New Attack Hijacks DNS Traffic From 300,000 Routers
nk497 writes "Florida-based security firm Team Cymru said it was examining a widespread compromise"of 300,000 consumer and small office/home office (SOHO) routers in Europe and Asia. The DNS server settings were changed to a pair of IP addresses, which correspond to Dutch machines that are registered to a company that lists its address in central London. The attack highlights the flaws in router firmware, the researchers said. 'It's not new as an issue to the InfoSec community but this is one of the biggest we've seen recently as it's quite insidious,' Cymru's Steve Santorelli said, adding the hack could let the attackers conduct man in the middle attacks, impersonating your bank, for example."
All you need is a knack for numbers, misanthropy, and a total lack of conscience.
That exact same link is in the summary.
You were in such a hurry to get first post that you didn't read the summary.
If you're a zombie and you know it, bite your friend!
And just how are these 300,000+ routers being reprogrammed to use alternate malicious DNS settings? Is this conducted via some common firmware exploit, or dumb users leaving default admin password in place?
Life is not for the lazy.
My bank is secure!!1!!!!
Between generous application of padlock gif's designed to make me feel safe and account specific image letting me know I'm logging into my bank and not some imposter bank... it would be impossible to get hacked. They even say so on their web site.
Remember years ago feeling board and actually getting ahold of one of their "IT" guys informing him of the dangers of requesting credentials directly from a home page loaded via HTTP... His response was ... drumroll... it is posted to a secure site so the credentials are encrypted and can't be compromised.
There is no arguing with stupid or those who willfully subvert browser security features for marketing and or checking off security boxes on the compliance chart even if you (should) know better.
Excuse me? Not my bank. My bank brings up a secure photo from one server and a secure message from another while logging in. If I do not see on the login screen the image and the text, it's not my real banking page no matter what the URL says in the address bar. It'd have to be such an unbelievably targeted attack to intercept the real page and replace it after the fact that it's not likely.
Could it be the chances of grabbing a really fast internet connection are better there than in the US?
In any case, my thanks to the OpenWrt folks!
208.67.222.222 and 208.67.220.220 .
and make http://www.opendns.com/welcome/ your homepage
Client settings should override router defaults
To be even safer use OpenWRT https://en.wikipedia.org/wiki/OpenWrt
No I'm not!
Great questions. Both happen to be answered in the .pdf linked.
Unless its ok for a legit company to use a multiple mailbox/remailer as a company hq and be linked with organised crime (google the ip addresses)
I read other places that some Linksys routers had a firmware flaw allowing control. So I wonder if this is related? The solution I believe that helps is to
manually set your DNS server addresses rather then having the DNS setting on your router set to automatically set DNS.
I generally do this anyway because I don't use Comcast DNS but Open DNS instead.
Was this attack done only on the IPv4 addresses of routers, or on the IPv6 addresses of dual stack routers as well? Just wondering whether that could have been averted that way.
Wondering whether this attack would have overlooked routers that were on IPv6-only networks
That's forming a bank, not impersonating one
Alright wiseguy, share with us details on how to impersonate a bank then ...
Muchas Gracias, Señor Edward Snowden !
Am I right in thinking that this would be mitigated by use of openDNS, or google's 8.8.8.8 or similar?
Thanks GCHQ. :|
I'm in the process of phasing mine out and building one with Debian (working on it today). Pretty scary.
I would say it's most likely a state agency involved in this.
"If any question why we died, Tell them because our fathers lied."
Verizon set thousands of home routers to the same password (which was "Password" plus a single digit number, BTW) when they rolled out FIOS in my area. A year later a worm ripped through them all and most of them are still compromised today.
Think about it; ISPs aren't any more likely to do a good job than a generic idiot who has a bank account at stake.
Is there any way to tell if your router has been compromised?
Proverbs 21:19
http://tech.slashdot.org/comme...
http://tech.slashdot.org/comme...
http://news.slashdot.org/comme...
http://it.slashdot.org/comments.pl?sid=4854243&cid=46397079
http://tech.slashdot.org/comme...
http://tech.slashdot.org/comments.pl?sid=4829029&cid=46367461
http://tech.slashdot.org/comme...
"Eating your words" (& my dust) after THIS I see -> http://tech.slashdot.org/comments.pl?sid=4829029&cid=46338565
* :)
(See how the "damaged fragile ego" of these "wannabes" like marsu_k react, 'stalking you' IF & WHEN you "get the better of them" on what THEY *think* is "their ballcourt"... lol, too bad marsu_k had to 'eat it' the way he did (his words, & MY DUST!!!)).
APK
P.S.=> Eat your words & "eat my dust" chump... you failed as always!
... apk
& my dust after THIS -> http://tech.slashdot.org/comments.pl?sid=4829029&cid=46338565
* :)
(See how the "damaged fragile ego" of these "wannabes" like marsu_k react, 'stalking you' IF & WHEN you "get the better of them" on what THEY *think* is "their ballcourt"... lol, too bad marsu_k had to 'eat it' the way he did (his words, & MY DUST!!!)).
APK
P.S.=> Eat your words & "eat my dust" chump... you failed as always!
... apk
& my dust after THIS -> http://tech.slashdot.org/comments.pl?sid=4829029&cid=46338565
* :)
(See how the "damaged fragile ego" of these "wannabes" like marsu_k react, 'stalking you' IF & WHEN you "get the better of them" on what THEY *think* is "their ballcourt"... lol, too bad marsu_k had to 'eat it' the way he did (his words, & MY DUST!!!)).
APK
P.S.=> Eat your words & "eat my dust" chump... you failed as always vs. myself
... apk
& my dust after THIS -> http://tech.slashdot.org/comments.pl?sid=4829029&cid=46338565
* :)
(See how the "damaged fragile ego" of these "wannabes" like marsu_k react, 'stalking you' IF & WHEN you "get the better of them" on what THEY *think* is "their ballcourt"... lol, too bad marsu_k had to 'eat it' the way he did (his words, & MY DUST!!!)).
APK
P.S.=> Eat your words & "eat my dust" chump - You failed as always vs. myself!
... apk
That I've SMOKED so badly before (on valid technical grounds, not ac trolling bullshit) that YOU are posting by ac now?
* :)
(You trolling by ac posts ALONE shows WHO the 'coward' really is (& it's NOT me - especially since you do a "Run, Forrest:RUN!!!" every single time I challenge you to disprove my points on hosts files as I am yet again in my 'p.s.' below))...
APK
P.S.=> Additionally/Lastly - As usual: You're MORE THAN WELCOME to *TRY* to disprove 17++ points in favor of custom hosts files use giving users of them added speed, security, reliability, & even added anonymity (to an extent) online, enumerated here (which YOU have repeatedly been "called out on & RAN, Forrest" (lol) since you CAN'T DISPROVE THOSE POINTS) ->
http://start64.com/index.php?o...
... apk