PDA

View Full Version : Possible Domain Poisoning Underway


BioALIEN
7 Mar 2005, 05:13 PM
Security experts late Friday warned that a DNS cache poisoning attack may be underway and redirecting users from some of the most popular Web sites to a malicious URL where spyware and adware is invisibly installed onto their computers.



According to the Internet Storm Center, which posted an alert on its Web site, it had received reports that the attack was redirecting traffic from popular domains such as google.com, ebay.com, and weather.com.

DNS (http://www.techweb.com/encyclopedia/defineterm.jhtml?term=DNS) cache poisoning occurs when an attacker hacks into a domain name server, then "poisons" the cache by planting counterfeit data in the cache of the name server. When a user requests, say, ebay.com, and the IP address (http://www.techweb.com/encyclopedia/defineterm.jhtml?term=IP+address) is resolved by the hacked domain server, the bogus data is fed back to the browser.

Another tactic, dubbed "DNS hijacking" is similar, but simply changes the domain server so that traffic is actually re-routed. It's unclear which of the two tactics this attack is using.


Full story: http://www.techweb.com/wire/security/60405913 (http://www.techweb.com/wire/security/60405913)

TheBush
8 Mar 2005, 07:43 AM
Grr... I hate when stuff like that happens. I know this has nothing to do with it, but I keep getting from everyone on MSN trying to send like "My Webcam" or "me naked" etc. I aint stupid though ;)

BioALIEN
8 Mar 2005, 04:26 PM
Yeah there are many viruses being passed down to people on MSN. Everyone, it is strongly advised NOT to accept anything files that ends with the extension .pif

A good upto date Antivirus is highly recommended on your machine. One that also supports AntiSpam!