R E L A T E D   C O N T E N T
ADVERTISEMENT

Researchers craft first RFID virus

RFID systems open to viruses

Tom Sanders in California, vnunet.com 15 Mar 2006
ADVERTISEMENT

Researchers at the VU Amsterdam university claim to have crafted the world's first RFID viruses and worms.

Organisations are using or looking to use the wireless identification tags at checkout stands in stores, for inventory control in warehouses or for luggage tagging and routing at airports.

In an airport scenario, one maliciously crafted tag on a suitcase could infect the scanning system, which could then be instructed to spread the exploit code to all suitcases in the system. This could cause a global RFID infection within 24 hours, researcher Melanie Rieback cautioned.

As the wireless tags are scanned, a specially crafted tag could inject infected code into the middleware, exploiting security vulnerabilities in components such as the web server or database, researcher Rieback demonstrated on Wednesday at the IEEE Conference on Pervasive Computing and Communications in Pisa, Italy.

The tag could also embed javascript to execute code on RFID systems incorporating web based components. The Javascript code could instruct the system to surf to a specific internet address hosting a malicious payload, or for instance format the system's hard drive.

Another possible attack method would be to launch a buffer overflow attack against the RFID reader. The sensor networks typically don't expect buffer overflow attacks because an RFID tags offers only a limited storage capacity, but it could be used to cause a system crash.

RFID worms require careful programming. Because of the limited storage space available, attackers will most likely create code that instructs the system to download additional exploit code off the internet.

Rieback recommended that software engineers pay close attention to how they design RFID systems. They should use security practices that are common in other software implementations, such as limiting privileges for applications and the removal of features that aren't required.

The university has published a special website on RFID viruses, which also offers a ten-page paper on the subject that has been submitted to the IEEE. 

See also:

The slow roll-out of RFID contrasts sharply with the optimism of a year agoPharmaceutical industry will not roll out RFID as quickly as predicted  08 Feb 2006
Asia PacificThai $1.87bn telecoms deal 'illegal'; China RFID use grows  27 Jan 2006
Radio Frequency IDStill early days but adoption increasing, says IDC  16 Jan 2006
RFIDCuts need for tinfoil hats  16 Jan 2006

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities