Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests and 3 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow New Version of DNS-Changing Malware Detected
EH-Net
May 24, 2012, 09:33:16 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: New Version of DNS-Changing Malware Detected  (Read 4700 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3916


Editor-In-Chief


View Profile WWW
« on: December 16, 2008, 09:40:45 AM »

Quote

A new twist in DNS-changing malware poisons other hosts on a local subnet, and installs a rogue DHCP server.

In a blog posting, JM Hipolito, technical communications spokesperson at Trend Micro, explained that once the malware was installed, "The system is turned into a DHCP server that monitors traffic and intercepts request packets from other computers in the network. It then replies to intercepted requests with packets containing malicious DNS servers. This causes the recipients of the malicious packets to be redirected to malicious sites without their consent."

Researchers at the SANS Internet Storm Center said that the technique does not have a 100 percent success rate.

In his blog posting, SANS Handler Bojan Zdrnja said, "While not too sophisticated, the whole attack is very interesting. First, it's about a race between the rogue DHCP server and the legitimate one. Second, once a machine has been poisoned it is impossible to detect how it actually got poisoned in the first place."

Trend Micro Advanced Threats Researcher Feike Hacquebord claimed that as the malware works, advertisements placed in websites are replaced with other advertisements that connect to the IP addresses used by cybercriminals.

Also, once a user clicks one of these targeted ads and gets connected to the cybercriminals' crafted site, any personal information they enter into the site can be leaked to this scheme's perpetrator. Hacquebord claimed that the estimated number of victims by this kind of threat have reached more than a million for November alone.


Original story:
http://www.scmagazineus.com/New-version-of-DNS-changing-malware-detected/article/122800/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
WCNA
Full Member
***
Offline Offline

Posts: 182



View Profile
« Reply #1 on: March 03, 2011, 06:16:53 PM »

I was going to send this in as a resource but the topic of rogue dhcp servers hits close to home. In addition to this type of malware, a frequent problem at university housing is students bringing in wireless routers and connecting them to the LAN incorrectly causing their new wireless router to start handing out IP addresses via dhcp. A solution we have found is by using dhcdrop. It's in the net-mgnt ports for FreeBSD. What it does is send out dhcp discover packets. If it gets a response from a server that is not legitimate then it sucks up all the address space the rogue router will hand out, rendering it harmless to other users.

Good times..... 
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
WCNA
Full Member
***
Offline Offline

Posts: 182



View Profile
« Reply #2 on: May 09, 2011, 10:23:45 PM »

I don't know that there would be much interest in Rogue DHCP servers here but I did a video for dhcdrop that can be found here in case someone else has run into the problem:
http://www.securitytube.net/video/1840
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.144 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.