Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 15 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Drive-By Pharming Hits Home Routers
EH-Net
May 24, 2012, 01:54:59 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Drive-By Pharming Hits Home Routers  (Read 3524 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 3915


Editor-In-Chief


View Profile WWW
« on: February 24, 2007, 10:58:28 PM »

Quote
New Drive-By Attack Taking Over Home Routers

By Sharon Gaudin,
06:39 PM ET, Feb 15, 2007

Researchers at Symantec are warning users that if they haven't changed the default password on their home wireless router, they should finally just DO IT.

Symantec's Zulfikar Ramzan issued a warning Thursday that hackers are lacing phony Web sites with malicious code that actually will log into and mess with your home broadband router. He's coined a term for it: Drive-By Pharming.

"I believe this attack has serious widespread implications and affects many millions of users worldwide," wrote Ramzan in his blog
on Symantec's Security Response Weblog Thursday morning. "Fortunately, this attack is easy to defend against, as well."

Now, here's the thing. How long have security types been telling us to be smart about our passwords, whether the passwords are for our laptops, our smartphones, or our home routers? It's not a new call to arms. But, obviously, it's one we all need to hear again.

Here's how Ramzan, and his fellow researchers, Sid Stamm and Markus Jakobsson of the Indiana University School of Informatics, say the new problem goes: Attackers build a fraudulent Web page that, simply when viewed, results in substantive configuration changes to your home broadband router or wireless access point. They add malicious JavaScript code to the page.

"When the Web page is viewed, this code, running in the context of your Web browser, uses a technique known as 'Cross Site Request Forgery' and logs into your local home broadband router," explains Ramzan. "Now, most such routers require a password for logging in. However, most people never change this password from the original factory default. Upon successful login, the JavaScript code changes the router's settings. One simple, but devastating, change is to the user's DNS server settings."

Once they mess with your router, the attackers have control over it, allowing them to direct you and your browser to whatever Web sites they choose. You may want to go to, say, Hack in the Box but, instead, you'll go to whatever site they want to send you to. (For more technical details about the attack, check out Ramzan's blog.)

Think about it. That could be bad. If you have kids using your home computer, do you suddenly want a hacker in charge of what Web site they're going to? It also can be dangerous. You could be surreptitiously diverted to another fraudulent Web site where you might divulge personal financial information, be infected by another round of Trojans, or unknowingly hand out critical company information.

So, it's another reminder to be smart about our passwords. I, myself, could be smarter about them. I'm trying but I still need to be better. Ramzan's warning serves as a good lesson about a new kind of attack, and a good reminder.

Original story:
http://www.informationweek.com/blog/main/archives/2007/02/new_driveby_att.html

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Kev
Guest
« Reply #1 on: February 25, 2007, 11:31:52 AM »

An excellent example of how crafty hackers can be. Its sad to think such talent is used that way.  Using fake websites is very effective and growing more and more and the Ethical hacker should have that in his arsenal.  You can do so many things now with them. A new favorite trick is to have a user click on your website and actually turn their browser into a port scanner that will enumerate servers and services on a network, while bypassing the firewall.  You can actually map out the entire organizations network. It’s a good way to test policies in an organization. Poor policies are still the easiest way to breach security if all else fails.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.131 seconds with 25 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.