techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Feb 19, 2007, 12:33 AM   #1
NamesDontMatter
500 Posts
 
NamesDontMatter's Avatar
 
Join Date: Oct 2005
Location: Connecticut, United States
Posts: 758 (0.27/day)
Thanks: 12
Thanked 27 Times in 19 Posts
Send a message via AIM to NamesDontMatter Send a message via MSN to NamesDontMatter Send a message via Yahoo to NamesDontMatter

System Specs

Computer routers face hijack risk:

Researchers at both Symantec Corp. and the University of Indiana say routers are at risk of highjacking. The research found that router users are succeptable to hijacking of their hardware through malicious code hiding in specially crafted websites that could change settings on the network devices and begin phishing attacks. These attacks are very dangerous to users an example givin by cbc.ca states, "For example, a person could enter the correct address of their bank's website into their web browser but they would be taken to a fake site designed to steal their banking information." The scary thing is that this particular type of attack works on The on all major consumer routers, including routers made by Linksys, Belkin, Netgear and D-Link, but only after a user on that device visited a specially crafted web page for it to work.

Source: cbc.ca
NamesDontMatter is offline  
Reply With Quote
Old Feb 19, 2007, 12:44 AM   #2
WarEagleAU
Bird of Prey
 
WarEagleAU's Avatar
 
Join Date: Jul 2006
Location: Gurley, AL
Posts: 9,994 (3.98/day)
Thanks: 3,810
Thanked 557 Times in 521 Posts
Send a message via AIM to WarEagleAU Send a message via Yahoo to WarEagleAU

System Specs

::cringe:: this isnt good news....
__________________
=-TheEagle-=



http://www.heatware.com/eval.php?id=62454
“You crazy? Surfing any website without an antivirus is like freaking with a dirty woman without protection” -OzzmanFloyd120
- Edited for content and clarity
WarEagleAU is offline  
Reply With Quote
Old Feb 19, 2007, 01:27 AM   #3
XooM
200 Posts
 
Join Date: Oct 2004
Location: Close to FrozenCPU.com
Posts: 478 (0.15/day)
Thanks: 9
Thanked 7 Times in 5 Posts
Send a message via AIM to XooM

System Specs

thank God, the FSM, and Tom Cruise for Smoothwall
__________________
“yeah i'm sorry .. i'm not so good at programming.. i just started” -W1zzard
XooM is offline  
Reply With Quote
Old Feb 19, 2007, 01:52 AM   #4
niko084
Eligible for custom title
 
niko084's Avatar
 
Join Date: Dec 2006
Location: Saint Paul, Minnesota
Posts: 6,387 (2.70/day)
Thanks: 190
Thanked 739 Times in 599 Posts
Send a message via ICQ to niko084 Send a message via AIM to niko084 Send a message via Skype™ to niko084

System Specs

Cisco 850 FTW! < Maybe I should get one, they do the trick, and are the cheapest of the group.

I have been highly considering setting up another linux machine to act as a router anyways.
__________________
This electronic post is encrypted in the 'English language method', any attempt to decipher meaning from these symbols is a violation of the Digital Millennium Copyright Act of 1998. This includes, but is not limited to: interpreting the symbols through use of biological, visual decryption devices, translating the symbols into another language encryption scheme, and digital processing the symbols into a form conducive to oral interpretation.
HWBOT HEATWARE
niko084 is offline  
Reply With Quote
Old Feb 19, 2007, 02:12 AM   #5
PyroInc
500 Posts
 
PyroInc's Avatar
 
Join Date: Aug 2006
Posts: 514 (0.21/day)
Thanks: 4
Thanked 0 Times in 0 Posts

System Specs

wouldn't the url be different then. I'd notice something was wrong then
PyroInc is offline  
Reply With Quote
Old Feb 19, 2007, 03:32 AM   #6
Namslas90
3500 Posts
 
Join Date: Aug 2006
Location: Earth
Posts: 3,908 (1.59/day)
Thanks: 107
Thanked 577 Times in 533 Posts

System Specs

Just another reason why I don't/won't use routers. Multiple ISP's is the way to go!!
__________________
Namslas90 is offline  
Reply With Quote
Old Feb 19, 2007, 04:31 AM   #7
XooM
200 Posts
 
Join Date: Oct 2004
Location: Close to FrozenCPU.com
Posts: 478 (0.15/day)
Thanks: 9
Thanked 7 Times in 5 Posts
Send a message via AIM to XooM

