Full Disclosure mailing list archives
Re: MS DNS worm
From: "Zed Qyves" <zqyves.spamtrap () gmail com>
Date: Wed, 18 Apr 2007 16:58:58 +0300
Hello Geo, According to Symantec Blog "W32.Rinbot.BC" was the first worm to incorporate the DNS exploit in its spreading methods. Furthermore "W32.Rinbot.BC opens a back door that connects to the x.rofflewaffles.us domain and awaits for commands from the attacker." Is this something your customer is experiencing? Z. -- --------------------------------------------------------------------- Κρέων ἐν τῇδ᾽ ἔφασκε γῇ· τὸ δὲ ζητούμενον ἁλωτόν, ἐκφεύγειν δὲ τἀμελούμενον. Οιδίπους Τύρρανος [110] --------------------------------------------------------------------- Creon In this our land, so said he, those who seek Shall find; unsought, we lose it utterly. Oedipus Rex [110] --------------------------------------------------------------------- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- MS DNS worm Geo. (Apr 18)
- Re: MS DNS worm ad () heapoverflow com (Apr 18)
- <Possible follow-ups>
- Re: MS DNS worm Zed Qyves (Apr 18)