thewayne: (Default)
[personal profile] thewayne
PLEASE CHANGE THE DEFAULT ADMINISTRATOR PASSWORD if you haven't already. There's a new attack going around where, if you go to a corrupt page, it launches a malicious script on your PC that tries to identify your wireless router and change the administrator password. If it succeeds, it then becomes a base layer for phishing attacks by redirecting your attempts to access financial accounts to servers under the attacker's control. In such cases, if the cloned sites are done well (and with the amount of work that this attack requires, they'll probably be done well), you may not know that you're not on your bank's web site.

There are two obvious solutions. First, make sure that your administrator password isn't the default factory setting. Second, don't go to such web sites that these attacks are launched from. Unfortunately it's not easy knowing where such sites might be lurking. I think that part of the reason that I've been virus-free for so long is that I don't go where angels fear to tread and I'm not constantly downloading programs and toolbars. But maybe I'm just lucky.



OK, I mis-read the article. This is a proof-of-concept, i.e., someone created this attack and proved it viable. This does not mean that it exists in the wild. Still, you should change the default password on your wireless router.

Date: 2007-02-24 04:08 pm (UTC)
From: [identity profile] thewayne.livejournal.com
Ooooh - VERY dangerous having your machine configured to auto-connect! Your basic problem is that you don't know what you're talking to. Yes, it's a WAP, but it is trivial to put a key logger behind it. They have also demonstrated that if your PC is not properly defended, once you're connected, it's not difficult to compromise your computer!

If you do use public WAPs that you don't know who is running them, NEVER do anything that requires a password, ESPECIALLY banking!

I'm not too concerned, personally, because I use Zone Alarm Pro and am always fully updated (yes, I could get caught by a theoretical zero day exploit) and my wife uses a Mac, which is much stronger security-wise. But NEVER do financial or other important stuff over open WAPs that you don't personally know!

Date: 2007-02-24 05:47 pm (UTC)
From: [identity profile] annaonthemoon.livejournal.com
It was on my old laptop,which long story short, someone had put one of those lojack for laptops things on it to know where I wasat all times - while I thought they were helping me by fixing my laptop. Ah, the things you find out.

January 2026

S M T W T F S
    1 23
45 6 7 89 10
11 12 13 14 15 1617
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 17th, 2026 03:32 pm
Powered by Dreamwidth Studios