Jump to content

Recommended Posts

Posted

Has anyone come across an attack whereby the DNS setting on a server NIC has been changed to 8.8.8.8? Google searches suggest a DNS cache 'poisoning' but none of the replies look right. The DNS is a static setting, but twice now it has somehow changed.

 

Anyone else had experience of this?

 

Cheers.

Posted
Yes - on my Exchange box once - didn't find out how it was done but I'd change your local password on that server pronto, as that server later had an automated attack launched against it, at which point I discovered my ISP had, for some reason, left all the ports open on that server (and only that server) on their firewall. Worth checking your firewall as well, actually.
  • Thanks 1
Posted
Yes - on my Exchange box once - didn't find out how it was done but I'd change your local password on that server pronto, as that server later had an automated attack launched against it, at which point I discovered my ISP had, for some reason, left all the ports open on that server (and only that server) on their firewall. Worth checking your firewall as well, actually.

 

Actually it's our Exchange box, too - coincidence?

 

I may contact our ISP as well, just in case.

 

Cheers

Posted (edited)
Whois 8.8.8.8

 

 

Hint: It's google.

 

 

Or more specifically, their public DNS server. Is the secondary DNS 8.8.4.4?

 

 

Also, one possibility.

 

Thanks, yes I knew from a search that these were the Google dns settings. I also saw that link, but thanks.

Edited by Gibson335
Posted (edited)
Actually it's our Exchange box, too - coincidence?

 

I may contact our ISP as well, just in case.

 

Cheers

 

Probably not coincidence - the automated attack when it came (few months later) had every appearance of a botnet, as the source IP kept jumping around and it was continually attempting to log in with certain account names (e.g. Tony, Dave, admin, reception etc. - just trying it's luck, basically). If it's a botnet attacking, it's likely trying to infect email servers to serve spam on its behalf.

 

Check your passwords are up to scratch and make sure there's no other changes been made - check your roles and features in particular, especially for any Remote Access stuff.

Edited by sonofsanta
why does my brain struggle with coincidence/coincedence so much? :doh:
  • Thanks 1
Posted
Probably not coincidence - the automated attack when it came (few months later) had every appearance of a botnet, as the source IP kept jumping around and it was continually attempting to log in with certain account names (e.g. Tony, Dave, admin, reception etc. - just trying it's luck, basically). If it's a botnet attacking, it's likely trying to infect email servers to serve spam on its behalf.

 

Check your passwords are up to scratch and make sure there's no other changes been made - check your roles and features in particular, especially for any Remote Access stuff.

 

Thanks - did you change password only for local admins, not domain admins?

Posted
Thanks - did you change password only for local admins, not domain admins?

 

Domain admin changes regularly anyway, but changed all the local admin passwords to long strings of garbage from KeePass. Probably safest to change both; changing passwords is quick and easy, and trawling through server logs to make sure nothing went wrong is long and boring. Prevention is better than cure etc.

Posted
Domain admin changes regularly anyway, but changed all the local admin passwords to long strings of garbage from KeePass. Probably safest to change both; changing passwords is quick and easy, and trawling through server logs to make sure nothing went wrong is long and boring. Prevention is better than cure etc.

 

Thanks again - one last thing, was your Exchange box v 2003 or higher?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...