Browser Hack Allows Router Control – To be demonstrated at RSA Security Conference

In: Site Feeds| VoIP| broadbandreports.com

8 Apr 2008


Researcher Dan Kaminsky today will show attendees of the RSA security conference how a Web-based attack can be used to seize control of routers, notes PC World. Kaminsky has spent the past year studying how browser design flaws allow someone to abuse the Domain Name System (DNS) in order to get around firewalls. According to Kaminsky, the “DNS rebinding attack” (so far just theory never demonstrated in the real world) should work on many major routers and some printers:

Here’s how it would work. The victim would visit a malicious Web page that would use JavaScript code to trick the browser into making changes on the Web-based router configuration page. The JavaScript could tell the router to let the bad guys remotely administer the device, or it could force the router to download new firmware, again putting the router under the hacker’s control.

Of course changing your default router password might just be a good idea, you think?

Although this particular attack takes advantage of the fact that routers often use default passwords that can be easily guessed by the hacker, there is no bug in the routers themselves, Kaminsky said. Rather, the issue is a “core browser bug,” he said.

OpenDNS today is supposed to offer users of its free service an easy way to prevent this type of attack.
read comment(s)

Comment Form

Advertising


Featured Message


The Internet has come a long way since its birth. There are now several different ways to get an internet connection. One can do this by inserting wireless internet card in computer or can use dsl. Apart from this, internet phone and ip phones are there as well to help people connect internet through phones. internet phone is not the last option available, wireless internet providers are there as well to offer internet connectivity.


Buy cell phone accessories 70% off retail.


Sponsors


HardCE.com - Apple iPhone and iPod Touch cases, solar cases and battery cases Universal Mind Inc. All-Natural Body and Health Products
Advertise with Remove The Labels Smartlive

Categories

Archives

Twitter Updates