This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Dns Poisoning...

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Widespread Internet Attack Cripples Computers with Spyware
Experts say at least 20,000 PCs already have been affected. Is your company next?
- http://www.pcworld.com/resource/printable/…d,120448,00.asp
"…It starts with an assault known as DNS poisoning: Domain name system servers, which guide Internet traffic, are fooled into directing anyone heading to any .com Web site–for example, …cnn.com or …americanexpress.com–to a malicious Web site that the attackers control. That Web site then surreptitiously installs a wide range of adware and spyware on the victim's computer. Companies suffer from the attack in a number of ways. First, the Internet connection for anyone using the poisoned DNS server–often the entire company in the case of smaller businesses–is completely disrupted. All Web traffic and e-mail trying to go to any .com site gets hijacked for as long as the DNS server remains compromised. Even after the DNS server is fixed, the company has to clean the adware and spyware from any affected computers, an onerous task that can keep IT people like David Parsons, who supports about 7000 people in his help-desk job at a Boston hospital, extremely busy. Parsons says his hospital was "slammed for about two days straight" by the DNS poisoning attacks starting March 29. Dunham conservatively estimates that 3000 DNS servers at a range of U.S. companies, including at least two with more than 8000 employees, were compromised over the past month.
"It's a very sophisticated attack," Dunham says. His company sent out a high-level threat warning to its clients, which includes Fortune 500 companies and government organizations. Dunham notes that both DNS poisoning attacks and the types of spyware and adware involved have been around for some time. But, he says, "this [attack] certainly is unprecedented in terms of the methodology and the sheer scope of adware and spyware installed." However, Web surfers at home generally are not vulnerable to this type of attack. Most ISPs use a type of DNS server called BIND, which is not directly affected by attempts at DNS poisoning. But older BIND servers can contribute to the problem by passing the attack along to vulnerable Windows DNS servers…"All the installation is done silently, in the background, with no user interaction," says Dunham…
What You Can Do
The bad news is that there's not much you can do personally to guard your work computer from being affected by DNS poisoning. You have no good way to avoid using DNS or to protect yourself if your company's DNS servers have been hit. Your IT department must make sure your DNS servers are not vulnerable. But you can protect yourself against the malicious software installs by making sure your version of Internet Explorer is up-to-date with all current patches. Other browsers, such as Firefox, are not vulnerable to such installs…
What's Behind It
Joe Stewart, a senior threat researcher at LURHQ, a South Carolina-based Internet security company that independently studied these attacks, analyzed the Web site redirection involved and the links in the two apparent Web search pages that resulted. Stewart found that clicking on one of the advertiser links in either of the sites sends information to Findwhat.com, an Internet marketing company that counts pay-per-click advertising as a big part of its business. The information sent includes one of two account numbers. That sent number notifies Findwhat to transfer payment to that particular account. So, according to Stewart, the attack is all about money…"

- http://www.lurhq.com/ppc-hijack.html
"…The incident in question involves DNS hijacking, and was widely reported in the beginning of 2005. The hijack was simple, and the vulnerability old and well-known. It involved a rogue DNS server sending bogus authority records in a DNS reply packet, in which it claimed to be the authoritative server for all of the .com TLD. Vulnerable hosts would then direct queries for any .com sites to the rogue DNS server. See the incidents.org March 31 Handler's Diary for details ( http://isc.sans.org/diary.php?date=2005-03-31 ).
Update: Several people have asked how to stop the hijacking from occurring on their computer. End users may not be able to prevent cache poisoning - the problem lies with the user's ISP or company DNS servers. Users may direct the persons responsible for maintenence of the DNS servers to Microsoft's KnowledgeBase article 241352 ( http://support.microsoft.com/default.aspx?…kb;en-us;241352 ), which explains how to secure Windows DNS servers against this type of cache poisoning (or "cache pollution", as Microsoft calls it). Modern *nix-based DNS servers are not vulnerable to this type of attack. This vulnerability in Windows DNS services has been common knowledge for nearly four years now ( http://www.kb.cert.org/vuls/id/109475 - Date First Published 08/09/2001 )…
At this point we can see clearly what is happening - the big-name companies are advertising on legitimate networks that utilize pay-per-click search engines to drive traffic to the ads. Unfortunately, the pay-per-click model lends itself to abuse by rogue affiliates who will hijack users in order to drive up their click count and revenue. At the heart of the pay-per-click model is findwhat.com. While it is a legitimate enterprise itself, it is the entity that pays the affiliates who are actively employing trojans and dns cache poisoning to drive traffic to the advertisers. FindWhat has a policy prohibiting certain activities of this type, and will likely terminate any affiliate account reported to them for abuse. However, terminating the account only means that FindWhat benefits from the hijacker's activity without having to pay the hijacking affiliate. It's a win-win situation for them. FindWhat's estimated earnings for 2004 were between $167.5 and $179.5 million dollars. There is no way to determine how much of that revenue was generated by traffic from hijacked machines…
It doesn't seem too far-fetched to imagine that the persons responsible for the DNS hijacking could be apprehended simply by serving FindWhat with a subpoena to find out where they've been sending the checks for the affiliate IDs being passed in the search redirects. However, this activity has persisted for years now without much law enforcement interest, and as each new affiliate comes on board they invent their own scheme to abuse the PPC system. Clearly it seems that through the chain of advertiser to consumer and back again, the end user is ultimately paying to have him or herself hijacked…"

