Win tickets to the ATP finals

Broadband users have been urged to change the default passwords on their routers or risk making their bank details available to cybercriminals.
Computer scientists have identified a technique that could allow hackers to steal bank details by hijacking a home broadband connection.
The technique, in which thieves guide home computers to fake a bank website, is being called “drive-by pharming” because all that is needed is a fleeting visit to a rogue site.
The criminals set up a website containing a single line of malicious code that operates whenever the page is viewed. Unlike “phishing” attacks, the victim does not have to click on any link or download any files.
Once the code starts to run, it hijacks the router — the connection that steers users to sites they type into the browser’s address field — if the router’s password is still set to default.
When victims try to access bank websites, they are unwittingly redirected to fake sites operated by the fraudsters. As they try to access their account, they unknowingly give up their passwords and personal details.
It is thought that up to 50 per cent of people with broadband have not changed the default passwords on their routers.
Drive-by pharming is not yet thought to have been used to steal money, but experts who hack into systems to improve online security staged a successful mock attack last week.
Zulfikar Ramzan, of Symantec, a computer security company based in Cupertino, California, told the American Association for the Advancement of Science conference that he was alarmed by how easy it had been to accomplish.
“All you have to do to be affected is to look at a web page,” he said. “Attackers gain complete control over the conduit by which you surf the web, allowing them to direct you to sites they designed.
“I believe this attack has serious implications. The new threats are worrying because they are silent and invisible, making it more difficult to convey to the public. All people have to do to protect themselves is change their home router password.”
Markus Jakobsson, from the University of Indiana, who also worked on identifying the vulnerability, said: “I would advise people never to buy routers on ebay, or thumb drives or iPods, or anything you attach to your computer. You should buy it in a shrink-wrapped box from a place you consider to be safe.”
The technique exploits the way in which computers access the internet. Each website has a unique identifier known as its internet protocol or IP address. To find this address, the computer looks it up in a remote Domain Name System (DNS) server, before accessing the site.
Drive-by pharming changes the default DNS settings on a computer’s broadband router so that it looks up bank IP ad-dresses from a false server. The computer is directed towards a copy of the bank website, where users enter their details without knowing that they are giving them up to criminals.
Dr Ramzen asked his audience to imagine having to look up their bank’s address in a phone directory before making a visit. “Our attack shows a simple way that attackers can replace the phone books in your house with one that they created. Now, when you pick up that rogue phone book it’ll give you the wrong address. At this wrong address, the attackers will have set up a fake bank that looks just like your bank. You’ll give up all your sensitive bank account information. You will never realise that you were at a fake bank since you trusted the address that you got from what you thought was your legitimate telephone book.”
He said that he was not aware of any criminals using drive-by pharming, but that he wanted to alert people to the danger.
How to beat cyber-fraudsters
-Antivirus software needs to be as up to date as possible. There were about ten new threats every hour last month, so checking for updates once a day isn’t enough. Your antivirus software should enable you to check for updates hourly
-Get the latest Microsoft security patches, released on the second Tuesday of every month. You can set up your PC to do this automatically through its security centre, via the control panel. Or go to www.windowsupdate.com
-You need a firewall — either built into your broadband router hardware or on your PC — and preferably both. Check out independent reviews on technology sites for the best products
-Change the password on your router. It will be shipped with a default password, such as “admin” or “password”. Hackers can use that to change its settings. So when you go to your online bank, for example, you are redirected, unwittingly, to a cybercriminals' site. You should be able to access your router through your web browser. It will have a web address that should be in the instruction manual
-Drive-by phishers also exploit Javascript, a computer language used in online features such as forms that can let in a host of other types of malicious software. A browser such as Firefox (available for free at www.mozilla.com/firefox) gives you the option of choosing whether or not to allow Java to run on a site-by-site basis
-Use common sense: check your bank account regularly; don’t use the same password for every site (40 per cent of people do); be extremely cautious of unsolicited e-mails; back up important data; don’t open files that you don’t trust
-Browsers such as Firefox, Opera and Apple’s Safari are hit less often by hackers
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
36-month car lease
on contract hire for
£359.99 plus VAT pm
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
The UK's leading alternative to showroom finance.
Finance packages tailored to your needs.
Minimum loan of £15,000
Car Insurance
£12,578 per annum
The Independent Housing Ombudsman
London
Competitive
Barclaycard
Not Specified
The Sheppard Trust
London
£80-95,000
Clay McGuire Executive Selection
Moments from Battersea Park.
For sale with Winkworth.
See your free Experian credit report beforehand
Book now & save over £100pp.
11 cool resorts, lowest prices... Early Booking offers 15 Nov.
20% off selected Azores holidays taken in October with Sunvil Discovery
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.