Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
For background you may wish to review this report and this issue about BIND 4 or 8 not being suitable as forwarders. Next, a request. PLEASE review your dns servers logs and cache for 65.23.154.2 If you find it listed as authoritative for .com please send us an email with a dump of the dns cache. Directions for dumping, cleaning and protecting your cache are available in the write-up above. . The link for this article located at SANS is no longer available. . Inspect the logs of your DNS servers regularly and implement measures to safeguard your cache from potential poisoning attacks.. DNS Security, Cache Management, Log Analysis, Threat Awareness, Server Protection. . Benjamin D. Thomas
Around 22:30 GMT on March 3, 2005 the SANS Internet Storm Center began receiving reports from multiple sites about DNS cache poisoning attacks that were redirecting users to websites hosting malware. As the "Handler on Duty" for March 4, I began investigating the incident over the course of the following hours and days. This report is intended to provide useful details about this incident to the community. The initial reports showed solid evidence of DNS cache poisoning, but there also seemed to be a spyware/adware/malware component at work. After complete analysis, the attack involved several different technologies: dynamic DNS, DNS cache poisoning, a bug in Symantec firewall/gateway products, default settings on Windows NT4/2000, spyware/adware, and a compromise of at least 5 UNIX webservers. We received information the attack may have started as early as Feb. 22, 2005 but probably only affected a small number of people. . On March 24, we received reports of a different DNS cache poisoning attack. This attack did not appear to affect as many people. This will be referred to as the "second attack" in the remainder of this report. After monitoring the situation for several weeks now, it has become apparent that the attacker(s) are changing their methods and toolset to point at different compromised servers in an effort to keep the attacks alive. This attack morphed into a similar attack with different IP addresses that users were re-directed toward. This will be referred to as the third attack and is still ongoing as of April 1, 2005. The link for this article located at isc.sans.org is no longer available. . On March 24, we received reports of a different DNS cache poisoning attack. This attack did not appe. around, march, internet, storm, center, began, receiving, reports, multip. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.