:huh: :( :ph34r:
FYI…

Hushmail hit by DNS attack
- http://www.theregister.co.uk/2005/04/25/hushmail_dns_attack/
25 April 2005
"Surfers trying to visit the web site of popular secure email service Hushmail were redirected to a false site early Sunday following a hacking attack. Hush Communications said hackers changed Hushmail's DNS records after "compromising the security" of its domain registrar (Network Solutions). These changes were undone after a few hours on Sunday and normal Hushmail services have now been restored…the impact of the attack was limited to lost email…Hush Communications said Hushmail users said users should be careful to make sure they are on its secure web page before they enter their pass phrase. "If your browser displays any error messages about the 'certificate' that verifies the website, do not continue," it adds."
- https://www.hushmail.com/login-status?PHPSE…8bfd5fb87ac684e
"Some servers throughout the Internet are still caching the wrong addresses for hushmail.com. We expect that all these addresses will be updated in the next 6 or 7 hours. In the interim, users are now able to access Hushmail through https://www.hush.com . This will avoid the problems associated with hushmail.com DNS records as the hush.com DNS settings were not affected…"

:ph34r:
FYI…

Continued DNS poisonings
- http://isc.sans.org/diary.php?date=2005-04-27
Updated April 28th 2005 15:52 UTC
"We continue to get reports of sporadic DNS cache poisonings. We've covered this in great detail earlier this month, so we won't spend a lot of time on it except to remind folks that the Internet Software Consortium (maintainer of BIND) agrees that BIND 4 and 8 are no longer suitable for use as forwarders, so, if you are running DNS servers that act as forwarders, please upgrade as soon as possible."

- http://www.isc.org/index.pl?/sw/bind/

.
FYI…

- http://isc.sans.org/diary.php?date=2005-04-28
Updated April 28th 2005 21:31 UTC
Safe Forwarding
"From: http://www.isc.org/index.pl?/sw/bind/
BIND4/BIND8 Unsuitable for Forwarder Use
If a nameserver – any nameserver, whether BIND or otherwise – is configured to use forwarders, then none of the the target forwarders can be running BIND4 or BIND8. Upgrade all nameservers used as forwarders to BIND9 . There is a current, wide scale Kashpureff-style DNS cache corruption attack which depends on BIND4 and BIND8 as forwarders targets.
Very useful BIND security matrix illustrating what issues affect which versions of BIND:
http://www.isc.org/sw/bind/bind-security.php
Also be sure to check out the fine template from Team CYMRU:
http://www.cymru.com/Documents/secure-bind-template.html …"

:huh:
FYI…

One more scripted mass hack
- http://isc.sans.org/diary.php?date=2005-05-05
Updated May 5th 2005 23:34 UTC
"It seems as if several web sites were modified in yet another mass hack yesterday, similar to the one we've reported two months ago ( http://isc.sans.org/diary.php?date=2005-03-13 ). Most likely, a script was used to amend all web sites hosted on one or more shared servers with a hostile IFRAME, redirecting visitors… Don't go there - it's an Adware site… places where you maybe should not tread, including a page… that tries the CHM exploit to drop a present. Checking with a search engine, it looks as if more than 1500 pages have been thus modified…"

:ph34r:
FYI…

OhMyGodGoogleIsGone!
- http://isc.sans.org/diary.php?date=2005-05-08
Updated May 9th 2005 06:05 UTC
"…Google went bye-bye for 15 minutes. Or perhaps it was an hour. It depends on who you ask… (or how long your DNS server cached the bogus information). This is, of course, one of several signs that Nostradamus predicted would signal the end days. And while several people were quick to expound theories about what caused the outage, we prefer to stick with the simplest explanation (which is also what Google is saying…): it was a DNS issue. Somebody in charge of Google’s DNS did something dumb. It fits the facts as we have heard them (“google.com” unavailable, but still reachable if you used the IP address). But what of the mysterious “redirects” to other search pages? Yesterday we reported that readers were seeing some suspicious “redirects” to an alternate search engine called “SoGoSearch.” It turns out that “SoGoSearch” owns the domain name “com.net,” and the machines “www.google.com.net” and “google.com.net” lead you to their search engine. So… if an overzealous browser tried to “fix” an unavailable “google.com,” it’s quite likely that you could end up looking at the SoGo search engine. As an aside: The fact that you can do a WHOIS lookup and find a listing showing:
GOOGLE.COM.SU***.FIND.CRACKZ.WITH.SEARCH.*****.COM
doesn’t mean that the entire DNS system has been compromised. It simply means that someone with far too much time on their hands registered their nameserver with that goofy name. Such childish stunts are widely acknowledged to increase your attractiveness to the opposite sex…"

:huh:
FYI…

DNS Denial of Service Vulnerability
- http://isc.sans.org/diary.php?date=2005-05-24
Updated May 24th 2005 21:20 UTC
"Earlier today, the NISCC released an advisory that involves a problem with some implementations of DNS. The vulnerability occurs during a recursion process used to decompress compressed DNS messages. Using specially crafted DNS packets, it is possible to cause vulnerable DNS servers to abnormally terminate. Later this afternoon, Cisco and Secunia both issued similar advisories which show some of the Cisco products that are vulnerable to this issue. For more information on this, please see the below URLs:

http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html

http://www.cisco.com/warp/public/707/cisco…50524-dns.shtml

http://secunia.com/advisories/15472/ …"

:ph34r: