Here is an interesting attack brought to us by the Symantec Security Response team.

It allows attackers to create a Web page that, simply when viewed, results in substantive configuration changes to your home broadband router or wireless access point. As a result, attackers gain complete control over the conduit by which you surf the Web, allowing them to direct you to sites they designed (no matter what Web address you direct your Web browser to).

Basically through the use of some known default passwords and flaws in home-based wireless router firmware, one can take control of the router—including changing DNS records and so forth. So, even if you type in your desired destination in the web browser, you might end up elsewhere.

Why call it “drive-by”? As an attacker, you could drive through neighborhoods, launching these attacks against any wireless router you come in contact with. Then the entire home/neighbors/others who use the router will also be subject to the same attacks. So, if you open your router up for free access, please make sure it is secured with a password and its firmware is up to date.