Is it possible that your home broadband router could be hijacked by malicious threat-mongers? Definitely, and quite easily according to a report and white paper from Symantec and the Indiana University School of Informatics. The two today detailed a new JavaScript-based security threat dubbed “Drive-by Pharming” and said such an attack could hit up to 50% of home broadband users. The bottom line: If you haven’t changed the default password on your home router, do it now, Symantec said. According to researchers, drive-by pharming lets a hacker change the DNS settings on a user’s broadband router or wireless access point. The attack is possible whenever a broadband router is not password protected or the attacker manages to guess the password. Most routers come with a default password and if you don’t change it, well, you leave your home network up for grabs, the companies say. Then the victim would have to visit a malicious Web site that served up the JavaScript. In tests, the researchers were able to do things like change firmware and redirect a D-Link Systems Inc. DI-524 wireless router to look up Web sites from a Domain Name System server of their choosing. Or instead of downloading legitimate Microsoft software updates, for example, they could be tricked into downloading malware. Instead of online banking, they could be giving up sensitive information to phishers.They describe these attacks in a paper, authored by Sid, Stamm and Markus Jakobsson of Indiana University, and Symantec’s Zulfikar Ramzan. According to a Symantec press release: Existing security offerings cannot protect against this type of attack since drive-by pharming targets the user’s router directly, and the existing products only protect the user’s computer system. “Owners of home routers who set a moderately secure password – one that is non-default and non-trivial to guess – are immune to router manipulation via JavaScript,” the paper states. According to the IDG News Service story, both Cisco and D-Link said they’ve taken steps to avoid this type of security problem. Over the past few years they’ve introduced step-by-step “wizard” software to configure their routers, and these products always suggest that the user come up with a unique password.
“Drive-by” Web attacks could hit home routers
Opinion
Feb 16, 20072 mins




