Lock Down Your Router!  (Read 15001 times)


Lock Down Your Router!
« on: February 19, 2007, 12:55:06 pm »
Indiana University, in conjunction with Symantec, published a technical report on Drive-By Pharming. Basically, this type of phishing involves hackers using default passwords on routers via malicious Javascript to hijack a router and change the DNS cache in the router. The effect would be to point users to fake web sites.

Here is a link to a ZDnet article about this exploit:

Here are links to the Indiana University report about the exploit: - the abstract (summary) - the details

Note that the report has not yet been published. I would take this one seriously, as Linux boxes can likely be used to mess up a router via malicious sites. The bottom line is to lock down your router by changing the default password on it.

Re: Lock Down Your Router!
« Reply #1 on: March 28, 2007, 06:08:49 am »
And if you have any doubts about the availability of these factory default passwords this is the list every hacker and "wardriver" uses:

Also a handy password strength checker:

Re: Lock Down Your Router!
« Reply #2 on: January 29, 2008, 08:49:00 pm »
While you are on the topic of router insecurity, a more serious problem has been reported when just about any router that uses UPNP could be compromised by a flash attack, and that regardless of the operating system. It exploits the lack of authentication with UPNP. You can look it up on "The register" a UK newsletter. Quite interesting.