Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » DNS Hacks: 'Phishing 2.0' » Old news
Search Topic:
Uniqs:
103
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
really? »
« This isn't just old. This is over 10 years old.  
AuthorAll Replies

raye
Premium
join:2000-08-14
Orange, CA
Old news

Talked about by Dan Kaminsky at Toorcon conference Sand Diego this past October. Think it was also mentioend at BlackHat/Defcon in Vegas last August.

lordofwhee

join:2007-10-21
Everett, WA

This is even older than that.

This kind of attack has been around for at least a year before the last Defcon, probably longer.

It's already a well-established attack among the old-time favorites such as SQL injection, at least in the various groups I know/am a part of.


swhx7
Premium
join:2006-07-23
Elbonia
·RoadRunner Cable

reply to raye
Can you explain more about it? The article is vague. Is it a hack on the DNS servers, or ActiveX or other executable changing the client's DNS to one the attacker controls, or a combination of the two, or something else? And how is it a new type of attack rather than the already-known DNS exploits?

Posters at the Ars Technica thread discussed the possibilities today.


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

said by swhx7 See Profile :

And how is it a new type of attack rather than the already-known DNS exploits?
I don't think it is really all that new. But the scale of the attack with 68,000 DNS servers that are compromised. And the combo of compromised DNS servers and the hack attacks on PC's to point to those servers.

BosstonesOwn

join:2002-12-15
Everett, MA
clubs:
reply to raye
I have preached about it for more then a couple years. This isn't new , I have seen a couple examples of this before.
--
"It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"

raye
Premium
join:2000-08-14
Orange, CA

reply to swhx7
As someone mentioned it goes back further than the presentations I mentioned.

I recommend going to the BlackHat site and downloading the relevant paper/presentations.

»www.blackhat.com/html/bh-media-a···007.html

Dan Kaminsky's paper.

I have the video from Dan's more extended talk at Toorcon which shows how to exploit step-by-step. You might be able to order it as I did. The link for the paper is at »www.blackhat.com/html/bh-media-a···007.html
Forums » DNS Hacks: 'Phishing 2.0'really? »
« This isn't just old. This is over 10 years old.  


Thursday, 26-Nov 18:37:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [107] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [69] TiVo Sees Record Customer Losses
· [61] In-Flight Internet Headed For Bumpy Landing?
· [43] Thanksgiving Open Thread
· [37] ICANN Slams DNS Redirection
· [34] Senators Want ACTA Made Public
· [34] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· So we need a legitimate reason to use a lot of bandwidth? [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· SSD [Computer Hardware Discussion/Reviews]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· Slow speeds in the evenings [TekSavvy]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]