DNS Address changed to 69.57.146.14 by devious means...

B

Bernie

This could be a "Man-in-the-middle" attack.
I scanned the 14 for open ports - and strange enough for a
DNS server - there are all common ports open - even SSH.
From the scan results I'm almost sure, that's a Linux box.
The DNS will resolve all DNS requests comming from your IP
with the IP of the man-in-the-middle, who will forward
your traffic to the correct sever, but also keep a copy
for himself. So it stays completely transparent to you.
Are you sure, you didn't install or exec any fishy apps?
What about the cleaning pers? Importing an adm.template to
your GPOs could do the trick as well.
WHAT DO YOU HAVE TO HIDE?
Try to run a "tracert" to a URL of your habits or
mailserver and see if it hits a 69... on the way.

Happy paranoia

Bernie
 
M

Mark

No fishy apps...

BUT (A very BIGGGG BUTT)

Yesterday I was researching the effectiveness of "Spyware Cleaning" software
....

I evaluated...

xpantispy
Lavasoft Ad-aware 6.0
SPYBLOCK.EXE
Spybot - Search & Destroy 1.2

I think this is the complete list

I can't help but think that one of these may be at the root of this

Has anyone else used these apps?

Mark
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top