|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
Re: [Dshield] QHOSTS-1 - DNS/Hosts file issues |  |
- To: General DShield Discussion List <[EMAIL PROTECTED]>
- Subject: Re: [Dshield] QHOSTS-1 - DNS/Hosts file issues
- From: Alan Frayer <[EMAIL PROTECTED]>
- Date: 02 Oct 2003 11:32:43 -0400
- In-reply-to: <[EMAIL PROTECTED]>
- Old-x-envelope-to: [EMAIL PROTECTED]
- References: <[EMAIL PROTECTED]>
- Reply-to: General DShield Discussion List <[EMAIL PROTECTED]>
- Sender: [EMAIL PROTECTED]
 |
| |
In attempting to understand this situation, I need to ask a question:
On Thu, 2003-10-02 at 10:35, wbeckham wrote:
> I got the following from Trusecure this morning.
>
> - WB
>
> ---------------------------------
> TruSecure Radar Notice
[snip]
> Summary:
> Yesterday TruSecure began to observe evidence of an active attack against
> users of Internet Explorer 6.0. The attack comprised of a banner, hosted by
> FortuneCity.com, which in turn used JavaScript to redirect the self-closing
> "pop-under" banner to a site hosted by EV1.NET (Everyone's Internet.) An
> EV1.NET site then delivered executable code which in turn invoked the HTA
> vulnerability.
Would blocking the IP address of the EV1.NET site from outbound traffic
defeat this attack? If so, this strikes me as much more time efficient
than visiting each PC and turning off scripting, etc.
________________________________________________________________________
Alan Frayer,CNE,CNI,CIW CI,MCP,Net+ - [EMAIL PROTECTED]
Seeking an IT Mgmt/Network Admin position in the Tampa Bay Region
If you would like to discuss an opportunity with me, please e-mail.
_______________________________________________
list mailing list
[EMAIL PROTECTED]
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
| |