Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow New Version of DNS-Changing Malware Detected
EH-Net
May 23, 2013, 06:51:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: New Version of DNS-Changing Malware Detected  (Read 6092 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« on: December 16, 2008, 09:40:45 AM »

Quote

A new twist in DNS-changing malware poisons other hosts on a local subnet, and installs a rogue DHCP server.

In a blog posting, JM Hipolito, technical communications spokesperson at Trend Micro, explained that once the malware was installed, "The system is turned into a DHCP server that monitors traffic and intercepts request packets from other computers in the network. It then replies to intercepted requests with packets containing malicious DNS servers. This causes the recipients of the malicious packets to be redirected to malicious sites without their consent."

Researchers at the SANS Internet Storm Center said that the technique does not have a 100 percent success rate.

In his blog posting, SANS Handler Bojan Zdrnja said, "While not too sophisticated, the whole attack is very interesting. First, it's about a race between the rogue DHCP server and the legitimate one. Second, once a machine has been poisoned it is impossible to detect how it actually got poisoned in the first place."

Trend Micro Advanced Threats Researcher Feike Hacquebord claimed that as the malware works, advertisements placed in websites are replaced with other advertisements that connect to the IP addresses used by cybercriminals.

Also, once a user clicks one of these targeted ads and gets connected to the cybercriminals' crafted site, any personal information they enter into the site can be leaked to this scheme's perpetrator. Hacquebord claimed that the estimated number of victims by this kind of threat have reached more than a million for November alone.


Original story:
http://www.scmagazineus.com/New-version-of-DNS-changing-malware-detected/article/122800/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
WCNA
Full Member
***
Offline Offline

Posts: 187



View Profile
« Reply #1 on: March 03, 2011, 06:16:53 PM »

I was going to send this in as a resource but the topic of rogue dhcp servers hits close to home. In addition to this type of malware, a frequent problem at university housing is students bringing in wireless routers and connecting them to the LAN incorrectly causing their new wireless router to start handing out IP addresses via dhcp. A solution we have found is by using dhcdrop. It's in the net-mgnt ports for FreeBSD. What it does is send out dhcp discover packets. If it gets a response from a server that is not legitimate then it sucks up all the address space the rogue router will hand out, rendering it harmless to other users.

Good times..... 
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
WCNA
Full Member
***
Offline Offline

Posts: 187



View Profile
« Reply #2 on: May 09, 2011, 10:23:45 PM »

I don't know that there would be much interest in Rogue DHCP servers here but I did a video for dhcdrop that can be found here in case someone else has run into the problem:
http://www.securitytube.net/video/1840
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.