Re: [NGSEC] AntiPharming v1.00 FREE

From: Lance James (lancej_at_securescience.net)
Date: 06/15/05

  • Next message: Mandriva Security Team: "MDKSA-2005:101 - Updated tcpdump packages fix vulnerability"
    Date: Wed, 15 Jun 2005 12:24:01 -0700
    To: "lists@NGSEC" <lists@ngsec.com>
    
    

    This technology can be thwarted by any malware that has access to the
    Layered Service Provider using the service provider interface. That and
    client side malware will also target the anti-pharming tool to modify or
    break the program. What happens if the target can not reach the "3
    secure" dns servers? Do we successfully DoS the user?

    Thoughts?

    lists@NGSEC wrote:
    > -----BEGIN PGP SIGNED MESSAGE-----
    > Hash: SHA1
    >
    > Hello,
    >
    > NGSEC is proud to announce the new release of our new product
    > AntiPharming v1.00 [1] TOTALLY FREE for non-commercial use.
    >
    > What is Pharming?
    >
    > "(...)Pharming is the exploitation of a vulnerability in the DNS
    > server software that allows a hacker to acquire the Domain Name
    > for a site, and to redirect traffic to that web site to another
    > web site. DNS servers are the machines responsible for resolving
    > internet names into their real addresses - the "signposts" of the
    > internet.
    >
    > If the web site receiving the traffic is a fake web site, such
    > as a copy of a bank's website, it can be used to "phish" or steal
    > a computer user's passwords, PIN number or account number.
    >
    > AntiPharming Configuration For example, in January, 2005, the Domain
    > Name for a large New York ISP, Panix, was hijacked to a site in
    > Australia. In 2004 a German teenager hijacked the eBay.de Domain Name.
    > Secure e-mail provider Hushmail was also caught by this attack on
    > 24th of April 2005 when the attacker rang up the domain registrar
    > and gained enough information to redirect users to a defaced
    > webpage(...)" (Source WikiPedia).
    >
    > What is AntiPharming?
    >
    > AntiPharming uses active and passive protections for identifying and
    > stopping Pharming (Phising variant) attacks.
    >
    > AntiPharming will actively protect your windows server from pharming
    > attacks by:
    >
    > * Denying any user (even Administrator) to write to the hosts file.
    > * Denying any user (even Administrator) to change your DNS settings.
    >
    > AntiPharming will passively protect your windows server from pharming
    > attacks by sniffing on each netowrk interface for DNS replies (both
    > TCP and UDP) and recheck them against at least with three secure DNS
    > nameservers.
    >
    > AntiPharming is TOTALLY FREE for non-commercial use.
    >
    > This e-mail has been signed with labs@NGSEC PGP key available at:
    >
    > http://www.ngsec.com/pgp/labs.asc
    >
    > [1] http://www.ngsec.com/ngproducts/antipharming/
    >
    > Best Regards,
    >
    > - ---
    > NEXT GENERATION SECURITY, S.L. [NGSEC]
    > C\ O'donnell 46, 3º B
    > 28009 - Madrid, SPAIN
    > Tel: +34 91 435 56 27
    > Fax: +34 91 577 84 45
    >
    > http://www.ngsec.com
    > -----BEGIN PGP SIGNATURE-----
    > Version: GnuPG v1.4.1 (GNU/Linux)
    >
    > iD8DBQFCrrwBKrwoKcQl8Y4RAsO5AJwIJ1Ngm38IT0JCujagcAz4oWgUUwCgl0Lv
    > vWvO9R/kd5Skb/vzeER7kls=
    > =XCYN
    > -----END PGP SIGNATURE-----
    >
    >

    -- 
    Best Regards,
    Lance James
    Secure Science Corporation
    www.securescience.com
    Author of 'Phishing Exposed'
    http://www.securescience.net/amazon/
    Have Phishers stolen your customers' logins? Find out with DIA
    https://slam.securescience.com/signup.cgi - it's free!	
    

  • Next message: Mandriva Security Team: "MDKSA-2005:101 - Updated tcpdump packages fix vulnerability"

    Relevant Pages

    • Re: One DC cant resolve all external addesses
      ... > We originally had our only DC (with DHCP and DNS) running Exchange ... Then we DCPROMOd the original server to a member ... > display page" when we tried to go to the web site. ... You should turn off friendly HTTP errors so you can see the exact error. ...
      (microsoft.public.windows.server.dns)
    • Re: Unable to access site with same dns name as domain
      ... > The web site for the company is www.mycompany.org. ... > The DNS server is a PDC, with DNS and MSX 03 on it. ... 828731 - An External DNS Query May Cause an Error Message in Windows Server ...
      (microsoft.public.windows.server.dns)
    • Re: Stand Alone Internet DNS Only?
      ... [phone number on web site] ... so how would you add the domain if the ZONE doesn't match the Domain Name ... Well, it matters to YOU, but not to DNS. ... Let's say I am running the configure your server wizard and now it ...
      (microsoft.public.windows.server.dns)
    • One DC cant resolve all external addesses
      ... We originally had our only DC (with DHCP and DNS) running Exchange 5.5. ... DCPROMOd the original server to a member server. ... page" when we tried to go to the web site. ...
      (microsoft.public.windows.server.dns)
    • Re: Have to go to web site twice before it comes up
      ... try to hit a site, after I've tried the first time, and after the refresh. ... pretty sure the problem is not with DNS lookups). ... server as well as the 10.10.10.10 address. ... However, once this is done for the first page on a web site, ...
      (microsoft.public.win2000.networking)