Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Actually thats not the

0

Actually thats not the problem and of course neither a solution...

The vulnerability consists in that via a bug inside the configuration wizard and attacker can overwrite the current admin password...
So the victim just need to see a simple image or flash or iframe, etc... and the modem password will be changed without even you notice, obviously after this the attackers send the necessary commands to add the dns resolve routes to the fraudulent bank site.

All this of course without you even notice, cause like i say before you just need to open any website and bang! you will be instantly driving-by-pharming.

So it doesn't bother that you have a 64 digits with alphanumeric + special chars or a really huge pass phrase in other to protect of these attacks, cause this is a flaw in the modem, this is a really major issue inside the 2wire modems and many other manufacturers that have same issues...

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: