TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Glenn Meadows
from: /m
date: 2006-06-26 21:38:14
subject: Re: Wareout

From: /m 


Do you have a firewall on the network?  If so, config it to allow only the
DNS connections you expect to occur.  (on my network here at home, I'd set
it to allow only my DNS caching server to access any DNS servers,
preventing the workstations from doing so.)

 /m

On Mon, 26 Jun 2006 16:23:11 -0500, "Glenn Meadows"
 wrote:

>The local DHCP server normally sets them, but this exploit changes the
>setting in TCPIP from "Automatic" to Manual, and plugs in two
dns servers
>that when I did a trackdown on them, showed up as part of Inhoster in the
>Ukraine.
>
>Then, we watched carefully, and when he clicked on a link in Google, he was
>redirected to a different address in the same subnet.  That's when we
>discovered that his DNS servers had change entries.
>
>Googled that whole browser hijack to that address, and got some threads at
>MajorGeeks that pointed me to the way to detect/remove it.
>
>I'm impressed with what they have to offer at Majorgeeks.com, but then, I'm
>easily amused...HAHAHAHAHA.

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270 5030/786
@PATH: 379/45 1 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.