On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner , ZDNet (UK)
Posted on ZDNet News: Jan 24, 2008 9:10:00 AM

Security company Symantec has warned of an attack involving the subversion of routers.

The security company said this was the first time it had seen such an attack "in the wild," although the concept had been discussed a year ago by Symantec researchers, according to a Symantec blog post.

In the attack, which targeted users of an undisclosed Mexican bank, the intended victims received a spam e-mail claiming they had received an e-card, directing them to gusanto.com, a Spanish-language e-card site. However, the e-mail also had embedded HTML image tags that contained an HTTP get-request to the router to change its Domain Name System settings, according to Symantec's U.K. manager of quality assurance, Thomas Parsons.

The HTTP get-request redirects traffic flowing over the router to a specific IP address when the user attempts to access six domain names that are banking-related. Symantec requested that ZDNet UK not publish the IP address.

The attack is made possible by a cross-site scripting vulnerability in routers made by broadband-equipment company 2Wire that was reported in August last year, according to Symantec. Parsons said this was "a simple hack" and advised small to medium-size businesses to change default security settings on routers and educate users about clicking on suspicious links.

Tom Espiner of ZDNet UK reported from London.

©2007 CNET Networks, Inc. All rights reserved. CNET , CNET.com , and the CNET logo are registered trademarks of CNET Networks, Inc. Used by permission.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 2 Talkback(s)
Norton full scan
Symantec should also look back into the way Norton full scan system functions. It takes 12 -24 hours to scan even a laptop computer. Contacting Symantec to report the problem is not easy
R.Venkataraman... (Read the rest)
Posted by: ramudu_v@... Posted on: 01/25/08 You are currently: a Guest | | Terms of Use
Norton full scan  ramudu_v@... | 01/25/08
Norton full scan  ramudu_v@... | 01/25/08

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here