Tuesday, April 08, 2008

Do you have an ATT 2Wire DSL modem ("Home Portal")? 

They have a security problem. To make a long story short, they made several mistakes and as a result someone can reprogram your modem by getting you to visit a malicious web page. In particular they can change where you go when you try to visit a particular site, for example your bank.

Worse yet, bad guys are taking advantage of this now.

I've heard conflicting stories about whether there's a fix yet. Email support@2wire.com and ask whether there's a firmware update that fixes "CVE-2007-4389".

There are ways to protect yourself in the absence of a fix, but but they're too complicated for normal people.


