Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
80655 posts

Uber Geek
+1 received by user: 41052

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#105328 2-Jul-2012 17:08
Send private message

I hear many ISP customers around New Zealand will be affected when the FBI switch off temporary DNS being currently provided to support users affected by the DNSChanger malware.

It is expected these servers will be switched off around the 9th July 2012.

DNSChanger affects both Windows and Mac OS computers.

Visit the DNSChanger Diagnostic page now to see if your computer is affected. If it is make sure you run a good antivirus/antispyware, clean up any of the infections acquired while visiting those dodgy websites, religious websites and hijacked Facebook accounts and switch the DNS configuration to the one provided by your ISP.

Also prepare for the "my computer can't connect to the Internet LOL" posts...




Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Create new topic

This is a filtered page: currently showing replies marked as answers. Click here to see full discussion.

Oubadah
676 posts

Ultimate Geek
+1 received by user: 12


  #653256 10-Jul-2012 00:28
Send private message

raytaylor: 

If your computer is programmed to use dns server x.x.x.x then it will ask that server to convert domain queries such as www.google.com into ip addresses so it knows where to go and pull the webpage for www.google.com

If your computer cannot access the dns server at x.x.x.x, then when you key in www.google.com into your web browser, it wont be able to find out what google's ip address is and you wont be able to open the web page.

It effectivley means that the internet will stop working for these people.

The correct DNS server to use is the one inside your modem which relays your dns query onto your own internet providers servers.

The malware changed the infected user's computers to their own dns malicious servers. So if an infected user tried to lookup www.google.com, they could reply with any ip address they liked - such as sites that will take you to advertising or wherever they liked. One way i commonly see this is that they will design a fake google website that places an advertising banner at the top of the page, but pulls the rest of the page from google's real servers - they then make money on that advertising.

When the FBI shut them down, the FBI installed some real DNS servers in place of the fake ones. This was to stop a partial shutdown of internet access to thousands/millions of people while their internet providers were able to contact the infected users and correct their settings.

Taylor Communications has had dns traffic to the FBI servers redirected to our own fake dns server for a number of weeks now. It would direct any google query to our own web server and showed the users a web page that they were infected and were to call us so we could remotley run a malware scan and correct their settings.
Only two customers were infected so the issue was small for us - but the big guys will be getting alot of phone calls tomorrow from those that didnt know they were infected.


Cheers.

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.