AplusWebMaster
Topic Starter
FYI…
Widespread Internet Attack Cripples Computers with Spyware
Experts say at least 20,000 PCs already have been affected. Is your company next?
- http://www.pcworld.com/resource/printable/…d,120448,00.asp
"…It starts with an assault known as DNS poisoning: Domain name system servers, which guide Internet traffic, are fooled into directing anyone heading to any .com Web site–for example, …cnn.com or …americanexpress.com–to a malicious Web site that the attackers control. That Web site then surreptitiously installs a wide range of adware and spyware on the victim's computer. Companies suffer from the attack in a number of ways. First, the Internet connection for anyone using the poisoned DNS server–often the entire company in the case of smaller businesses–is completely disrupted. All Web traffic and e-mail trying to go to any .com site gets hijacked for as long as the DNS server remains compromised. Even after the DNS server is fixed, the company has to clean the adware and spyware from any affected computers, an onerous task that can keep IT people like David Parsons, who supports about 7000 people in his help-desk job at a Boston hospital, extremely busy. Parsons says his hospital was "slammed for about two days straight" by the DNS poisoning attacks starting March 29. Dunham conservatively estimates that 3000 DNS servers at a range of U.S. companies, including at least two with more than 8000 employees, were compromised over the past month.
"It's a very sophisticated attack," Dunham says. His company sent out a high-level threat warning to its clients, which includes Fortune 500 companies and government organizations. Dunham notes that both DNS poisoning attacks and the types of spyware and adware involved have been around for some time. But, he says, "this [attack] certainly is unprecedented in terms of the methodology and the sheer scope of adware and spyware installed." However, Web surfers at home generally are not vulnerable to this type of attack. Most ISPs use a type of DNS server called BIND, which is not directly affected by attempts at DNS poisoning. But older BIND servers can contribute to the problem by passing the attack along to vulnerable Windows DNS servers…"All the installation is done silently, in the background, with no user interaction," says Dunham…
What You Can Do
The bad news is that there's not much you can do personally to guard your work computer from being affected by DNS poisoning. You have no good way to avoid using DNS or to protect yourself if your company's DNS servers have been hit. Your IT department must make sure your DNS servers are not vulnerable. But you can protect yourself against the malicious software installs by making sure your version of Internet Explorer is up-to-date with all current patches. Other browsers, such as Firefox, are not vulnerable to such installs…
What's Behind It
Joe Stewart, a senior threat researcher at LURHQ, a South Carolina-based Internet security company that independently studied these attacks, analyzed the Web site redirection involved and the links in the two apparent Web search pages that resulted. Stewart found that clicking on one of the advertiser links in either of the sites sends information to Findwhat.com, an Internet marketing company that counts pay-per-click advertising as a big part of its business. The information sent includes one of two account numbers. That sent number notifies Findwhat to transfer payment to that particular account. So, according to Stewart, the attack is all about money…"
- http://www.lurhq.com/ppc-hijack.html
"…The incident in question involves DNS hijacking, and was widely reported in the beginning of 2005. The hijack was simple, and the vulnerability old and well-known. It involved a rogue DNS server sending bogus authority records in a DNS reply packet, in which it claimed to be the authoritative server for all of the .com TLD. Vulnerable hosts would then direct queries for any .com sites to the rogue DNS server. See the incidents.org March 31 Handler's Diary for details ( http://isc.sans.org/diary.php?date=2005-03-31 ).
Update: Several people have asked how to stop the hijacking from occurring on their computer. End users may not be able to prevent cache poisoning - the problem lies with the user's ISP or company DNS servers. Users may direct the persons responsible for maintenence of the DNS servers to Microsoft's KnowledgeBase article 241352 ( http://support.microsoft.com/default.aspx?…kb;en-us;241352 ), which explains how to secure Windows DNS servers against this type of cache poisoning (or "cache pollution", as Microsoft calls it). Modern *nix-based DNS servers are not vulnerable to this type of attack. This vulnerability in Windows DNS services has been common knowledge for nearly four years now ( http://www.kb.cert.org/vuls/id/109475 - Date First Published 08/09/2001 )…
At this point we can see clearly what is happening - the big-name companies are advertising on legitimate networks that utilize pay-per-click search engines to drive traffic to the ads. Unfortunately, the pay-per-click model lends itself to abuse by rogue affiliates who will hijack users in order to drive up their click count and revenue. At the heart of the pay-per-click model is findwhat.com. While it is a legitimate enterprise itself, it is the entity that pays the affiliates who are actively employing trojans and dns cache poisoning to drive traffic to the advertisers. FindWhat has a policy prohibiting certain activities of this type, and will likely terminate any affiliate account reported to them for abuse. However, terminating the account only means that FindWhat benefits from the hijacker's activity without having to pay the hijacking affiliate. It's a win-win situation for them. FindWhat's estimated earnings for 2004 were between $167.5 and $179.5 million dollars. There is no way to determine how much of that revenue was generated by traffic from hijacked machines…
It doesn't seem too far-fetched to imagine that the persons responsible for the DNS hijacking could be apprehended simply by serving FindWhat with a subpoena to find out where they've been sending the checks for the affiliate IDs being passed in the search redirects. However, this activity has persisted for years now without much law enforcement interest, and as each new affiliate comes on board they invent their own scheme to abuse the PPC system. Clearly it seems that through the chain of advertiser to consumer and back again, the end user is ultimately paying to have him or herself hijacked…"

Widespread Internet Attack Cripples Computers with Spyware
Experts say at least 20,000 PCs already have been affected. Is your company next?
