Hosting generously provided by
www.mv.com





Pick Your Language


Hackers using rogue DNS servers to pwn you like a noob
Posted 2/15/08 by Robert from the DNS4lyfe department

"Mendacious machines controlled by hackers that reroute Internet traffic from infected computers to fraudulent Web sites are increasingly being used to launch attacks, according to a paper published this week by researchers with the Georgia Institute of Technology and Google Inc.

The paper estimates roughly 68,000 servers on the Internet are returning malicious Domain Name System results, which means people with compromised computers are sometimes being directed to the wrong Web sites — and often have no idea.

The peer-reviewed paper, which offers one of the broadest measurements yet of the number of rogue DNS servers, was presented at the Internet Society's Network and Distributed System Security Symposium in San Diego.

The fraud works like this: When a user with an affected computer tries to go to, for example, Google's Web site, they are redirected to a spoof site loaded with malicious code or to a wall of ads whose profits flow back to the hackers.

The hackers who hijack DNS queries are looking to steal personal information, from e-mail login credentials to credit data, and take over infected machines.

The spoof sites run the gamut. Some are stunningly convincing, others amusingly bogus with spelling errors and typos."

Article Link: http://www.sfgate.com/cgi-bin/article.cgi?f=/n/a/2008/02/13/financial/f160437S91.DTL&feed=rss.business
Link to this Story: Hackers using rogue DNS servers to pwn you like a noob
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals . buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse
  • [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • RE: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • Re: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • Re: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body