Network World
Friday, August 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

RE: First case of "drive-by pharming" identified in the wild

This is why I offer everyone I work with and people I do work for to configure their equipment for them. Most people will buy it, plug it in and go. Very bad idea.

Click to read the article this is in response to.

Good for you, Willie

0

You are a good man.

Actually thats not the

0

Actually thats not the problem and of course neither a solution...

The vulnerability consists in that via a bug inside the configuration wizard and attacker can overwrite the current admin password...
So the victim just need to see a simple image or flash or iframe, etc... and the modem password will be changed without even you notice, obviously after this the attackers send the necessary commands to add the dns resolve routes to the fraudulent bank site.

All this of course without you even notice, cause like i say before you just need to open any website and bang! you will be instantly driving-by-pharming.

So it doesn't bother that you have a 64 digits with alphanumeric + special chars or a really huge pass phrase in other to protect of these attacks, cause this is a flaw in the modem, this is a really major issue inside the 2wire modems and many other manufacturers that have same issues...

Not the UPnP vulnerability then?

0

So this attack is dependent on factory password authentication and not a result of the well publicised UPnP vulnerability which of course requires nothing other than UPnP to be enabled which is a default setting on most home routers and access points?

sounds to be similar

0

People must learn to change

0

People must learn to change their router's password and take this security risk seriously.

Router Passwords

0

I have an idea.

What if the routers came from the vendor, pre-configured with a default password, one that involved say the serial number of the device? It would be unique, it would be immediately available to the user. If the user wanted to change it or remove it, then that was HIS business.

Not great, but better than "password" or no pasword at all.

User set up vs. Admin

0

Routers are new to me.. But I learned that my USER ID & PWD in my router is set by my ISP.... no way to manage that except routinely ask them for a new install?

Then I learned that the "Router PWD" CAN be managed by me. No one said that as I installed the Linksys router...

SO, change the Router PWD is about all I can do re: Diarming the 'PHarmers', right?

Cheers,

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Latest security headlines from Network World:

China Netcom falls prey to DNS cache poisoning

Lockdown monitors the security of your computer

Analyzing fundamental flaws: Opening vs. unlocking

Nokia admits security flaws in Series 40 OS

DeviceLock counters USB stick menace with alliance

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: