Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: [Dshield] QHOSTS-1 - DNS/Hosts file issues
.

  • To: General DShield Discussion List <[EMAIL PROTECTED]>
  • Subject: Re: [Dshield] QHOSTS-1 - DNS/Hosts file issues
  • From: Alan Frayer <[EMAIL PROTECTED]>
  • Date: 02 Oct 2003 11:32:43 -0400
  • In-reply-to: <[EMAIL PROTECTED]>
  • Old-x-envelope-to: [EMAIL PROTECTED]
  • References: <[EMAIL PROTECTED]>
  • Reply-to: General DShield Discussion List <[EMAIL PROTECTED]>
  • Sender: [EMAIL PROTECTED]
.
 
In attempting to understand this situation, I need to ask a question:

On Thu, 2003-10-02 at 10:35, wbeckham wrote:
> I got the following from Trusecure this morning.  
> 
> - WB
> 
> ---------------------------------
> TruSecure Radar Notice

[snip]

> Summary:
> Yesterday TruSecure began to observe evidence of an active attack against
> users of Internet Explorer 6.0. The attack comprised of a banner, hosted by
> FortuneCity.com, which in turn used JavaScript to redirect the self-closing
> "pop-under" banner to a site hosted by EV1.NET (Everyone's Internet.) An
> EV1.NET site then delivered executable code which in turn invoked the HTA
> vulnerability.  

Would blocking the IP address of the EV1.NET site from outbound traffic
defeat this attack? If so, this strikes me as much more time efficient
than visiting each PC and turning off scripting, etc.

________________________________________________________________________
Alan Frayer,CNE,CNI,CIW CI,MCP,Net+ - [EMAIL PROTECTED]
Seeking an IT Mgmt/Network Admin position in the Tampa Bay Region
If you would like to discuss an opportunity with me, please e-mail.


_______________________________________________
list mailing list
[EMAIL PROTECTED]
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.