ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec warns of router compromise

Tom Espiner ZDNet.co.uk

Published: 24 Jan 2008 13:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Symantec has warned of an attack involving the subversion of routers.

The security company said this was the first time it had seen such an attack "in the wild", although the concept had been discussed a year ago by Symantec researchers, according to a Symantec blog post.

In the attack, which targeted users of an undisclosed Mexican bank, the intended victims received a spam email claiming they had received an e-card, directing them to gusanto.com, a Spanish language e-card site. However, the email also had embedded HTML image tags, which contained an HTTP get-request to the router to change its DNS settings, according to Symantec's UK manager of quality assurance, Thomas Parsons.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

The HTTP get-request redirects traffic flowing over the router to a specific IP address when the user attempts to access six domain names that are banking-related. Symantec requested that ZDNet.co.uk did not publish the IP address.

The attack is made possible by a cross-site scripting vulnerability in 2Wire routers that was reported in August last year, according to Symantec. Parsons said this was "a simple hack", and advised small to medium-sized businesses to change default security settings on routers, and educate users about clicking on suspicious links.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
7 out of 9 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Network Administrator/ CCNP/ Cisco/ Switches/ Routers/ MPLS/ 40k

Network Administrator/ CCNP/ Cisco/ Switches/ Routers/ MPLS/ OSPF/ BGP/ EIGRP/ 40k Worlds leaders in Technology are looking for a Network ...

CCNA/CCNP Cisco Engineer - Routers/Switches/Firewalls - Bath

The ideal candidate will have a skill set to include as many of the following: CCNA or CCNP certified, Routers, Catalyst Switches 29xx, 35xx and ...

Network Analyst, Southampton

I am looking for someone who has knowledge of Cisco router configuration, Windows 2003 and server hardware builds. Your role will be to administer ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation