DNS Poisoning, pharming, pollution



Hi,

I'm running Windows 2003 and have 4 DNS servers setup on the network.
Every server is configured with our ISP's DNS resolvers as forwarders.
About 2 weeks ago, users trying to go to microsoft.com, google.com, and some
other sites were getting redirected to a "search" page that didn't look very
trustworthy. I ran a ping on the names and received addresses in the
67.15.35.* block. After blocking web traffic to this class C at the
firewall and reading several topics on the subject, I cleared the cache on
all 4 DNS servers, and haven't seen any signs of misdirection until today.
Today, it is azcentral.com (a local TV station website) that is being
misdirected. Two weeks ago, I assumed that the faulty records were coming
from the ISP, but now I don't think that's true. The "secure cache against
pollution" setting is on (as it is by default), but I have read that
vulnerabilities may still exist. Unfortunately, I'm not sure how to protect
my network further. I've read that certain versions of BIND have
vulnerabilities, but I don't think we're running BIND. I'm no DNS expert,
so please bear with me. It appears the attacks are coming from within, and
possibly from an infected client(?). Could someone lead me to some
information that might help me locate the source of the attacks and how to
stop them?

Thank you,
Jerry


.



Relevant Pages

  • Re: Cannot connect to the Internet
    ... Connection 2 Status icon shows "Connected" with a speed of 10.0 Mbps, ... The master browser has received a server announcement from the ... service will not use the network to avoid further network performance ... these DNS servers or contact your network administrator. ...
    (microsoft.public.mac.virtualpc)
  • Re: Cannot connect to the Internet
    ... Connection 2 Status icon shows "Connected" with a speed of 10.0 Mbps, ... The master browser has received a server announcement from the ... service will not use the network to avoid further network performance ... these DNS servers or contact your network administrator. ...
    (microsoft.public.mac.virtualpc)
  • Re: hanging behavior and event ID questions
    ... > use the network to avoid further network performance problems. ... > verify network conditions to these DNS servers or contact. ... > Thanks, Josie ... Please explain your internet connection more clearly. ...
    (microsoft.public.win2000.general)
  • Network logins take too long!
    ... Intel or Broadcomm network adapters. ... As in almost all cases of slow network logins the culprit is DNS or network ... We have 2 AD integrated DNS servers on the ... Domain Controller machines. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Do I have a virus?
    ... So do other computers on your network experience the same problem ... another Mac that I haven't used in a couple weeks, ... On the guest account, the home page ... Macs using the same DNS servers as the PCs? ...
    (comp.sys.mac.system)