The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Drive-By Pharming: This Nasty Attack Technique Looks Significant


Posted by George Hulme, Jan 23, 2008 01:08 PM

The first time I learned of the concept of drive-by pharming was when reading about a presentation given by application security expert Jeremiah Grossman at Black Hat in mid-2006. It's a concerning attack technique, not just because it enables an attacker to do nasty things, but also because of how passively Web users can become victimized. Until very recently, this attack was merely theoretical.


According to security firm Symantec, it has seen the attack under way in the real world. And in order to get nailed with this, all you need is to have the factory-set password in place, and click on the wrong Web page, or simply view the wrong e-mail, since the attack is most often inflicted through specially crafted HTML or JavaScript.

The attacker then reconfigures the targeted router's DNS server settings. Now, the attacker effectively controls the victim's Internet connection. According to Symantec, the attack they spotted redirects users trying to access a popular Mexican bank's Web site in Mexico to a malicious Web site instead.

That makes this attack so dangerous to not only anyone who has failed to reset their factory router passwords, but anyone who visits a site managed by anyone who also has failed to do the same.

On its blog, Symantec goes into more detail, and lists some things that can be done to protect yourself. Things that should already have been done in the first place: stay away from untrustworthy sites, don't blindly click links in e-mail, and change the default router password. Let's hope many home users and business do the latter. Like, now.

« Who's Afraid Of A Little Recession? | Main | Intel Blog Warns Of Multicore Crisis »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Verizon: $350 ETF Is A Go
  4. Motorola Explains Why Droid Doesn't Have Multi-Touch


  1. Florida Hospital Dials Up iPhones For Nurses
  2. Full Nelson: A Web Presence Needs Sizzle, My Nizzle
  3. Is Antivirus Software Dead?
  4. Practical Analysis: The Fastest-Growing Security Threat
  5. InformationWeek Analytics Research: Federated Search
  6. Securing The Cyber Supply Chain

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007