According to Symantec, the first drive-by pharming attack has become reality. Symantec warned of the concept almost a year ago, and now has reported such an attack against a Mexican bank.
In a drive-by pharming attack, victims only have to view a web page or open an e-mail. Embedded malicious code could change the DNS (Domain Name System) settings on a victim’s router. From that point on, Symantec reports, all future URL requests would be resolved by the attacker’s DNS server, which means the attacker effectively controls the victim’s Internet connection.
“At the time we described the attack concept, it was theoretical in the sense that we had not seen an example of it in the wild. That’s no longer the case,” said Symantec security expert Zulfikar Ramzan.
In one real-life variant that Symantec researchers observed, the attackers embedded the malicious code inside an e-mail that said it had an e-card waiting at the Web site gusanito.com.
However, the e-mail also contained an HTML IMG tag that resulted in an HTTP GET request being made to the victim’s router. The GET request modified the router’s DNS settings so that the URL for a popular Mexico-based banking site, as well as other related domains, were mapped to the attacker’s Web site.
“Now, anyone who subsequently tried to go to this particular banking Web site — one of the largest banks in Mexico — using the same computer would be directed to the attacker’s site instead,” Ramzan said. “Anyone who transacted with this rogue site would have their credentials stolen.”
Symantec said the first real-life instance of drive-by pharming was even more devastating than the researchers’ original concept because the particular brand of router involved has a substantial vulnerability that makes the attack far more potent.
“In its original incarnation, the drive-by pharming…