Drive-By Pharming

Drive-By Pharming
复制标题

路过式网络嫁接

DOI:
10.1007/978-3-540-77048-0_38
复制
发表时间:
2007
期刊:
J. Netw. Comput. Appl.
影响因子:
--
通讯作者:
M. Jakobsson
M. Jakobsson
中科院分区:
--
文献类型:
--
作者:
Sid Stamm;Zulfikar Ramzan;M. Jakobsson

文献摘要

被引文献

相似文献

这篇论文描述了一种被称为Drive-by Pharming的攻击概念,即攻击者设置一个网页,当受害者(在支持javascript的浏览器上)简单地查看该网页时,攻击者试图改变受害者家庭宽带路由器上的DNS服务器设置。因此,未来的DNS查询将由攻击者选择的DNS服务器解析。攻击者可以引导受害者的互联网流量,并将受害者指向攻击者自己的网站,而不管受害者认为他实际上要去哪个域名,这可能导致受害者凭证的妥协。同样的攻击方法可以用于对路由器进行其他更改,例如更换其固件。然后,路由器可以承载恶意网页或参与点击欺诈。由于攻击是通过浏览网页进行的,因此不需要攻击者与受害者有任何物理上的接近,也不需要明确下载传统的恶意软件。攻击是在受害者没有更改其宽带路由器的默认管理密码的合理假设下进行的。
This paper describes an attack concept termed Drive-by Pharming where an attacker sets up a web page that, when simply viewed by the victim (on a JavaScript-enabled browser), attempts to change the DNS server settings on the victim's home broadband router. As a result, future DNS queries are resolved by a DNS server of the attacker's choice. The attacker can direct the victim's Internet traffic and point the victim to the attacker's own web sites regardless of what domain the victim thinks he is actually going to, potentially leading to the compromise of the victim's credentials. The same attack methodology can be used to make other changes to the router, like replacing its firmware. Routers could then host malicious web pages or engage in click fraud. Since the attack is mounted through viewing a web page, it does not require the attacker to have any physical proximity to the victim nor does it require the explicit download of traditional malicious software. The attack works under the reasonable assumption that the victim has not changed the default management password on their broadband router.