Nov
21
2008
Today
 

access   avg   backup   business   click   computer   customers   data   files   information   internet   into   its   microsoft   network   not   online   security   server   service   services   singapore   site   software   spector   tape   text   users   vista   web   windows  

Created with AkoCloud 1.1 final.

Subscribe Newsletter

Subscriber List


Receive HTML?

WebSearch Here
Translate This Website
 
Microsoft Kills Live OneCare   Infamous Vendor Of AntiVirus XP Badware Sued   About Stellar Information   Sony Recalls 440,000 Vaio Laptops   Promotions   What is Blogging... Exactly?   Marketing Services for the Internet   What You Should Know About Ecommerce Web Hosting   Why You Need A Computer Firewall   Getting Backlinks The Easy Way   CCTV Home Security   FrontPage   Beware Of Malicious Fake Adobe Flash Player   Pacific LANWorks Awarded As AVG Gold Reseller   Alibaba Retains Its Independence To Yahoo
Pinnacle Studio Ultimate Version 11
Symantec Warns Of Router Compromise PDF Print E-mail
Sunday, 27 January 2008

Security company Symantec has warned of an attack involving the subversion of routers.



The security company said this was the first time it had seen such an attack "in the wild," although the concept had been discussed a year ago by Symantec researchers, according to a Symantec blog post.


Acronis Disk Director 10.0


In the attack, which targeted users of an undisclosed Mexican bank, the intended victims received a spam e-mail claiming they had received an e-card, directing them to gusanto.com, a Spanish-language e-card site. However, the e-mail also had embedded HTML image tags that contained an HTTP get-request to the router to change its Domain Name System settings, according to Symantec's U.K. manager of quality assurance, Thomas Parsons.

The HTTP get-request redirects traffic flowing over the router to a specific IP address when the user attempts to access six domain names that are banking-related. Symantec requested that ZDNet UK not publish the IP address.

The attack is made possible by a cross-site scripting vulnerability in routers made by broadband-equipment company 2Wire that was reported in August last year, according to Symantec. Parsons said this was "a simple hack" and advised small to medium-size businesses to change default security settings on routers and educate users about clicking on suspicious links.







Article extracted from ZDNet.




Reddit!Del.icio.us!Facebook!Slashdot!Netscape!Technorati!StumbleUpon!Newsvine!Furl!Yahoo!Ma.gnolia!Free social bookmarking plugins and extensions for Joomla! websites!
 
< Prev   Next >