Re: DNS Poisoning, pharming, pollution



I had investigated this before, but I need to reread it again to see if I
can gather anything else from it. My recollection was that since I'm
running Windows 2003 and have the "secure cache against pollution" setting
on, the next thing to look for would be a malicious program on the server.
I haven't done that yet because other priorities have superceded this for
right now, and since I cleared the cache last, the incorrect DNS entries
haven't reappeared, yet. Once I'm able to get back on this, I'll post any
findings or questions.

Thanks for your help,
Jerry

"Ace Fekay [MVP]"
<PleaseSubstituteMyActualFirstName&LastNameHere@xxxxxxxxxxx> wrote in
message news:OcHlCOHeFHA.3492@xxxxxxxxxxxxxxxxxxxxxxx
> In news:O4ABI$rdFHA.620@xxxxxxxxxxxxxxxxxxxx,
> Jerry <jerry.giacinto@xxxxxxxxxxxxxxxxxxxxxx> stated, and I replied below:
> > Hi,
> >
> > I'm running Windows 2003 and have 4 DNS servers setup on the network.
> > Every server is configured with our ISP's DNS resolvers as forwarders.
> > About 2 weeks ago, users trying to go to microsoft.com, google.com,
> > and some other sites were getting redirected to a "search" page that
> > didn't look very trustworthy. I ran a ping on the names and received
> > addresses in the
> > 67.15.35.* block. After blocking web traffic to this class C at the
> > firewall and reading several topics on the subject, I cleared the
> > cache on all 4 DNS servers, and haven't seen any signs of
> > misdirection until today. Today, it is azcentral.com (a local TV
> > station website) that is being misdirected. Two weeks ago, I assumed
> > that the faulty records were coming from the ISP, but now I don't
> > think that's true. The "secure cache against pollution" setting is
> > on (as it is by default), but I have read that vulnerabilities may
> > still exist. Unfortunately, I'm not sure how to protect my network
> > further. I've read that certain versions of BIND have
> > vulnerabilities, but I don't think we're running BIND. I'm no DNS
> > expert, so please bear with me. It appears the attacks are coming
> > from within, and possibly from an infected client(?). Could someone
> > lead me to some information that might help me locate the source of
> > the attacks and how to stop them?
> >
> > Thank you,
> > Jerry
>
> See if this helps. It seems to be a prevalent issue lately, although I'vbe
> heard it seems to have subsided. You may not be using BIND, but the
> forwarders may well be BIND.
>
> SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert
> System - Current Infosec News and Analysis:
> http://isc.sans.org/presentations/dnspoisoning.php
>
>
>
> --
> Regards,
> Ace
>
> Please direct all replies ONLY to the Microsoft public newsgroups
> so all can benefit.
>
> This posting is provided "AS-IS" with no warranties or guarantees
> and confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
> Microsoft Windows MVP - Windows Server - Directory Services
> Infinite Diversities in Infinite Combinations.
> =================================
>


.



Relevant Pages

  • [NEWS] BIND 9 DNS Cache Poisoning
    ... BIND 9 DNS Cache Poisoning ... source UDP port and DNS transaction ID can be effectively predicted. ... address of the target name server), and the destination UDP port (53 the ...
    (Securiteam)
  • Re: [WARNING] The DNS Resolver Cache service is not running.
    ... It prevents anyone (at least on the server) from ... receiving, DNS Resolver Cache no running, so sorry. ... DHCP Client Service ...
    (microsoft.public.win2000.dns)
  • Re: DNS Access Denied
    ... For your information ILSAS1 is Master role. ... You cannot expect AD replication to work unless DNS works; ... have an IP or DNS (server or client) problem. ... ILSAS1 is the Schema Owner, but is not responding to DS RPC Bind. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Access Denied
    ... I believed that the replications are not happening from this both ... ILSAS1 is the Schema Owner, but is not responding to DS RPC Bind. ... > problems have their origin in DNS issues. ... you mean the MMC cannot add the other DNS server. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS auto entry nightmare
    ... >dedicated dns server and the "other app server with AD installed) or using a ... >single server with bind for windows installed to handle split horizon tagging. ... >I successfully tried to set-up multiple dns servers on the single server ...
    (microsoft.public.windows.server.dns)