appearance of the extra network.

True ... anything is possible ... didnt think of that aspect.


Originally Posted by sbm12 (Post 7700973)
And if you're an IT guy you should disable the ability to connect to a peer-to-peer wireless network. That will give you infinitely better protection than hoping you can find the guys planning on stealing your data. Otherwise, connecting to any public wireless network is about the same level of (non-)security.

Theres alot of things I would love to be able to do to lock down my users PCs but management refuses to allow it ... frustrating for sure ... every step towards locking them down is met with three steps back of "you cant do that". No matter how many times the security side of things is explained it gets repealed. I spent almost 2 years arguing to get approval to make users "standard users" on their PCs ... But I digress ...

tutt May 17, 2007 10:15 am


Originally Posted by PepsiAddict (Post 7700502)
I just flew through JFK on May 4th and there were 2 of these "rogue networks" operating in the terminal ... "Jet Blue hot spot" and "Free Internet Access". I put in a "Speak Up" for it, maybe one of the JetBlue IT Guys can track them down.

If interesting in the "Free Wifi Scam" there is a pretty good article here: http://www.computerworld.com/action/...icleId=9008399

Just had a layover at JFK on Tuesday and could see the rogue networks, "Jet Blue hotspot" and "Free Public WiFi, on my Powerbook" (Both under Computer to Computer networks) The real hotspot name was "default", but the familiar WiFi hotspot acceptance screen came up and after accepting, it forwarded to JetBlue.com

I have had trouble accessing the hotspot on previous trips through JFK and CMH. (Although I think the CMH hotspot is their own and not JetBlue's)

nsx Aug 20, 2008 7:07 pm

The definitive story on "Jet Blue hot spot" fake SSID
 
http://blogs.techrepublic.com.com/hiner/?p=602 explains everything. This is a viral attack, not an on-site hacker. Click on the peer-to-peer network once and your PC is infected too. Check your list of preferred networks and delete Jet Blue hot spot if you find it there. The full list of these bogus network SSIDs includes:

* Free public Wi-Fi
* Free Internet!
* US Airways Free WiFi
* Thrifty
* Verizon Wi-Fi
* Megahoc.21
* Megahoc.v22
* Megahoc.v24
* hpsetup
* WIRELESS
* ETWireless
* ConnectionPoint
* Jet Blue hot spot
* Raisinet
* Wireless
* WIFI
* Wireless Canes
* Annies
* Ramada
* Default

sbm12 Aug 20, 2008 8:53 pm


Originally Posted by nsx (Post 10234801)
http://blogs.techrepublic.com.com/hiner/?p=602 explains everything. This is a viral attack, not an on-site hacker.

This is hardly definitive and certainly doesn't explain everything. They skip over the part about where there is no evidence of anyone actually using the "viral" networks to actually pilfer data. Certainly having your system configured to connect automatically to unknown hotspots is bad and all that much more so for peer-to-peer networks. But that doesn't make it a virus. And to suggest that it is going to become a botnet is just ridiculous. How do they plan to harvest those many, many computers that have an SSID set in them? It isn't like a hacker can spontaneously establish a "Free Public Wi-Fi" access point in range of thousands of "compromised" laptops.

The only useful thing in that article is the link at the end for how to disable ad hoc networking. The rest of it is ridiculous conjecture, but it makes for fun reading and I'm sure that the folks who published it will be having a good time at the Gartner conference selling their services to companies that could avoid the problem with a simple Group Policy setting to disable ad hoc networks.

stimpy Aug 21, 2008 3:56 am

I saw the same thing at JFK recently. I know to NEVER click on an Ad Hoc SSID. There was another AP SSID (default) that I clicked on and the browser brought up a welcome to Jet Blue WiFi screen. In any case I always use end-to-end layer 3 encryption.

ellinj Aug 21, 2008 4:55 pm

Why the heck don't they give the name of the wifi connections names that can tell me if they are legit are not? JFK calls it default? As the OP mentioned I think LGB had something called ColorBroadband_South. I have gotten in the habit of either firing up my VPN or using my broadband modem when in public areas because you just don't know. They should put up signs or something.


All times are GMT -6. The time now is 9:08 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.