[YLUG] Web sites hacking router [was: Re: Router]

Arthur Clune arthur at clune.org
Mon Sep 29 12:57:56 UTC 2008


On 29 Sep 2008, at 13:50, Harry Mills wrote:

> So in theory we should all use that separate browser we already use  
> for
> online banking etc (the one with no plugins, javascript turned off,  
> run
> as a completely unprivileged user with all history, temp files and
> cookies deleted after each session and before starting etc) for our
> routers as well.

No. Your router isn't malicious, so why would you do that?

The attack is that any *other* site can bounce out onto your private
net. So if you router doesn't have a password, it's settings can be
changed.

So you need to use that browser everywhere :)

Arthur



More information about the York mailing list