[Dshield] RE: FriendGreetings Worm is back
russ.washington at vaultsentry.com
Thu Oct 31 18:11:15 GMT 2002
Or even better, now that I think about it... DNS spoof the domain names of
the nameservers. :)
From: Russell Washington
Sent: Thursday, October 31, 2002 10:06 AM
To: 'list at dshield.org'
Subject: RE: [Dshield] RE: FriendGreetings Worm is back
It sounds like they're moving the www sites around to avoid folks doing
exactly what we're trying to do. With that in mind I'd say the best
blackholing strategy might just be to spoof authoritative DNS on your own
DNS server so that the thing just plain won't resolve.
At least that way they (the folks at Permissioned Media) have to come up
with new domain names and tweak the message content that is being sent out
so that it uses different domain names, rather than simply reorganizing IP
addresses behind the scenes.
From: James C Slora Jr [mailto:Jim.Slora at phra.com]
Sent: Thursday, October 31, 2002 9:28 AM
To: list at dshield.org
Subject: [Dshield] RE: FriendGreetings Worm is back
Friendgreetings sites best as I can tell last time I checked were: Web
sites: *.friendgreetings.com Web sites: *.cool-downloads.com Web sites:
*.cool-downloads.net IP addresses: 22.214.171.124-126.96.36.199
(cool-downloads.* class C - www, dns, etc) IP addresses:
188.8.131.52-184.108.40.206 (friendgreetings.com class C) IP addresses:
220.127.116.11-18.104.22.168 (HostPanama nameservers and
Plus subject blocking, content filtering, etc.
These are just band-aid measures. The download site could change daily, and
the message subject and text could just as easily be changed. The success of
this perfectly legal social engineering worm will certainly not go unnoticed
by other unscrupulous sites.
Richard Roy wrote Thu, 31 Oct 2002 07:35:31 -0700
> does anyone have the ip(s) to block? I would also like to reconfig my
> dns to remap it to say... www.gettowork.com so when my users go there
> they get the message! ;-)
Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:
More information about the list