Gibson335 Posted May 1, 2012 Posted May 1, 2012 Has anyone come across an attack whereby the DNS setting on a server NIC has been changed to 8.8.8.8? Google searches suggest a DNS cache 'poisoning' but none of the replies look right. The DNS is a static setting, but twice now it has somehow changed. Anyone else had experience of this? Cheers.
sonofsanta Posted May 1, 2012 Posted May 1, 2012 Yes - on my Exchange box once - didn't find out how it was done but I'd change your local password on that server pronto, as that server later had an automated attack launched against it, at which point I discovered my ISP had, for some reason, left all the ports open on that server (and only that server) on their firewall. Worth checking your firewall as well, actually. 1
Gibson335 Posted May 1, 2012 Author Posted May 1, 2012 Yes - on my Exchange box once - didn't find out how it was done but I'd change your local password on that server pronto, as that server later had an automated attack launched against it, at which point I discovered my ISP had, for some reason, left all the ports open on that server (and only that server) on their firewall. Worth checking your firewall as well, actually. Actually it's our Exchange box, too - coincidence? I may contact our ISP as well, just in case. Cheers
X-13 Posted May 1, 2012 Posted May 1, 2012 Whois 8.8.8.8 Hint: It's google. Or more specifically, their public DNS server. Is the secondary DNS 8.8.4.4? Also, one possibility.
Gibson335 Posted May 1, 2012 Author Posted May 1, 2012 (edited) Whois 8.8.8.8 Hint: It's google. Or more specifically, their public DNS server. Is the secondary DNS 8.8.4.4? Also, one possibility. Thanks, yes I knew from a search that these were the Google dns settings. I also saw that link, but thanks. Edited May 1, 2012 by Gibson335
sonofsanta Posted May 1, 2012 Posted May 1, 2012 (edited) Actually it's our Exchange box, too - coincidence? I may contact our ISP as well, just in case. Cheers Probably not coincidence - the automated attack when it came (few months later) had every appearance of a botnet, as the source IP kept jumping around and it was continually attempting to log in with certain account names (e.g. Tony, Dave, admin, reception etc. - just trying it's luck, basically). If it's a botnet attacking, it's likely trying to infect email servers to serve spam on its behalf. Check your passwords are up to scratch and make sure there's no other changes been made - check your roles and features in particular, especially for any Remote Access stuff. Edited May 1, 2012 by sonofsanta why does my brain struggle with coincidence/coincedence so much? :doh: 1
Gibson335 Posted May 1, 2012 Author Posted May 1, 2012 Probably not coincidence - the automated attack when it came (few months later) had every appearance of a botnet, as the source IP kept jumping around and it was continually attempting to log in with certain account names (e.g. Tony, Dave, admin, reception etc. - just trying it's luck, basically). If it's a botnet attacking, it's likely trying to infect email servers to serve spam on its behalf. Check your passwords are up to scratch and make sure there's no other changes been made - check your roles and features in particular, especially for any Remote Access stuff. Thanks - did you change password only for local admins, not domain admins?
sonofsanta Posted May 1, 2012 Posted May 1, 2012 Thanks - did you change password only for local admins, not domain admins? Domain admin changes regularly anyway, but changed all the local admin passwords to long strings of garbage from KeePass. Probably safest to change both; changing passwords is quick and easy, and trawling through server logs to make sure nothing went wrong is long and boring. Prevention is better than cure etc.
Gibson335 Posted May 1, 2012 Author Posted May 1, 2012 Domain admin changes regularly anyway, but changed all the local admin passwords to long strings of garbage from KeePass. Probably safest to change both; changing passwords is quick and easy, and trawling through server logs to make sure nothing went wrong is long and boring. Prevention is better than cure etc. Thanks again - one last thing, was your Exchange box v 2003 or higher?
sonofsanta Posted May 1, 2012 Posted May 1, 2012 Thanks again - one last thing, was your Exchange box v 2003 or higher? Exchange 2007 running on Server 2003 R2 SP2 x64
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now