| View previous topic :: View next topic |
| Author |
Message |
Nightmaretony Warrior
Joined: 15 Mar 2005 Last Visit: 30 Jun 2011 Posts: 256 Location: Meadowbrook
|
|
| Back to top |
|
 |
datababe Warrior

Joined: 13 Dec 2004 Last Visit: 10 Oct 2012 Posts: 217 Location: Inside your head
|
|
| Back to top |
|
 |
mikey Malware Expert

Joined: 12 Feb 2004 Last Visit: 03 Sep 2012 Posts: 1061 Location: CenTex
|
|
| Back to top |
|
 |
Oldfrog Site Admin

Joined: 08 Aug 2004 Last Visit: 09 Feb 2013 Posts: 1161 Location: Hewitt, TX
|
Posted: Fri Jan 25, 2008 1:25 pm Post subject: |
|
|
| The astounding fact about the ITW attack described by Symantec is that the attack can only succeed if the broadband router still uses the default out-of-the-box administrative password. The router make wasn't specified but since the attack used an HTTP GET command I would imagine that the command is sent to an IP address. This would in turn require that the default LAN IP address was also being used. It shouldn't take a rocket scientist to figure that a password everyone knows isn't much security. |
|
| Back to top |
|
 |
|