New Trojan In Mass Dns Hijack


Recommended Posts

New trojan in mass DNS hijack

Single box pollutes entire LAN

By Dan Goodin in San Francisco

"Researchers have identified a new trojan that can tamper with a wide array of devices on a local network, an exploit that sends them to impostor websites even if they are hardened machines that are fully patched or run non-Windows operating systems.

The malware is a new variant of the DNSChanger, a trojan that has long been known to change the domain name system settings of PCs and Macs alike. According to researchers with anti-virus provider McAfee's Avert Labs, the update allows a single infected machine to pollute the DNS settings of potentially hundreds of other devices running on the same local area network by undermining its dynamic host configuration protocol, or DHCP, which dynamically allocates IP addresses.

"Systems that are not infected with the malware can still have the payload of communicating with the rogue DNS servers delivered to them," McAfee's Craig Schmugar writes here of the new variant. "This is achieved without exploiting any security vulnerability."

The scenario plays out something like this:

Jill connects a PC infected by the new DNSChanger variant to a coffee shop's WiFi hotspot or her employer's local network.

Steve connects to the same network using a fully-patched Linux box, which requests an IP address.

Jill's PC injects a DHCP offer command to instruct Steve's computer to rout all DNS requests through a booby-trapped DNS server.

Steve's Linux box can no longer be trusted to visit authoritative websites. Although the address bar on his browser may show he is accessing bankofamerica.com, he may in fact be at an impostor website."

Full story here: http://www.theregister.co.uk/2008/12/05/ne...hanger_hijacks/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...