Odd DNS Traffic sparks interest
Results 1 to 2 of 2

Thread: Odd DNS Traffic sparks interest

  1. #1
    Senior Member
    Join Date
    Sep 2003
    Posts
    156

    Odd DNS Traffic sparks interest

    The odd DNS issues are likely caused by the QHosts-1 Trojan
    Source: Internet Storm Center Diary

    heads up.


    t.e.k.n.o.

  2. #2
    THE Bastard Sys***** dinowuff's Avatar
    Join Date
    Jun 2003
    Location
    Third planet from the Sun
    Posts
    1,250
    From Security Wire Digest:

    *MYSTERIOUS MALWARE HITS DNS SERVERS
    Malicious code—possibly related to the Microsoft Internet Explorer 'object
    type' vulnerability—is changing local DNS settings to random numbers. As a
    result, it makes all DNS-dependent applications, such as e-mail, Web
    access and internal servers unavailable.

    By presstime it was too early to say if the malware was only Web-based or
    if a worm or virus was involved. Network Associates reported the problem is being caused by a Trojan, but other antivirus researchers couldn't corroborate the findings.

    Security experts say that to fix the problem, clients need to be changed
    to get DNS from DHCP and rebooted. No patch is available to fix the flaw
    but Microsoft recommends changing IE Internet security zone settings to
    prompt them before running ActiveX components.

    For continuing coverage, please see:
    http://www.searchSecurity.com/origin...930281,00.html

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •