Readings for April 20th, 2008


« April 17th, 2008
April 23rd, 2008 »

Wired: ISPs' Error Page Ads Let Hackers Hijack Entire Web, Researcher Discloses

Seeking to make money from mistyped website names, some of the United States' largest ISPs instead created a massive security hole that allowed hackers to use web addresses owned by eBay, PayPal, Google and Yahoo, and virtually any other large site.

The vulnerability was a dream scenario for phishers and cyber attackers looking for convincing platforms to distribute fake websites or malicious code.

The hole was quickly and quietly patched Friday after IOActive security researcher Dan Kaminsky reported the issue to Earthlink and its technology partner, a British ad company called Barefruit.  Earthlink users, and some Comcast subscribers, were at risk.

Source: Wired