Welcome! Register for a free account (or login) > How does it work?
|
|


Mar 16 2009, 02:38 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 4,571 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3 |
FYI...
- http://isc.sans.org/diary.html?storyid=6025 Last Updated: 2009-03-16 19:49:12 UTC - "...new version of rogue DHCP server malware... The malware appears to be similar to Trojan.Flush.M which was found last December. Like back then, after infecting its target, the malware installs a rogue DHCP server. The main goal of the DHCP server is to spread a bad DNS server IP address... summary of the differences: • The new version sets the DHCP lease time to 1 hour. • It sets the MAC destination to the broadcast address, rather then the MAC address of the DHCP client. • It does not specify a DNS Domain Name. • The options field does not contain an END option followed by PAD options. • Unlike Trojan.Flush.M, the BootP Broadcast Bit is set. The malicious DNS server is 64.86.133.51 and 63.243.173.162. Recommendation: Monitor connections to DNS servers other then the approved one pushed out by your DHCP server. This should help you spot this kind of malware. Yes, you can block the two IP addresses listed above, but it will likely do little good." |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
267 | AplusWebMaster | 19,325 | 51 minutes ago Last post by: AplusWebMaster |
|||
![]() |
17 | hubbcap_86 | 299 | Today, 12:12 PM Last post by: schrauber |
|||
![]() |
3 | dsimono | 113 | Today, 11:49 AM Last post by: dsimono |
|||
![]() |
2 | AplusWebMaster | 72 | Yesterday, 01:36 PM Last post by: AplusWebMaster |
|||
|
Time is now: 18th March 2010 - 03:12 PM |