“Millions” of Routers at Risk of New Attack
By Craig Lloyd on Jul 21st, 2010 at 12:03PM

At this year’s upcoming Black Hat security conference, Craig Heffner, a researcher with security firm Seismic, is giving a keynote entitled “How to Hack Millions of Routers.” He plans to release a piece of software that he claims is capable of hacking into half of all routers in existence. This isn’t a new attack really, but is a modified version of a technique known as “DNS rebinding.” The hack capitalizes on part of the DNS, so that when someone visits a compromised website, the hacker hijacks their browser, which then gives them access to router settings. Heffner says that releasing this attack may be the best way to draw attention to the problem and convince browser and router makers to release patches that fix this problem.
A good way to keep yourself safe is to update your router’s firmware and make sure that you’re not using default security settings.
You can view a list of routers that were tested and whether or not they’re vulnerable here.
via [Forbes]






