lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <63C5D58429F6D41196040006298F207C02B85963@eg-msgmbx-b05.int.westgroup.com> From: kevin.hansen at thomson.com (Hansen, Kevin) Subject: Mystery DNS Changes We have seen multiple instances where DHCP enabled workstations have had their DNS reconfigured to point to two of the three addresses listed below. Can anyone else confirm this? Incidents.org is reporting an increase in port 53 traffic over the last two days. Are we looking at the precursor to the next worm? 216.127.92.38 69.57.146.14 69.57.147.175 -KJH ++++++++++++++++++++++++++ Kevin J. Hansen Architect Global Network Thomson Legal & Regulatory kevin.hansen@...mson.com 651-687-8466 ++++++++++++++++++++++++++ -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20031001/fccfcd69/attachment.html