Sophisticated phishing malicious malware software now uses DNS to direct users to fraudulent sites

Jan 31, 2008 3 Replies

Sophisticated phishing malicious malware software now uses DNS to direct users to fraudulent sites



formatting link


formatting link

*sigh*

When a phisher (or any other attacker) can tamper with your DNS settings (or hosts file or whatever) you have far more serious problems than a phishing attempt.

On every reasonably configured system this is a non-issue, because normal users simply cannot tamper with these settings.

cu

59cobalt

formatting link

One version of this scenario is a hacker gets into the home router settings because the user hasn't changed the default password and changes the DNS server settings there. I don't know how vulnerable routers are to this possibility, but it motivated motivated me to set a seriously hardened password on the configuration.

^^^^^^^^^^^^^^^^^^^^^

I underlined the operative words for your convenience. "Default password" does not match the criteria.

They are.

Good idea. You should also disable UPnP.

cu

59cobalt

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required