[Full-disclosure] MS DNS worm
Zed Qyves
zqyves.spamtrap at gmail.com
Wed Apr 18 14:58:58 BST 2007
Hello Geo,
According to Symantec Blog "W32.Rinbot.BC" was the first worm to
incorporate the DNS exploit in its spreading methods.
Furthermore "W32.Rinbot.BC opens a back door that connects to the
x.rofflewaffles.us domain and awaits for commands from the attacker."
Is this something your customer is experiencing?
Z.
--
---------------------------------------------------------------------
Κρέων
ἐν τῇδ᾽ ἔφασκε γῇ· τὸ δὲ ζητούμενον
ἁλωτόν, ἐκφεύγειν δὲ τἀμελούμενον.
Οιδίπους Τύρρανος [110]
---------------------------------------------------------------------
Creon
In this our land, so said he, those who seek Shall find; unsought, we
lose it utterly.
Oedipus Rex [110]
---------------------------------------------------------------------
Full-Disclosure is hosted and sponsored by Secunia.