Full Disclosure mailing list archives

Re: Mystery DNS Changes


From: "Mary Landesman" <mlande () bellsouth net>
Date: Wed, 1 Oct 2003 17:12:48 -0400

This exploit has been dubbed QHosts-1 Trojan by NAI. Details can be found
at:
http://vil.nai.com/vil/content/v_100719.htm

Regards,
Mary Landesman
Antivirus About.com Guide
http://antivirus.about.com

----- Original Message ----- 
From: "Hansen, Kevin" <kevin.hansen () thomson com>
To: <full-disclosure () lists netsys com>
Sent: Wednesday, October 01, 2003 3:19 PM
Subject: [Full-disclosure] Mystery DNS Changes


We have seen multiple instances where DHCP enabled workstations have had
their DNS reconfigured to point to two of the three addresses listed below.
Can anyone else confirm this? Incidents.org is reporting an increase in port
53 traffic over the last two days. Are we looking at the precursor to the
next worm?

216.127.92.38
69.57.146.14
69.57.147.175

-KJH

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: