Major DNS cache poisoning at Verisign/WorldNIC

From: Matthew F. Caldwell (mattc@guarded.net)
Date: 03/19/02


Date: Tue, 19 Mar 2002 14:18:56 -0500
From: "Matthew F. Caldwell" <mattc@guarded.net>
To: <incidents@securityfocus.com>

Just to let everyone know, there has been some major DNS cache poisoning going on at Verisign apparently done by some Brazilians ("Web Pirates") for web site defacements. If your parking your DNS at worldnic.com (netsol/verisign) you might want to see if you site has been redirected to 64.225.154.175 (owned by Interland of Atlanta) using random DNS servers.

Don't you love UDP.

Matthew F. Caldwell, CISSP
Chief Security Officer
GuardedNet, Inc

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: Malicious web sites
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: [incident] IIS defacement through FTP, possible DoS
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Distributed ICMP/UDP scan or attack?
    ... This list is provided by the SecurityFocus ARIS analyzer service. ... and tracking system please see: http://aris.securityfocus.com ... For more information on this free incident handling, management ...
    (Incidents)
  • Re: strange attacks - flood udp packets from 1030 to msql
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Can anyone identify this backdoor?
    ... > and tracking system please see: http://aris.securityfocus.com ... This list is provided by the SecurityFocus ARIS analyzer service. ... For more information on this free incident handling, management ...
    (Incidents)