DNS hacked/hijacked by the "Delude.B" trojan

From: Jonathan de Boyne Pollard (J.deBoynePollard_at_Tesco.NET)
Date: 10/05/03

  • Next message: Nico Kadel-Garcia: "Re: See important pack from MS Corporation"
    Date: Sun, 05 Oct 2003 11:04:55 +0100
    
    

    JF> the address that my DNS was changed to was 69.57.146.14, which
    JF> is different from the 207.44.194.56 used in the Hosts file.

    That should come as no surprise. The former was where the attacker intended
    to provide his/her own proxy DNS service to you, publishing name->address
    mappings of his/her choosing; and the latter was part of one of those very
    mappings, directing you to where the attacker intended to provide his/her own
    content HTTP service (amongst others), providing web pages of his/her choosing
    and impersonating other entities.

    This ploy has been well-known for years. The only novelty of this attack, if
    there can be said to be any at all, is that someone found a means of having a
    large number of people execute the trojan unwittingly.

    And, of course, one question that affected people should be asking themselves
    is why they were running Microsoft's Internet Explorer under the aegis of a
    user account that is allowed to reconfigure their machine.


  • Next message: Nico Kadel-Garcia: "Re: See important pack from MS Corporation"

    Relevant Pages

    • DNS hacked/hijacked by the "Delude.B" trojan
      ... to provide his/her own proxy DNS service to you, ... mappings, directing you to where the attacker intended to provide his/her own ... providing web pages of his/her choosing ...
      (microsoft.public.win2000.security)
    • DNS hacked/hijacked by the "Delude.B" trojan
      ... The DNS addresses were: ... You've been hit by the "Delude.B" trojan. ... name->address mappings of his/her choosing, ... passing it a command script containing commands to ...
      (comp.os.ms-windows.nt.admin.security)
    • DNS hacked/hijacked by the "Delude.B" trojan
      ... The DNS addresses were: ... You've been hit by the "Delude.B" trojan. ... name->address mappings of his/her choosing, ... passing it a command script containing commands to ...
      (microsoft.public.win2000.security)
    • Re: slow drive mappings
      ... -Drive mappings are Lan mappings. ... A mapping from XP to only the Windows SBS server worked fine. ... > Are your client PCs looking only at the DNS on the SBS server? ... >> When users browse in their windows explorer to their drive mappings ...
      (microsoft.public.windowsxp.network_web)
    • Re: DNS Design Question--revisited
      ... > you are using cannot support AD's requirements. ... Choosing not to ... > DNS on the NW servers is the same thing that I was saying. ... Meaning DNS or the NW servers themselves? ...
      (microsoft.public.win2000.dns)