4/8/2005

DNS Cache Poisoning Hacks on the Rise

Filed under: Aviran Mordo @ 1:19 pm

According to the SANS Internet Storm Center, there have been reports of continuing attacks related to Microsoft server software and Domain Name System (DNS) cache systems, resulting in users being routed to sites run by attackers.

Also called “cache poisoning,” the attacks differ from more common phishing or pharming attacks because they do not rely on spyware installation or users clicking on bogus links.

Instead, attackers put false information into the DNS caches of servers that have been compromised. The servers then route users away from legitimate sites.

However, these attacks also can lead to traditional phishing methods, putting Internet users at risk for a kind of one-two identity-theft punch.

At least three attacks using DNS cache poisoning have been reported since early March, according to the Internet Storm Center.

Two attacks drove users to adware installation sites, and the other routed users to a site purporting to sell herbal supplements.

Approximately 500 to 1,000 companies have been affected by these attacks, the Center estimates.

Source: News Factor Network (via Yahoo)

 

2 Responses to “DNS Cache Poisoning Hacks on the Rise”

  1. Simon Says:

    The SANS Stormcenter is now reporting that all is essential back to normal, other than Comcast, which is apparent still experiencing sporadic, nationwide outages: these outages are unrelated to the cache poisoning however, according to Comcast.

  2. John Says:

    I was having problem with comcast yesterday, Now I know why

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress