AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-06-30
Updated July 1st 2005 00:04 UTC
"…New malware strategy of filtering packets instead of mucking with the local hosts files mentioned in the excellent F-Secure blog http://www.f-secure.com/weblog/#00000585
and the full description here: http://www.f-secure.com/v-descs/fantibag_b.shtml
So instead of redirecting Anti-Virus sites to localhost (127.0.0.1) http://www.answers.com/topic/localhost
and essentially preventing firewall and anti-virus updates from occurring,
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.symantec.com
127.0.0.1 www.mcafee.com
it blocks the actual network traffic. Much harder to detect and troubleshoot…"

- http://isc.sans.org/diary.php?date=2005-06-30
Updated July 1st 2005 00:04 UTC
"…New malware strategy of filtering packets instead of mucking with the local hosts files mentioned in the excellent F-Secure blog http://www.f-secure.com/weblog/#00000585
and the full description here: http://www.f-secure.com/v-descs/fantibag_b.shtml
So instead of redirecting Anti-Virus sites to localhost (127.0.0.1) http://www.answers.com/topic/localhost
and essentially preventing firewall and anti-virus updates from occurring,
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.symantec.com
127.0.0.1 www.mcafee.com
it blocks the actual network traffic. Much harder to detect and troubleshoot…"