Here is a News Item from Tech Web ( Saturday March 5, 2005 ) that tells how extensive a threat is facing our computers and the internet.
Personalize News Home Page
Yahoo! News   Sat, Mar 05, 2005
Search for    Advanced
News Home
Top Stories
U.S. National
Business
World
Entertainment
Sports
Technology
   Internet
   Personal Tech.
   Communications
   Software
   Enterprise
   Apple/Macintosh
   Linux/Open Source
Most Popular
Tech Tuesday
Politics
Science
Health
Oddly Enough
Op/Ed
Local
Comics
News Photos
Most Popular
Weather
Audio/Video
Full Coverage


News Resources
Providers
· Reuters
· AP
· washingtonpost.com
· USATODAY.com
· NewsFactor
· PC World
· AFP
· Ziff Davis
· InfoWorld
· SiliconValley.com
· TechWeb
· CP
Services
· News Alerts


News via RSS
Technology News
Technology
Internet
Personal Tech
Wireless
Linux/Open Source
Software
Enterprise
Apple/Macintosh
Tech Tuesday

More Tech Feeds | All Feeds
Technology - TechWeb
tech_web.gif (1386 bytes)

Possible Domain Poisoning Underway


Fri Mar 4, 7:24 PM ET

addtomyyahoo3.gif (568 bytes)  Technology - TechWeb

Security experts late Friday warned that a DNS cache poisoning attack may be underway and redirecting users from some of the most popular Web sites to a malicious URL where spyware and adware is invisibly installed onto their computers.

tech_web2.gif (2391 bytes)

More On Storage
More On Security & Privacy
More On Servers
More On Small Biz
More On Mobile & Wireless
More On Data Center Mgmt


According to the Internet Storm Center, which posted an alert on its Web site, it had received reports that the attack was redirecting traffic from popular domains such as google.com, ebay.com, and weather.com.

DNS cache poisoning occurs when an attacker hacks into a domain name server, then "poisons" the cache by planting counterfeit data in the cache of the name server. When a user requests, say, ebay.com, and the IP address is resolved by the hacked domain server, the bogus data is fed back to the browser.

Another tactic, dubbed "DNS hijacking," is similar, but simply changes the domain server so that traffic is actually re-routed.

It's unclear which of the two tactics this attack is using.

Even security firms had difficulty confirming the attack, however. Dan Hubbard, the senior director of security at San Diego-based Websense, for instance, said that his team had been investigating the report for several hours but had not yet been able to hit a domain server that had been poisoned.

But Websense's monitoring of its customer's usage patterns did pick up a spike in traffic to the three malicious sites supposedly feeding spyware to redirected users. (In turn, the three feed users to one single site.)

"It's circumstantial evidence," he said, "but it seems something is going on."

Nor was Hubbard able to confirm the targets of the poison and/or hijack. "We haven't been able to trace a redirect from, say, Google," he added.

The hack could be quite localized if, for instance, the affected domain server was one operated by an enterprise or small Internet service provider. "It's certainly not at the root level, or we'd all end up at this malicious site."

Domain cache poisoning and domain hijacking, while rare, are not unheard of. In the late 1990s, a vulnerability in BIND (Berkeley Internet Name Domain), the software used by nearly all of the name servers on the Internet, was disclosed. A few exploits followed. And in 2000, RSA Security was victimized by a Web defacement that really wasn't: instead, domain cache poisoning simply fed bogus pages to users.

"One interesting thing about malicious Web sites is that the hackers have to get people to the site," said Hubbard. "How they get people to their sites is becoming very important. In this case, they're getting more creative than the traditional phishing or instant messaging approach where links are sent to users."

The adware and spyware on the malicious sites is thankfully "not very dangerous," said Hubbard. The sites try to download and install code and an Active X control called "ABC Search Webinstall" that changes the browser's toolbar, its home page, and search preferences, among other things.

For additional details of the attack as they become available, refer to the Internet Storm Center's Diary page, which promises to update as the Center finds out more.


Click Here to Read About BHO's and
how You can protect Yourself.


Click Here to see the details of an
attempted intrusion from China

Click Here to See the Code/Program that was
a BHO on My Computer


Story Tools

Mail to Friend  Email Story
Message Boards   Post/Read Msgs
Printer Version   Print Story  
Ratings: Would you recommend this story?
Not at all 1 - 2 - 3 - 4 - 5 Highly




Prev. Story: Report: AMD's Flash Unit Being Prepared For Possible Spin Off (TechWeb)
Next Story: Disk-Storage Market Topped $13 Billion In 2004 (TechWeb)


More Technology - Top Stories Stories
· 'Wrist Video' Gives Israeli Army an Edge   (AP)
· ChoicePoint Data Cache Became a Powder Keg  (washingtonpost.com)
· Andrew Kantor: CyberSpeak - Remember that computers need tune-ups too  (USATODAY.com)
· The Bleeding Edge of Computing  (NewsFactor)
· Analysis: Intel on Track to Rebound in 2005  (PC World)

Sponsored Links

  • Free Adware and Spyware Removal Tutorial

    Our free tutorial will help you to choose spyware removal software. Remove malware, keyloggers, spyware, adware, trojans and some viruses in a couple of ...

    www.spywarefightingguide.com

  • Remove Adware - Free Scan

    Remove adware, spyware, malware and keyloggers from you PC. Protect yourself from identity theft while speeding up your PC.

    www.free-spyware-scan.com

  • $39.90 Download McAfee Anti Spyware Now

    Automatically detect, remove and prevent all spyware, adware and identity theft attacks now. Download immediately or get CD. Authorized McAfee Partner. Save $30 ...

    www.secureie.com

( )





Copyright © 2005 CMP Media LLC.