Today the blogger received an email from the Security Alliance — a wave of DNS hijacking is coming. What is DNS hijacking?
A website is illegally intruded by hackers who embed malicious code, causing the user’s DNS to be maliciously tampered with, seriously affecting the user’s security. When a netizen visits a hijacked website, the site opens normally, but in the background it automatically analyzes the router username and password the user is using. For users with weak passwords, the site automatically cracks the login, and after successful login tampers with the user’s DNS settings. Then, without the user’s knowledge, it tracks the user’s web behavior and steals personal information. Hijacked users are easily manipulated by hackers. When the user makes a cash transaction or payment, they are highly likely to suffer major property loss.
The main target is TP-LINK routers.
When a user’s DNS is hijacked, when visiting online banking they will first visit the hacker’s DNS; the user resolves the hacker server’s IP address, leading them into a phishing site.
The Security Alliance’s recommendation: http://zhanzhang.anquan.org/topic/dns_hijacking/
