RE: RE Question

"Schmehl, Paul L" <[email protected]> Mon, 2 May 2005 10:38:56 -0500
Newsgroups gmane.comp.security.intrusions
Message-ID <ADA47EFE15ACA74E8B702B6EF90D913902C2FFB9@UTDEVS08.campus.ad.utdallas.edu>
> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Joel Esler
> Sent: Saturday, April 30, 2005 8:31 AM
> To: Intrusions List (GCIA Practicals)
> Subject: Re: [Intrusions] RE Question
> 
> I'd hate to be hasty about it, as I am still laying in bed 
> this morning... *yawn*
> 
> My thoughts are..  DNS poisoning, 

Precisely my thoughts as well.  Looking at the packets, it looks
suspiciously familiar to other DNS poisoning instances that I have seen.

The question is, whose DNS is being poisoned?

Mike, are you running a MS DNS server internal to your network?  Does
your ISP run an MS DNS server?

Paul Schmehl ([email protected])
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/ 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions