Technology, Discovery & Innovation
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Computing Digital Life Discovery Space More Topics...
Data Security
Average Rating:
Rate this article:  
Millions Vulnerable to New Hack Attack Millions Vulnerable to New Hack Attack
By Elizabeth Millard
February 19, 2007 10:25AM

Bookmark and Share
Drive-by pharming is dangerous not only because it directs users to malicious sites, but also because an attacker can permanently change router settings, exposing unwitting victims to ongoing attacks. Symantec recommends that users change their default router passwords and employ a multilayered security strategy.
 


Security firm Symantec and the Indiana University School of Informatics have discovered a new type of security threat that could leave up to 50 percent of home broadband users susceptible to attack.

Called "drive-by pharming," the threat is focused on home routers, which can be reconfigured and directed to a malicious Web site if default settings and passwords are being used.

With traditional pharming, an attacker redirects a user from a legitimate Web site to a bogus Web site that contains malicious code. Pharming attacks can be executed by either changing the host file on a victim's PC or manipulating a domain name system Relevant Products/Services (DNS) server Relevant Products/Services.

In the new scheme, when a user visits a malicious Web site, an attacker is able to remotely change the DNS settings on the broadband router or wireless access point and reroute requests for legitimate sites -- like online banking sites or financial institutions -- to bogus sites designed to steal login information.

Default Passwords

The security team that examined the issue believes that the problem potentially affects millions of broadband users worldwide, and that the attacks can be easily launched. The researchers urged users to protect their broadband routers and wireless access points by changing their default passwords.

Drive-by pharming is dangerous not only because it directs users to malicious sites, but also because an attacker can permanently change router settings, exposing unwitting victims to ongoing attacks.

"This new research exposes a problem affecting millions of broadband users worldwide," Oliver Friedrichs, director of Symantec Security Response, said in a statement. "Because of the ease by which drive-by pharming attacks can be launched, it is vital that consumers adequately protect their broadband routers and wireless access points today."

Symantec recommends that users should change their default passwords and= employ a multilayered security strategy consisting of an Internet security program that combines antivirus, firewall, intrusion detection, and vulnerability protection. Also important, the research team noted, is avoiding clicking on links that seem suspicious.

User Education

But the main issue, according to Sophos senior technology consultant Graham Cluley, is that many users either do not change settings or use the password supplied by the manufacturer. Many devices are given obvious passwords for shipping and setup, such as "administrator" or "password," which Cluley noted are very easy for hackers to guess.

"For the sake of thirty seconds' effort, home users may be leaving themselves dangerously open to attack by not changing their passwords," he said.

While the great likelihood of attack predicted by Symantec could have some effect on user education, Cluley said he hopes that router makers will also take notice and design their software to be more insistent about changing default passwords.

"More prominent warnings that passwords have not been changed from their default might help encourage users to take this relatively simple step," he said. An additional line of defense is to disable JavaScript on untrusted Web sites, he added.
 

Tell Us What You Think
Your Comment:



Advertisement


 Data Security
1.   China Busted Hacker-Training Site
2.   FBI Tackles Haiti-Relief Scams
3.   Patch Tuesday Will Tie MS Record
4.   Google Apps Controls Mobile Devices
5.   Torrent Traps Used To Harvest Logins


advertisement
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Google Attack Highlights Black MarketGoogle Attack Highlights Black Market
Paying for bug info is hotly debated.
Average Rating:


advertisement

Enterprise Hardware Spotlight
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
Sci-Tech Today
Home/Top News | Computing | Digital Life | Discovery | Space | Innovation | Health | Science News
Environment
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.