DNS poisoning to Korean address

From: Iso Mage (isoat_private)
Date: Tue May 13 2003 - 08:56:10 PDT

  • Next message: jlepichat_private: "Source 126.0.0.1 UDP/137"

    We're experiencing DNS resolution of some internal and external
    (www.boston.com) sites to 211.202.1.43, and it looks like our mail
    servers have a pile of emails destined for that address (checking into
    it now).
    
    Interestingly, boston.com seems to have removed their DNS records from
    the net. 
    
    Anyone else seeing anything similar?  
    
    Regards,
    
    Iso
    
    ----------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies 
    that are enforced to protect WLANs from known vulnerabilities and threats. 
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.
    
    To get your FREE white paper visit us at:    
    http://www.securityfocus.com/AirDefense-incidents
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue May 13 2003 - 12:11:56 PDT