Phishers using DNS servers to lure victims?

By Robert Lemos, CNET News.com
Wednesday, March 09, 2005 10:32 AM
Online thieves looking for personal data are moving to more active measures by manipulating DNS servers to redirect people to their malicious Web sites, security experts said this week.

The warning follows reports Friday that some people's computers were being redirected from legitimate sites, including eBay and Google, to malicious Web servers that attempted to install spyware. The compromises affected 30 to 40 networks, according to Jason Lam, incident handler for the Internet Storm Center, which tracks network threats.

"It's hard to tell how many people were impacted by this, but it wasn't very widespread," Lam said Tuesday.

The attacks compromised servers that act as the white pages of the Internet--a key part of cyberspace that's known as the domain name system, or DNS--to replace the numerical addresses of popular Web sites with the addresses of malicious sites run by the attackers. Known as DNS poisoning, the scheme redirects Internet users to bogus sites where they may be asked for sensitive information or have spyware installed on their PCs.

The Internet Storm Center, which represents a group of incident response professionals organized by the SANS Institute, a security training organization, said that a recent flaw in Symantec's firewall and gateway security appliances likely allowed some of the DNS poisoning to occur. However, other sites that do not use Symantec products also were victims, Lam said.

"We haven't really determined what caused this," he said. "We don't have enough reported cases, so it is hard to draw a conclusion from that."

Symantec did not immediately respond to a request for comment.

Using DNS poisoning to redirect customers to sites that appear to be legitimate but actually collect sensitive information is a relatively new threat. Some security companies have called this technique pharming.

Lam warned that future attacks, if more adeptly executed, could be nearly undetectable. It's possible users would believe they are going to a legitimate site and would get no indication from their browsers that the site that actually appears is not official.

"In this case, the content of the site was different," he said. "But with DNS poisoning, if they intended to use it for phishing, it would have been very bad."

Lam said that the site certificates used by financial Web sites and other sensitive services would give users some warning that something was amiss.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary Part 4: Using OpenAmplify via SOAP

Web Development

Justin James walks you through the process of using the SOAP interface to OpenAmplify from Visual Studio 2008.


Read more »



When technology costs more than human

Blog thumbnail

Movie director James Cameron waited 15 years for technology to catch up before it was sufficiently advanced for him to create the much-anticipated upcoming film, Avatar.

To be released in..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web