Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Drive-By Pharming: This Nasty Attack Technique Looks Significant


Posted by George Hulme, Jan 23, 2008 01:08 PM

The first time I learned of the concept of drive-by pharming was when reading about a presentation given by application security expert Jeremiah Grossman at Black Hat in mid-2006. It's a concerning attack technique, not just because it enables an attacker to do nasty things, but also because of how passively Web users can become victimized. Until very recently, this attack was merely theoretical.


According to security firm Symantec, it has seen the attack under way in the real world. And in order to get nailed with this, all you need is to have the factory-set password in place, and click on the wrong Web page, or simply view the wrong e-mail, since the attack is most often inflicted through specially crafted HTML or JavaScript.

The attacker then reconfigures the targeted router's DNS server settings. Now, the attacker effectively controls the victim's Internet connection. According to Symantec, the attack they spotted redirects users trying to access a popular Mexican bank's Web site in Mexico to a malicious Web site instead.

That makes this attack so dangerous to not only anyone who has failed to reset their factory router passwords, but anyone who visits a site managed by anyone who also has failed to do the same.

On its blog, Symantec goes into more detail, and lists some things that can be done to protect yourself. Things that should already have been done in the first place: stay away from untrustworthy sites, don't blindly click links in e-mail, and change the default router password. Let's hope many home users and business do the latter. Like, now.

« Who's Afraid Of A Little Recession? | Main | Intel Blog Warns Of Multicore Crisis »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.