All the latest UK technology news, reviews and analysis

Home wireless networks wide open

by Iain Thomson

20 Feb 2007

Be the first to comment

  • Tweet this

Research by the Indiana University School of Informatics (IUSI) has uncovered a security threat that could affect half of all home servers.

The attack uses a JavaScript application to change the domain name system settings on an unsecured router, or one that uses the default password.

This could allow a hacker to redirect the user to a phishing site whenever they try and log-on to their online banking sites, for instance.

Professor Markus Jakobsson of the IUSI, explained that the attack highlights the importance of the human factor in security.

"While drive-by pharming arises due to inadequate protective measures, there is also another human component: if an attacker can trick you into visiting his page, he can probe your machine," he said.

"Deceit is not new to humankind, but it is fairly recently that security researchers started taking it seriously."

The IUSI estimates that around 50 per cent of home routers are vulnerable to the attack because of poor password protection.

It recommends the use of a multi-layer password that includes upper and lower case letters, numbers and symbols to make cracking difficult.

"This new research exposes a problem affecting millions of broadband users worldwide," said Oliver Friedrichs, director of Symantec Security Response.

"Because of the ease with which drive-by pharming attacks can be launched, it is vital that consumers adequately protect their broadband routers and wireless access points today."

The attack is even more worrying since it requires no physical access to the router. A hacker could simply drive through a neighbourhood and launch the attack remotely.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

2%

13%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

.NET C# Dynamics CRM SQL Server Developer - Banking

C# Developer with MS Dynamics A global Bank is currently...

IT Systems Management Team Leader

CCNA accredited IT Systems Management Team Leader required...

Oracle DBA

Oracle Administrator (Oracle Agile PLM DBA) Title...

J2Me Mobile Developer

J2ME Mobile developer required to work in Yorkshire...

To send to more than one email address, simply separate each address with a comma.