System Specs

Quote:
Originally Posted by PyroInc View Post
wouldn't the url be different then. I'd notice something was wrong then
no. It could spoof your DNS and redirect any normal URL to any page they wanted, all while looking completely legit.
__________________
“yeah i'm sorry .. i'm not so good at programming.. i just started” -W1zzard
XooM is offline  
Reply With Quote
Old Feb 19, 2007, 09:07 AM   #8
spectre440
500 Posts
 
spectre440's Avatar
 
Join Date: Jul 2005
Location: Israel
Posts: 739 (0.26/day)
Thanks: 8
Thanked 15 Times in 13 Posts
Send a message via ICQ to spectre440 Send a message via MSN to spectre440

System Specs

this definantly isnt good...

there are way to protect one's PC against these types of things, but how does one protect ones router?
__________________
“I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me.” - Hunter S. Thompson
spectre440 is offline  
Reply With Quote
Old Feb 19, 2007, 09:13 AM   #9
ex_reven
2000 Posts
 
Join Date: Sep 2006
Posts: 3,413 (1.39/day)
Thanks: 117
Thanked 181 Times in 166 Posts

System Specs

Quote:
Originally Posted by spectre440 View Post
this definantly isnt good...

there are way to protect one's PC against these types of things, but how does one protect ones router?
get a firewall router?
and set it up properly
ex_reven is offline  
Reply With Quote
Old Feb 19, 2007, 09:59 AM   #10
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

hmm, i hope SMC isnt affected
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 19, 2007, 01:54 PM   #11
Poisonsnak
200 Posts
 
Join Date: Feb 2005
Location: Saskatoon, SK
Posts: 363 (0.12/day)
Thanks: 14
Thanked 18 Times in 12 Posts

System Specs

read the rest of the story at the end of the link:

Quote:
The researchers cited surveys that showed half of home router users use the default password or no password on the device, and 95 per cent allow their web browsers to use JavaScript code.

"This means 47.5 per cent of all home users … are effectively leaving themselves open to another attack — allowing attackers to circumvent all known anti-phishing countermeasures," the researchers wrote.
These are the same kind of people that don't secure their wireless networks
Poisonsnak is offline  
Reply With Quote
Old Feb 19, 2007, 03:03 PM   #12
newbielives
75 Posts
 
Join Date: Apr 2005
Posts: 164 (0.06/day)
Thanks: 4
Thanked 4 Times in 4 Posts

I was scared for a minute there lol

Quote:
Originally Posted by Poisonsnak View Post
read the rest of the story at the end of the link:



These are the same kind of people that don't secure their wireless networks
newbielives is offline  
Reply With Quote
Old Feb 19, 2007, 06:53 PM   #13
Alec§taar
Banned
 
Alec§taar's Avatar
 
Join Date: May 2006
Location: Someone who's going to find NewTekie1 and teach him a lesson
Posts: 3,380 (1.32/day)
Thanks: 0
Thanked 102 Times in 101 Posts

System Specs

Quote:
Originally Posted by NamesDontMatter View Post
Researchers at both Symantec Corp. and the University of Indiana say routers are at risk of highjacking. The research found that router users are succeptable to hijacking of their hardware through malicious code hiding in specially crafted websites that could change settings on the network devices and begin phishing attacks. These attacks are very dangerous to users an example givin by cbc.ca states, "For example, a person could enter the correct address of their bank's website into their web browser but they would be taken to a fake site designed to steal their banking information." The scary thing is that this particular type of attack works on The on all major consumer routers, including routers made by Linksys, Belkin, Netgear and D-Link, but only after a user on that device visited a specially crafted web page for it to work.

Source: cbc.ca
Turn off JAVASCRIPT in your browsers & web based apps that use it...



* This is the reason WHY I do so, OR rather, a part of it... & only use it, where you HAVE to. For INTRANET usage, it's decent stuff... but, for the public internet, it definitely has DOWNSIDES!

APK

P.S.=> Webmasters may not LIKE me doing that, but it is a personal choice - I'd like to keep my system solid & secure as is possible! apk

Last edited by Alec§taar; Feb 19, 2007 at 06:59 PM.
Alec§taar is offline  
Reply With Quote
Old Feb 19, 2007, 09:52 PM   #14
Poisonsnak
200 Posts
 
Join Date: Feb 2005
Location: Saskatoon, SK
Posts: 363 (0.12/day)
Thanks: 14
Thanked 18 Times in 12 Posts

System Specs

Well I was more concerned with those who leave the default password on their router but hey I've never liked javascript either.
Poisonsnak is offline  
Reply With Quote
Old Feb 19, 2007, 09:54 PM   #15
Scavar
200 Posts
 
Scavar's Avatar
 
Join Date: Aug 2006
Location: Ft Lauderdale, FL
Posts: 497 (0.20/day)
Thanks: 1
Thanked 1 Time in 1 Post
Send a message via AIM to Scavar Send a message via MSN to Scavar Send a message via Yahoo to Scavar

System Specs

After reading this, I decided I would finally turn Javascript off.

