|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Full-Disclosure] Mystery DNS Changes
From: Gary Flynn (flynngn
jmu.edu)
Date: Wed Oct 01 2003 - 15:04:33 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hansen, Kevin wrote:
> We have seen multiple instances where DHCP enabled workstations have had
> their DNS reconfigured to point to two of the three addresses listed below.
> Can anyone else confirm this? Incidents.org is reporting an increase in port
> 53 traffic over the last two days. Are we looking at the precursor to the
> next worm?
This is currently being discussed on NTBUGTRAQ too.
--
Gary Flynn
Security Engineer - Technical Services
James Madison University
Please R.U.N.S.A.F.E.
http://www.jmu.edu/computing/runsafe
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]