- http://www.pcworld.com/resource/printable/…d,120448,00.asp
"…It starts with an assault known as DNS poisoning: Domain name system servers, which guide Internet traffic, are fooled into directing anyone heading to any .com Web site–for example, …cnn.com or …americanexpress.com–to a malicious Web site that the attackers control. That Web site then surreptitiously installs a wide range of adware and spyware on the victim's computer. Companies suffer from the attack in a number of ways. First, the Internet connection for anyone using the poisoned DNS server–often the entire company in the case of smaller businesses–is completely disrupted. All Web traffic and e-mail trying to go to any .com site gets hijacked for as long as the DNS server remains compromised. Even after the DNS server is fixed, the company has to clean the adware and spyware from any affected computers, an onerous task that can keep IT people like David Parsons, who supports about 7000 people in his help-desk job at a Boston hospital, extremely busy. Parsons says his hospital was "slammed for about two days straight" by the DNS poisoning attacks starting March 29. Dunham conservatively estimates that 3000 DNS servers at a range of U.S. companies, including at least two with more than 8000 employees, were compromised over the past month.
"It's a very sophisticated attack," Dunham says. His company sent out a high-level threat warning to its clients, which includes Fortune 500 companies and government organizations. Dunham notes that both DNS poisoning attacks and the types of spyware and adware involved have been around for some time. But, he says, "this [attack] certainly is unprecedented in terms of the methodology and the sheer scope of adware and spyware installed." However, Web surfers at home generally are not vulnerable to this type of attack. Most ISPs use a type of DNS server called BIND, which is not directly affected by attempts at DNS poisoning. But older BIND servers can contribute to the problem by passing the attack along to vulnerable Windows DNS servers…"All the installation is done silently, in the background, with no user interaction," says Dunham…
What You Can Do
The bad news is that there's not much you can do personally to guard your work computer from being affected by DNS poisoning. You have no good way to avoid using DNS or to protect yourself if your company's DNS servers have been hit. Your IT department must make sure your DNS servers are not vulnerable. But you can protect yourself against the malicious software installs by making sure your version of Internet Explorer is up-to-date with all current patches. Other browsers, such as Firefox, are not vulnerable to such installs…
What's Behind It
Joe Stewart, a senior threat researcher at LURHQ, a South Carolina-based Internet security company that independently studied these attacks, analyzed the Web site redirection involved and the links in the two apparent Web search pages that resulted. Stewart found that clicking on one of the advertiser links in either of the sites sends information to Findwhat.com, an Internet marketing company that counts pay-per-click advertising as a big part of its business. The information sent includes one of two account numbers. That sent number notifies Findwhat to transfer payment to that particular account. So, according to Stewart, the attack is all about money…"
- http://www.lurhq.com/ppc-hijack.html
"…The incident in question involves DNS hijacking, and was widely reported in the beginning of 2005. The hijack was simple, and the vulnerability old and well-known. It involved a rogue DNS server sending bogus authority records in a DNS reply packet, in which it claimed to be the authoritative server for all of the .com TLD. Vulnerable hosts would then direct queries for any .com sites to the rogue DNS server. See the incidents.org March 31 Handler's Diary for details ( http://isc.sans.org/diary.php?date=2005-03-31 ).
Update: Several people have asked how to stop the hijacking from occurring on their computer. End users may not be able to prevent cache poisoning - the problem lies with the user's ISP or company DNS servers. Users may direct the persons responsible for maintenence of the DNS servers to Microsoft's KnowledgeBase article 241352 ( http://support.microsoft.com/default.aspx?…kb;en-us;241352 ), which explains how to secure Windows DNS servers against this type of cache poisoning (or "cache pollution", as Microsoft calls it). Modern *nix-based DNS servers are not vulnerable to this type of attack. This vulnerability in Windows DNS services has been common knowledge for nearly four years now ( http://www.kb.cert.org/vuls/id/109475 - Date First Published 08/09/2001 )…
At this point we can see clearly what is happening - the big-name companies are advertising on legitimate networks that utilize pay-per-click search engines to drive traffic to the ads. Unfortunately, the pay-per-click model lends itself to abuse by rogue affiliates who will hijack users in order to drive up their click count and revenue. At the heart of the pay-per-click model is findwhat.com. While it is a legitimate enterprise itself, it is the entity that pays the affiliates who are actively employing trojans and dns cache poisoning to drive traffic to the advertisers. FindWhat has a policy prohibiting certain activities of this type, and will likely terminate any affiliate account reported to them for abuse. However, terminating the account only means that FindWhat benefits from the hijacker's activity without having to pay the hijacking affiliate. It's a win-win situation for them. FindWhat's estimated earnings for 2004 were between $167.5 and $179.5 million dollars. There is no way to determine how much of that revenue was generated by traffic from hijacked machines…
It doesn't seem too far-fetched to imagine that the persons responsible for the DNS hijacking could be apprehended simply by serving FindWhat with a subpoena to find out where they've been sending the checks for the affiliate IDs being passed in the search redirects. However, this activity has persisted for years now without much law enforcement interest, and as each new affiliate comes on board they invent their own scheme to abuse the PPC system. Clearly it seems that through the chain of advertiser to consumer and back again, the end user is ultimately paying to have him or herself hijacked…"