Results 1 to 8 of 8

Thread: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

  1. #1
    David H. Lipman Guest

    ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    A variant of the ZLob Trojan known as DNSChanger has been known to modify the DNS servers on
    your PC. Thus you get directed to malicious web sites instead of the web site you are
    trying to get to.

    Now there is a variant of the DNSChanger, installer ~300KB, that can use TCP port 80 and a
    dictionary of passwords to modify the DNS Server list on SOHO Routers.

    http://www.trustedsource.org/blog/42...s-into-routers
    http://blog.washingtonpost.com/secur..._wirele_1.html

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



  2. #2
    Andrew McGovern Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    I always update my anti-virus software regularly so I should be OK.

    Thanks for the news anyway.

    --
    PC Slowing Down? Hardware Problems?
    http://andrewmcgovernonline.com/pcrepair/


    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:uiB4k.19$TL6.16@trnddc01...
    >A variant of the ZLob Trojan known as DNSChanger has been known to modify
    >the DNS servers on
    > your PC. Thus you get directed to malicious web sites instead of the web
    > site you are
    > trying to get to.
    >
    > Now there is a variant of the DNSChanger, installer ~300KB, that can use
    > TCP port 80 and a
    > dictionary of passwords to modify the DNS Server list on SOHO Routers.
    >
    > http://www.trustedsource.org/blog/42...s-into-routers
    > http://blog.washingtonpost.com/secur..._wirele_1.html
    >
    > --
    > Dave
    > http://www.claymania.com/removal-trojan-adware.html
    > Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
    >
    >




  3. #3
    Kerry Brown Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    There are other exploits that do this as well. The best protection against
    this is to use a strong password on your router.

    --
    Kerry Brown



    "Andrew McGovern" <a.mcgovern@blueyonder.co.uk> wrote in message
    news:5lB4k.78830$cL6.22385@newsfe27.ams2...
    >I always update my anti-virus software regularly so I should be OK.
    >
    > Thanks for the news anyway.
    >
    > --
    > PC Slowing Down? Hardware Problems?
    > http://andrewmcgovernonline.com/pcrepair/
    >
    >
    > "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    > news:uiB4k.19$TL6.16@trnddc01...
    >>A variant of the ZLob Trojan known as DNSChanger has been known to modify
    >>the DNS servers on
    >> your PC. Thus you get directed to malicious web sites instead of the web
    >> site you are
    >> trying to get to.
    >>
    >> Now there is a variant of the DNSChanger, installer ~300KB, that can use
    >> TCP port 80 and a
    >> dictionary of passwords to modify the DNS Server list on SOHO Routers.
    >>
    >> http://www.trustedsource.org/blog/42...s-into-routers
    >> http://blog.washingtonpost.com/secur..._wirele_1.html
    >>
    >> --
    >> Dave
    >> http://www.claymania.com/removal-trojan-adware.html
    >> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
    >>
    >>

    >
    >



  4. #4
    David H. Lipman Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    From: "Kerry Brown" <kerry@kdbNOSPAMsys-tems.c*a*m>

    | There are other exploits that do this as well. The best protection against
    | this is to use a strong password on your router.
    |

    Yes. There have been discussions about SOAP in conjunction with uPnP. However using uPnP
    you may be able to bypass the TCP port 80 authentication.

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



  5. #5
    Kerry Brown Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:x3E4k.13213$8q2.5746@trnddc02...
    > From: "Kerry Brown" <kerry@kdbNOSPAMsys-tems.c*a*m>
    >
    > | There are other exploits that do this as well. The best protection
    > against
    > | this is to use a strong password on your router.
    > |
    >
    > Yes. There have been discussions about SOAP in conjunction with uPnP.
    > However using uPnP
    > you may be able to bypass the TCP port 80 authentication.
    >



    And turn off uPnP. I forgot about that. It's the first thing I do with
    anything I set up that may have it enabled. If you can believe this
    Microsoft wants uPnP turned on so they can automagically configure the
    router with the still in beta SBS 2008. Trustworthy computing :-)

    --
    Kerry Brown




  6. #6
    a.qarta Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHORouter

    On Jun 14, 7:06*am, "Kerry Brown" <ke...@kdbNOSPAMsys-tems.c*a*m>
    wrote:
    > "David H. Lipman" <DLipman~nosp...@Verizon.Net> wrote in messagenews:x3E4k.13213$8q2.5746@trnddc02...
    >
    > > From: "Kerry Brown" <ke...@kdbNOSPAMsys-tems.c*a*m>

    >
    > > | There are other exploits that do this as well. The best protection
    > > against
    > > | this is to use a strong password on your router.
    > > |

    >
    > > Yes. *There have been discussions about SOAP in conjunction with uPnP..
    > > However using uPnP
    > > you may be able to bypass the TCP port 80 authentication.

    >
    > And turn off uPnP. I forgot about that. It's the first thing I do with
    > anything I set up that may have it enabled. If you can believe this
    > Microsoft wants uPnP turned on so they can automagically configure the
    > router with the still in beta SBS 2008. Trustworthy computing :-)
    >
    > --
    > Kerry Brown


    I've compiled a checklist to follow

    http://extremesecurity.blogspot.com/...-hijacked.html

  7. #7
    David H. Lipman Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    From: "a.qarta" <A.Qarta@gmail.com>


    |
    | I've compiled a checklist to follow
    |
    | http://extremesecurity.blogspot.com/...-hijacked.html

    Very good Aa'ed !

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



  8. #8
    Kerry Brown Guest

    Re: ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router

    "a.qarta" <A.Qarta@gmail.com> wrote in message
    news:9c65a7cb-70e7-4b2b-9306-73b1df57f2b7@l64g2000hse.googlegroups.com...
    On Jun 14, 7:06 am, "Kerry Brown" <ke...@kdbNOSPAMsys-tems.c*a*m>
    wrote:
    > "David H. Lipman" <DLipman~nosp...@Verizon.Net> wrote in
    > messagenews:x3E4k.13213$8q2.5746@trnddc02...
    >
    > > From: "Kerry Brown" <ke...@kdbNOSPAMsys-tems.c*a*m>

    >
    > > | There are other exploits that do this as well. The best protection
    > > against
    > > | this is to use a strong password on your router.
    > > |

    >
    > > Yes. There have been discussions about SOAP in conjunction with uPnP.
    > > However using uPnP
    > > you may be able to bypass the TCP port 80 authentication.

    >
    > And turn off uPnP. I forgot about that. It's the first thing I do with
    > anything I set up that may have it enabled. If you can believe this
    > Microsoft wants uPnP turned on so they can automagically configure the
    > router with the still in beta SBS 2008. Trustworthy computing :-)
    >
    >
    >I've compiled a checklist to follow
    >
    >http://extremesecurity.blogspot.com/...-hijacked.html
    >


    Looks good.

    --
    Kerry Brown




Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •