The attack works by re-writing the address book in network hardware to point victims to the scam sites. About 50% of users leave default passwords unchanged, suggests research.
The theoretical attack was explored in a paper written by researchers from the University of Indiana and security firm Symantec.