Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Mystery DNS Changes
From: "Hansen, Kevin" <kevin.hansen () thomson com>
Date: Wed, 1 Oct 2003 14:19:12 -0500

We have seen multiple instances where DHCP enabled workstations have had
their DNS reconfigured to point to two of the three addresses listed below.
Can anyone else confirm this? Incidents.org is reporting an increase in port
53 traffic over the last two days. Are we looking at the precursor to the
next worm?

216.127.92.38
69.57.146.14
69.57.147.175

-KJH


++++++++++++++++++++++++++
Kevin J. Hansen
Architect
Global Network
Thomson Legal & Regulatory
kevin.hansen () thomson com
651-687-8466
++++++++++++++++++++++++++



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]