Home page logo

bugtraq logo Bugtraq mailing list archives

Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
From: "Jamie Riden" <jamesr () europe com>
Date: Sun, 16 Apr 2006 14:32:29 +1200

On 14/04/06, Brandon S. Allbery KF8NH <allbery () ece cmu edu> wrote:

On Apr 13, 2006, at 1:29 , Dave Korn wrote:

  Hey, guess what I just found out:  Microsoft have deliberately
their DNS client's hosts table lookup functionality.

I thought this was part of avoiding malware attempts to block Windows

In that case, they should allow us to add symantec et al - it's not
much use having Windows Update working while the machine is happily
rootkitted. Grepping hosts files across campus for ...
liveupdate.symantec.com  - or your local equivalent - can prove

If it was a feature, I'd expect there to be ways to add to the list of
pass-through domains, or ways to disable it.

Jamie Riden / jamesr () europe com / jamie.riden () computer org
"Microsoft: Bringing the world to your desktop - and your desktop to
 the world." -- Peter Gutmann

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]