Phishers turn DNS against authorities

Botnets used to frustrate efforts to shut sites down.

Phishing scammers are cleverly abusing automated "bots" by targeting DNS servers, security experts have warned. The new technique makes it significantly harder to shut down phishing sites.

In a conventional phishing scam, users are lured to a malicious website which counterfeits the appearance of a trusted site such as a bank or e-commerce site, and convinces the user to input their account information. Such scams can only operate for a limited time before they come to light though and the malicious site is shut down, normally by the ISP that hosts the site.

But the scammers have started using botnets to get around the problem. A botnet consolidates a number of compromised computers so that they can be organised to work together. Using a botnet, a scammer can host the same malicious site at several different IP addresses, and when one is shut down, modify the DNS record for the domain to point to a different IP address. A DNS record is hosted on a DNS name server, and is used to turn an address such as www.techworld.com into a numeric IP address for a specific server, such as 111.222.333.444.

In this case, the malicious site can still be shut down by working with the ISP that hosts the name server and remove or modify the DNS records in question. The newest type of attack however, reported this week, takes the use of botnets further by using them to host name servers with several different ISPs, said security experts.

"In the most recent report, the attacker was using a botnet to host not only the malicious websites, but also the DNS servers that provided domain resolution services for the targeted domain name," wrote Lenny Zeltser, a handler with the Internet Storm Center (ISC) on Wednesday. "This setup allowed the attacker to move to a new DNS server when one of the malicious servers got shut down." The ISC is operated by the SANS Institute, which provides computer education and information security training.

Zeltser said the ISC received a report of such an attack that matched closely with a report that surfaced on the Daily Dave mailing list run by security company Immunity. In the scam reported on this mailing list, scammers used a botnet to host five different name servers on compromised computers served by different ISPs. These served five different IP addresses for the phishing site, with the addresses changing every ten to 15 minutes, according to "byte_jump", who contributed the report.

Such a scheme makes it difficult for companies to shut down a phishing site that targets their customers, according to ISC. "An organisation battling this threat typically has to deal with the registrar of the malicious domain, instead of attempting to shut down the individual DNS server," Zeltser wrote. Many domain registrars don't have formal procedures for dealing with such requests, making it difficult to get the malicious domain shut down, ISC said.

ISPs may be able to make a dent in the problem by intercepting and redirecting malicious DNS traffic on their network, so that requests for a malicious site are cut off, ISC said. This can be particularly effective if put into play by a large ISP, although it only affects traffic on the ISP's own network, according to ISC.

In March, the Honeynet Project estimated that more than one million compromised computers are controlled by botnets. They are used for a variety of purposes such as distributing spam, sniffing network traffic for unencrypted passwords and other kinds of fraud, say industry observers.



What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Antivirus programs fail to stop new malware

One in three systems infected.

Adobe sorry for 16-month-old Flash bug

Unpatched vulnerability 'slipped through the cracks'

HTML 5 leaves client storage open to web attacks

Security researcher says web apps could be vulnerable

Rugged Manifesto calls on developers for secure code

Security professionals call for better programming practices



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *