Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

June 18, 2008

New Home Router Hacking Program

A newly discovered Trojan in the wild hacks into home wireless routers and changes their DNS settings to point to the attacker’s rogue DNS server. The malware is a new variant of the DNSChanger Trojan that has been circulating around the Internet, according to researchers at Secure Computing who have been studying it.

Home routers make easy prey because many users don’t lock them down, and even use their default passwords for authentication. There’s been plenty of research in this space over the past year, everything from drive-by hacks to botnet infections to DNS rebinding. (See Attackers Use New 'Call-Home' Method to Infiltrate Home Networks and RSA Session Features Live Linksys Router Hack and The Hack Your Home Router Challenge.)

Sven Krasser, director of data mining research for Secure Computing, says the new DNSChanger Trojan attack also indirectly infects any machine that connects to the router. “This is the first time we’ve seen on [a] wide basis that the computing resources of the wireless router are part of the attack,” he says. “It also [affects] machines that are not directly exploited -- ones that are connecting to the router.”

The Trojan executes brute-force attacks on the Web interface of a router that only uses basic authentication -- and it’s mostly going after D-Link and Linksys routers so far, according to Krasser.

Secure Computing says the attackers behind the malware are the infamous Zlob malware authors.

Krasser says the attackers can send a victim to any Website, and most times return the correct site back to the user to evade detection. Other times they redirect a user to their own spoofed pages, he says. He says phishing is a likely goal of the attackers.

He says it’s possible that attackers could kick the attack up a notch and add put their malcode onto the routers, such as zombie code. Secure Computing researchers have posted some screen shots and an analysis of the Trojan in their blog.

Never use default passwords in home routers, Krasser says, and keep it updated.

June 2, 2008

Microsoft wants your Opinion?

In the continuing effort to improve computer and network security, Microsoft has developed the End to End Trust initiative. As a part of that initiative, Microsoft is seeking input from users and information security professionals to help answer the questions that need to be addressed in order to evolve computer security such as How should we enhance security on the Internet without undermining social values, such as privacy and anonymity? There are more questions to be answered in the End to End Trust Forums. Scott Charney, Microsoft's Corporate Vice President of Trustworthy Computing, has developed a white paper entitled Establishing End to End Trust which provides more details on Microsoft's vision.

While  it is not beyond the stretch of a reasonable person's imagination that a giant of the industry would want to keep it's users secure. The employees and designers of microsoft have showed a lack of willingness to address serious security issues, and wrap every tiny piece of security as the next big step in computing. Rather than the required software that all of this should have been back in Windows 98. It seems that every time Microsoft attempts security, it undoubtedly blows up in it's face. So I would encourage you to voice your opinion to microsoft- Let them know you value your security, as well as your wallet.