Saturday, April 19, 2008

Domain Typo Error Page Ads Let Hackers Hijack Entire Web, Researcher Discloses

Ryan Singel writes on Threat Level:

Some of the U.S.'s largest ISPs are seeking to make money off mistyped website names and instead created gaping security holes in the web's largest websites, including eBay, PayPal, Google and Yahoo, making it possible for hackers to turn any site on the net into a source of malware, a security researcher revealed Saturday.

The massive vulnerability introduced by Earthlink and Comcast was quietly and quickly patched on Friday, after IOActive security researcher Dan Kaminsky reported the vulnerability to Earthlink and its technology partner Barefruit.

More here.

Note: Brian Krebs writes extensively about this, too, here on Security Fix.

0 Comments:

Post a Comment

<< Home