CPE dns hijacking malware

2013-11-11 Thread Mike
Hi, It appears that some of my subscribers DSL modems (which are acting as nat routers) have had their dns settings hijacked and presumably for serving ads or some such nonsense. The dns server addresses are statically programmed in and of the onces I have seen, they are not currently respons

Re: CPE dns hijacking malware

2013-11-11 Thread Dobbins, Roland
On Nov 12, 2013, at 12:56 PM, Mike wrote: > It appears that some of my subscribers DSL modems (which are acting as nat > routers) have had their dns settings hijacked and presumably for serving ads > or some such nonsense. How do you think this was accomplished? Via some kind of Web exploit

Re: CPE dns hijacking malware

2013-11-11 Thread Jeff Kell
On 11/12/2013 1:12 AM, Dobbins, Roland wrote: > On Nov 12, 2013, at 12:56 PM, Mike wrote: > >> It appears that some of my subscribers DSL modems (which are acting as nat >> routers) have had their dns settings hijacked and presumably for serving ads >> or some such nonsense. > How do you think

Re: CPE dns hijacking malware

2013-11-11 Thread Dobbins, Roland
On Nov 12, 2013, at 1:17 PM, Jeff Kell wrote: > (2) DHCP hijacking daemon installed on the client, supplying the hijacker's > DNS servers on a DHCP renewal. Have seen both, the latter being more > common, and the latter will expand across the entire home subnet in time > (based on your lease