Full Disclosure mailing list archives
Re: Drive-by Pharming Threat
From: Jeremy Saintot <jeremy.saintot () free fr>
Date: Tue, 20 Feb 2007 12:11:01 +0100
auto400208 () hushmail com wrote:
I am curious as to how one "automatically" logs on? 1. Internet Explorer disallows username:pass@http://192.168.1.0 2. Opera has a very clear warning that you are logging on 3. Firefox has a very clear warning that you are logging on Are there any other methods to log on without any warning? If so does it work with Internet Explorer? Also when you do reset or change parameters in the router, does it not require a reboot of the router (auto after you hit save), whereby your connection is lost for x amount of time?
I did not test that, but I think some routers use HTML forms to log in to the admin panel. In this case, you should be able to use CSRF with AJAX xhr objects, or simple Javascript to auto-submit the form. Once the browser is logged in, it could use the same process and submit forms to change configuration settings such as DNS servers (for this attack) and more. Regards, Jeremy Saintot _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Drive-by Pharming Threat auto400208 (Feb 19)
- Re: Drive-by Pharming Threat Andrew Farmer (Feb 19)
- Re: Drive-by Pharming Threat Martin Johns (Feb 19)
- Re: Drive-by Pharming Threat Gaurang Pandya (Feb 19)
- Re: Drive-by Pharming Threat mikeiscool (Feb 19)
- Re: Drive-by Pharming Threat Gaurang Pandya (Feb 19)
- Re: Drive-by Pharming Threat Andrew Farmer (Feb 19)
- Re: Drive-by Pharming Threat Gaurang Pandya (Feb 19)
- Re: Drive-by Pharming Threat Gaurang Pandya (Feb 19)
- <Possible follow-ups>
- Re: Drive-by Pharming Threat auto400208 (Feb 20)
- Re: Drive-by Pharming Threat auto400208 (Feb 20)