My dad is pretty insane when it comes to routers. Who the hell uses the default password? Isn't it like admin for all of them? I mean come on....
__________________
[img disabled]http://www.forumsigs.com/users/Scavar1190/banner.jpg[/img]
Only time can save the world now.
Immortality is your last hope.
For my existence to be true, Hell's Fire must burn hotter then Heaven's Cold Gates can stand.
Ashentech
Scavar is offline  
Reply With Quote
Old Feb 20, 2007, 04:21 AM   #16
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

Quote:
Originally Posted by Poisonsnak View Post
read the rest of the story at the end of the link:



These are the same kind of people that don't secure their wireless networks
lol who doesnt use a password
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 20, 2007, 04:36 AM   #17
ex_reven
2000 Posts
 
Join Date: Sep 2006
Posts: 3,413 (1.39/day)
Thanks: 117
Thanked 181 Times in 166 Posts

System Specs

My router password is set to default
i could never really be bothered to change it

i would of course do so if i was visiting less than ideal websites, but i havnt ventured away from hotmail, tpu, myspace and wikipedia on this computer in the few months ive had it.

il change it later
ex_reven is offline  
Reply With Quote
Old Feb 20, 2007, 04:41 AM   #18
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

you log onto your internet banking !

dont mind me if i sit out the front of your house with my bro's laptop
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 20, 2007, 04:46 AM   #19
ex_reven
2000 Posts
 
Join Date: Sep 2006
Posts: 3,413 (1.39/day)
Thanks: 117
Thanked 181 Times in 166 Posts

System Specs

you would have no idea how to steal my bank funds kiddo
ex_reven is offline  
Reply With Quote
Old Feb 20, 2007, 04:47 AM   #20
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

make a bet ?

I already know your router password
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 20, 2007, 04:48 AM   #21
ex_reven
2000 Posts
 
Join Date: Sep 2006
Posts: 3,413 (1.39/day)
Thanks: 117
Thanked 181 Times in 166 Posts

System Specs

shutup
ex_reven is offline  
Reply With Quote
Old Feb 20, 2007, 04:51 AM   #22
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

Moral of the story, change ur password
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 20, 2007, 05:05 AM   #23
ex_reven
2000 Posts
 
Join Date: Sep 2006
Posts: 3,413 (1.39/day)
Thanks: 117
Thanked 181 Times in 166 Posts

System Specs

changed...

you happy?
ex_reven is offline  
Reply With Quote
Old Feb 20, 2007, 05:06 AM   #24
Pinchy
3500 Posts
 
Join Date: Apr 2006
Location: Sydney, Australia
Posts: 4,650 (1.80/day)
Thanks: 302
Thanked 360 Times in 344 Posts
Send a message via MSN to Pinchy

System Specs

no, now i cant wipe your bank account
__________________
mATX rig: TT Lanbox Lite, GA-G33M-DS2R, q9300, 4GB G.Skill Pi PC8000, 2x640GB Samsung F1's in RAID 0, LG 20x DVD+/RW, HIS IceQ HD4670 512MB, Gigabyte G-Power PRO, TT 450W TR2 RX Modular PSU
HTPC: i-Cute iBox, GA-MA780GM-S2H, 4850e, 2GB G.Skill PC6400, 1x640GB WD SE16, Onboard HD3200, D-link XtremeN PCIe, Leadtek WinFast DVR3100 H Tuner, 450W Vantec PSU
Server: Custom made case, EPIA Mini-ITX mobo, 1GHz VIA, 1GB PC2700 SO-DIMM, 1TB WD, Gigabit PCI LAN card, 60W 12V AC adapter
Pinchy is offline  
Reply With Quote
Old Feb 21, 2007, 08:55 AM   #25
xylomn
500 Posts
 
xylomn's Avatar
 
Join Date: May 2006
Location: Swindon, England, United Kingdom
Posts: 538 (0.21/day)
Thanks: 4
Thanked 18 Times in 17 Posts
Send a message via Skype™ to xylomn

System Specs

Just use firefox with the NoScript extension... then you can enable javascript for the sites you need and leave it off for everything else... works a treat
__________________
Bsc(Hons) Computer Science Software Engineering
MSc(Hons) Computer Game Engineering
xylomn is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT. The time now is 11:38 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts