Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

Hotel WiFi across MENA compromised and exposing private data

Hotel WiFi across MENA compromised and exposing private data

Cybersecurity researcher uncovers faulty system used by hotels in the Middle East surrendering personal information on millions of guests worldwide.

Pakistani cybersecurity researcher Etizaz Mohsin was in a hotel room in Qatar when he unexpectedly discovered a technical vulnerability in its internet system that exposed the private information of hundreds of hotels and millions of guests worldwide.

Mohsin told Al Jazeera he was “stunned” by what he uncovered late last year.

“I found out that there is a service running rsync [file synchronization tool], which allows me to dump the files of the device to my own computer,” Mohsin explained. “I was able to access the sensitive information of all other hotels which were using the FTP [file transfer protocol] server for backup purposes.”

From his hotel room he was able to obtain network configurations of 629 major hotels across 40 countries, and the personal information of millions of guests, including their room numbers, emails, and dates they checked in and out of the hotel.

The data included that of major hotel chains across the Middle East and North Africa region, including the Kempinski, the Millennium, Sheraton, and St Regis in Qatar, Turkey, the United Arab Emirates (UAE), Saudi Arabia, Lebanon, Egypt, Bahrain, Oman, Jordan, Kuwait and Bahrain.

The hotels all use an internet system called HSMX Gateway by British company AirAngel. Its clients are among the largest hotel brands worldwide.

This is common practice; most hotels, malls, restaurants, and cafés require people to create an account and fill their information after connecting to the internet in order to start using it. However, it is not without its risks.

“A public WiFi network is fundamentally less secure than one you use at home,” Mohsin explained. “It allows hackers to monitor and intercept data sent across the link, giving them access to sensitive information such as banking credentials and account passwords.”

The HSMX Gateway incident is similar to a vulnerability in hotel routers researchers discovered seven years ago, which affected 277 devices in hotels and convention centres in the United States, Singapore, the United Kingdom, the UAE, and 25 other countries.


‘Stakes are high’


Cybersecurity consultant Ragheb Ghandour told Al Jazeera the ease of access to this data, especially with how centralized it is among hundreds of hotels, is a huge cause for concern.

“Let’s say a spy checks into one of these listed hotels, skims through the files and finds a point of intrusion. They could modify – or mirror – the landing page for the WiFi connection and all the clients of the hotel would send their information straight to them,” Ghandour said. “The stakes are high. You could wreak havoc through the hotel.”

It is not just guests’ personal information that is at risk. Mohsin said a hacker could use the vulnerability to access the guests’ computer and mobile devices, as well as the hotel’s security footage, ventilation systems, and electronic door locks.

In fact, assassins used a vulnerability in a luxury hotel’s internet to unlock an electronic door and carry out a targeted killing in Dubai 12 years ago.

In 2010, a hit squad, reportedly members the Israeli Mossad intelligence agency, assassinated senior Hamas official Mahmoud al-Mabhouh at a luxury hotel in the Emirati city after hacking the key system to enter al-Mabhouh’s room.

AirAngel said in a statement it stopped updating its software in November 2020, and the firm encouraged clients to replace it with a new service called Captivnet. The issue with the previous service remains unfixed, however.

AirAngel added only a small number of clients have not migrated to Captivnet and still use HSMX Gateway. But more than half of the hotels Mohsin discovered compromised continue to use the service.

Of the 629 hotels Mohsin found with faulty internet protection, 378 have not switched to AirAngel’s new service, including more than 100 in the UAE, Saudi Arabia, Qatar, Lebanon, Egypt, and other countries across the MENA region, he said.

Mohsin said he hopes his findings will encourage more people to improve their digital security.

“Always a use a VPN to encrypt all your data as it travels via the network via secure tunnel,” he explained. “Alternatively, you might use mobile data [instead of WiFi] to avoid the dangers in the first place.”


Comments

Oh ya 2 year ago
And people believe that their crypto is also safe from the bad people and the government. Just ask the people in Canada that donated to the truckers and had their bank account stolen. Play stupid games win stupid prizes

Newsletter

Related Articles

0:00
0:00
Close
Unelected PM of the UK holds an emergency meeting because a candidate got voted in… which he says is a threat to democracy…
Farmers break through police barriers in Brussels.
Ukraine Arrests Father-Son Duo In Lockbit Cybercrime Bust
US Offers $15 Million For Info On Leaders Of Cybercrime Group Lockbit
Apple warns against drying iPhones with rice
Alexei Navalny: UK sanctions Russian prison chiefs after activist's death
German economy is in 'troubled waters' - ministry
In a recent High Court hearing, the U.S. argued that Julian Assange endangered lives by releasing classified information.
Tucker Carlson says Boris Johnson wants "a million dollars, in Bitcoin or cash, from Tucker Carlson to talk about Ukraine.
Russia is rebuilding capacity to destabilize European countries, new UK report warns
EU Commission wants anti-drone defenses at Brussels HQ
Von der Leyen’s 2nd-term pitch: More military might, less climate talk
EU Investigates TikTok for Child Safety Concerns
EU Launches Probe Into TikTok Over Child Protection Under Digital Content Law
EU and UK Announce Joint Effort on Migration
Ministers Confirm Proposal to Prohibit Mobile Phone Usage in English Schools
Avdiivka - Symbol Of Ukrainian Resistance Now In Control Of Russian Troops
"Historic Step": Zelensky Signs Security Pact With Germany
"Historic Step": Zelensky Signs Security Pact With Germany
Russian opposition leader Alexey Navalny has died at the Arctic prison colony
Tucker Carlson grocery shopping in Russia. This is so interesting.
France and Germany Struggle to Align on European Defense Strategy
‘A lot higher than we expected’: Russian arms production worries Europe’s war planners
Greece Legalizes Same-Sex Marriage and Adoption Rights
Russia "Very Close" To Creating Cancer Vaccines, Says Vladimir Putin
Hungarian Foreign Minister: Europeans will lose Europe, the Union's policy must change drastically
Microsoft says it caught hackers from China, Russia and Iran using its AI tools
US Rejects Putin's Ceasefire Offer in Ukraine
The Dangers of Wildfire Smoke and Self-Protection Strategies
A Londoner has been arrested for expressing his Christian beliefs.
Chinese Women Favor AI Boyfriends Over Humans
Greece must address role in migrant vessel disaster that killed 600: Amnesty
Google pledges 25 million euros to boost AI skills in Europe
Hungarian President Katalin Novák Steps Down Amid Pardon Controversy
Activist crashes Hillary Clinton's speech, calls her a 'war criminal.'
In El Salvador, the 'Trump of Latin America' stuns the world with a speech slamming woke policing after winning a landslide election
Trudeau reacts to Putin's mention of Canadian Parliament applauding a former Ukrainian Nazi in his interview with Tucker Carlson.
The Spanish police blocked the farmers protest. So the farmers went out and moved the police car out of the way.
Volodymyr Zelenskiy fires top Ukraine army commander
Tucker Carlson's interview with Vladimir Putin raises EU concerns
Finnish Airline, Finnair, is voluntarily weighing passengers to better estimate flight cargo weight
Russia's Economy Expands by 3.6% Due to Increased Military Spending
Ukraine MPs Vote To Permit Use Of Dead Soldiers' Sperm
German Princess Becomes First Aristocrat To Pose Naked On Playboy Cover
UK’s King Charles III diagnosed with cancer
EU's Ursula von der Leyen Confronts Farmer Protests Amid Land Policy Debates
Distinguishing Between Harmful AI Media and Positive AI-Generated Content: A Crucial Challenge for the EU
Tucker Carlson explains why he interviewed Putin
Dutch farmers are still protesting in the Netherlands against the government, following the World Economic Forum's call for 'owning nothing.'
Hungarian Prime Minister Viktor Orbán stands up for European farmers and says, 'Brussels is suffocating European farmers.
×