AplusWebMaster
Topic Starter
FYI…
Increasing Number of Malicious DNS Servers Reported
- http://preview.tinyurl.com/yvn3s5
14 February 2008 (redOrbit news) - "A paper published this week by researchers with the Georgia Institute of Technology and Google Inc. noted a rise in hacker activity aimed toward controlling infected computers and stealing user identities. In the paper, which was presented at the Internet Society's Network and Distributed System Security Symposium in San Diego, they reported an estimated 68,000 servers currently returning malicious Domain Name System results. These rogue DNS servers are used to re-route computers to spoof sites, some of which appear to be very convincing. These spoof sites can be full of code or walls of ads which redirect funds back to the hackers… These profit-driven attacks aren’t new to the Web. The paper studied viruses which appeared back in 2003. Researchers noted that oftentimes, the rogue DNS servers will try to disguise its activity by sporadically directing traffic to the proper sites, making it appear as though the Internet is running as it should. Most updated antivirus software is capable of locating the faulty DNS servers. After a computer is infected, users should re-scan their machines to return to the proper settings. Security experts noted that the paper, which is the most comprehensive studies performed on the topic to date, adds valuable insight into the increasingly popular form of attack. "A lot of people don't realize the seriousness of it," said Paul Ferguson, a threat researcher with Trend Micro Inc. "The problem is getting worse".

Increasing Number of Malicious DNS Servers Reported
- http://preview.tinyurl.com/yvn3s5
14 February 2008 (redOrbit news) - "A paper published this week by researchers with the Georgia Institute of Technology and Google Inc. noted a rise in hacker activity aimed toward controlling infected computers and stealing user identities. In the paper, which was presented at the Internet Society's Network and Distributed System Security Symposium in San Diego, they reported an estimated 68,000 servers currently returning malicious Domain Name System results. These rogue DNS servers are used to re-route computers to spoof sites, some of which appear to be very convincing. These spoof sites can be full of code or walls of ads which redirect funds back to the hackers… These profit-driven attacks aren’t new to the Web. The paper studied viruses which appeared back in 2003. Researchers noted that oftentimes, the rogue DNS servers will try to disguise its activity by sporadically directing traffic to the proper sites, making it appear as though the Internet is running as it should. Most updated antivirus software is capable of locating the faulty DNS servers. After a computer is infected, users should re-scan their machines to return to the proper settings. Security experts noted that the paper, which is the most comprehensive studies performed on the topic to date, adds valuable insight into the increasingly popular form of attack. "A lot of people don't realize the seriousness of it," said Paul Ferguson, a threat researcher with Trend Micro Inc. "The problem is getting worse".