NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Technology / Connectivity

Connectivity


Web Pages Can Hijack Your Home Router

All the code exploits rely on human error, though

By Bogdan Botezatu, Hardware Editor

8th of April 2008, 12:06 GMT

Adjust text size:


Most of the existing routers are running with default passwords
Enlarge picture
A group of researchers will demonstrate, later today, a method of hijacking an average home router using a plain web page infected with an undetectable object. Dan Kaminsky is a specialist in security that researched on the
browser-specific flaws that allow attackers to get behind the users' firewalls.

According to the security group, the browsers' interaction with the Domain Name System (DNS) affect a range of common routers, such as the units manufactured by Cisco's Linksys division and D-Link. The hijacking technique is called a DNS rebinding attack, and affects a wide range of consumer electronics, including printers, that work with a default administrator password.

Kaminsky, director of penetration testing with IOActive, claims that the attack can be performed when the victim visits a malicious Web page running a malicious JavaScript code.

The tiny script implemented in the webpage forces the browser to perform changes on the router's web-based interface. The changes include altering the remote administration policies, or even re-flashing the router's firmware to send it back into the default state.

DNS rebinding attacks are extremely complex, and maybe that is why there are few skilled hackers to take over the users' networks. However, the main flaw is in the way the browser handles the DNS protocol.

The attack is not new at all, but today's demonstration is intended to prove that it can be reproduced in a real-world environment. Moreover, Kaminsky wants to draw users' attention that lack of cautiousness can lead to unfortunate side-effects. "I'm always a fan of when something that's theoretical gets made real, because it makes people act," said David Ulevitch, CEO of DNS service provider OpenDNS.

Beyond hardware and software flaws, the key factor in a successful attack is users' lack of concern towards security. Many of the currently deployed routers are still "protected" with the default admin password, despite the manufacturers' advising the users to change it immediately.

For instance, Linksys routers force users to change the password as part of the initial setup. "One of the first things that our setup software does is change that default name," said Trevor Bratton, a spokesman for Linksys. "So anyone who does as we ask with the initial setup will be prompted to change that."

TAGS:

Router | DNS | hijack | security | connectivity
Read by 2,037 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Cisco: Your Copy of Network Router is Not Genuine!

Hitachi to Release 320 GB Notebook Hard-Disk Drive

Duke University Has World's Largest Individual Wireless Network

Actiontec MegaPlug AV200: Ethernet-Over-Powerlines Strikes Back

Delkin's ImageRouter: The UDMA CF Chain Card Reader

Juniper to 'Switch' to Enterprise-Class Networking Gear

Covergence to Regret the Absence of x86-Based Network Routers

US Federal Trade Commission to Defend the Ethernet Standard

Birmingham and the OLPC: We Have the Laptops, But We Need Wireless Access!

Keep an Eye on Your Router: It May Lead You On a Wrong Way!

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM