Send press releases, job openings & all inquiries to info@pugetsoundradio.com


Puget Sound Radio Communicates - Banner Advertise with PSR and get results! Contact: Michael Easton


I Hear You Knockin' (And You Can Probably Come In)
Welcome, Guest. Please login or register.




Puget Sound Radio Dot Com    Puget Sound Radio's "Computer World"    Computer World  ›  I Hear You Knockin' (And You Can Probably Come In)
Users Browsing Forum
bigtalker, NBeaconIsBack and 3 Guests

I Hear You Knockin' (And You Can Probably Come In)  This thread currently has 230 views. Print
1 Pages 1 Recommend Thread
Scott James
February 18, 2007, 1:19pm Report to Moderator

Maximum Member
cyber world dot ca
I’ve talked many times about the sorry state of security on home networking equipment. For instance, if you leave most wireless networks in their factory configuration, anyone can connect without a password, which is the equivalent of leaving your front door open.  As well, the username to administer the system will probably be admin, and the password for that will probably be blank – and that’s the scary part.  

When you type the name of a website into your browser, your system looks up the unique numerical IP address for the site using one or more of the Internet’s Domain Name System servers, which are like massive electronic telephone books.  Using a technique called pharming, it’s possible for a remote attacker to get into the unsecured network and make the firmware on the router update itself and use a fake DNS server.  The fake server then points the browser to a fake website – so, when you type in “mybank.com”, you end up at a site which looks just like your bank site, but which is actually a phishing site. Type in your username and password, and you’ve just handed your identity over to the bad guys.  

All of this is made possible by building a web page with malicious Javascript code on it.  A user with an unsecured network would merely have to view the page to fall victim to it; their router would be automatically reconfigured without their knowledge.  And knowing that the majority of users leave their wireless networks in their unprotected factory configuration, it’s a sure bet that someone is building one of those malicious web pages right now.  

Read more about drive-by pharming in the Symantec Enterprise Security Response Blog.


PSR Administrator
Logged
Private Message
1 Pages 1 Recommend Thread
Print

Puget Sound Radio Dot Com    Puget Sound Radio's "Computer World"    Computer World  ›  I Hear You Knockin' (And You Can Probably Come In)



Powered by E-Blah Forum Software 10.3.6 © 2001-2008