2005/03/19 pharming

Guess they had to have new word, didn't they? Well, what they are now calling "pharming" is just DNS hacking. It's scary because it's not like phishing where you are tricked into clicking on a link that doesn't take you where you think it will. This is worse, because your DNS gives you a fake address for a legitimate site address.

There is more than one way that can happen: corruption of a real DNS server either by hacking into it or by presenting false credentials ("I'm from Citibank, and we need to update our DNS"), or by hacking a PC and screwing up its DNS. Either way it's not pretty.


Hate these ads?

Read more at http://reviews.cnet.com/4520-3513_7-5670780-1.html?tag=nl.e497 and http://isc.sans.org/diary.php?date=2005-03-13

I mentioned this to someone who responded saying that they flush their DNS cache regularly (in Windows that's "ipconfig /flushdns"; on Unix that's a much more complex subject and probably unnecessary anyway). That certainly isn't harmful, but it's not going to help against this sort of poisoning.



Comments /Words2005/2005_03_19.html


Add your comments

ad

Enter your email address for automatic notification of new posts here
(be sure to whitelist 'feedburner.com' if you use spam filtering)

Or use any RSS reader

Delivered by FeedBurner


Views for this page
Today This Week This Month This Year  Overall
118416 1,888

Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.

Publishing your articles here

pavatar.jpg
More:
       - Security




Unix/Linux Consultants

Your ad here - $24.00 yearly!

SCO, OpenServer, UnixWare, software, servers, security, networks, installation, administration, troubleshooting, maintenance, Watchguard, firewalls, VPNs, e-mail. Visit us at http://opensystemscomputing.com and www.go2unix.com.


http://www.schewanick.com SCO Unix, Solaris, Linx (various), PHP, MySQL, Apache, uniBasic, dL4, Perl, System Administration and more....


http://www.vss3.com SCO/Caldera OpenServer, Unixware & Linux. Tarantella & Non-stop Clustering









Change Congress


Related Posts