RE: DNS cache poisoning and pharming

Salvador.Manaois_at_infineon.com
Date: 05/31/05

  • Next message: mike_at_genxweb.net: "Re: user name from security logs"
    Date: Tue, 31 May 2005 22:15:02 +0800
    To: <david@clicksee.net>, <security-basics@securityfocus.com>
    
    

    Imho this is a serious threat that every sysadmin and ISO should be
    concerned with. Classic MITM attacks (with ARP spoofing) could be used
    to trick users to connect to a rogue DNS server which contains records
    of well-known sites which are actually spoofed on the attacker's web
    server. To the user, it would seem that he is connecting to the
    www.paypal.com (for example) when he is in fact connected to a spoofed
    page on the attacker's web server.

    Phishing requires some user interaction (clicking on some links, for
    example) but pharming is an entirely different story. The user might
    just type www.somepaysite.com in the address bar and would be shown a
    relatively harmless page.

    ...badz...
    http://www.rancidroot.blogspot.com

    -----Original Message-----
    From: David [mailto:david@clicksee.net]
    Sent: Tuesday, May 31, 2005 5:55 PM
    To: security-basics@securityfocus.com
    Subject: DNS cache poisoning and pharming

    http://hostsearch.com/news/logiguard_news_3177.asp
     
    This article makes a claim that DNS poisoning and pharming are really
    dangerous in that anyone can be redirected from trying to go to their
    online bank to a fake bank site where there login is collected. Is this
    really such a threat or is it just Logiguard advertising themselves?
     
    Thanks,
     
    Dave


  • Next message: mike_at_genxweb.net: "Re: user name from security logs"

    Relevant Pages

    • Re: Re. Suse 10.
      ... But anyway, 9.3 is still a current version, any updated drivers ... threat when you have a new question." ... conversation come argument with me saying its safe and him saying I needed ... I set about installing a scsi drive onto a mirror server, ...
      (alt.os.linux.suse)
    • Re: Re. Suse 10.
      ... But anyway, 9.3 is still a current version, any updated drivers ... threat when you have a new question." ... conversation come argument with me saying its safe and him saying I needed ... I set about installing a scsi drive onto a mirror server, ...
      (alt.os.linux.suse)
    • Re: Securing PHP
      ... You are checking for attacks coming from your own web server? ... is the situation with frames, Google doesn't have a chance to mess ... a specific IP address or piece of hardware (and a web server belonging ... Threat: Someone/something wants to have your site distribute viruses. ...
      (comp.lang.php)
    • Re: Encryption in OLAP
      ... There is no way that I know of to limit what *type* of client can ... >> What kind of threat attack are you looking to cover with encryption? ... >> authorized users obviously would have to the data decrypted for them to ... >> reverse engineering the data stream being passed from server to ...
      (microsoft.public.sqlserver.olap)
    • Re: DNS cache poisoning - Wake up everyone!
      ... what about companies that are large enough to run their own DNS ... pants down despite all the publicity this vulnerability has had. ... The risk is just too high. ... The threat is very serious, ...
      (uk.comp.sys.mac)