Thursday, 2. October 2003

The "r0x s0x" Virus:
Anyone else having their DNS settings maliciously switched?


Hi all

Whilst trying to sort a VPN problem on my workstation today I >discovered that the DNS server addresses on both of my LAN >cards had been changed (remotely, I am assuming) to >69.57.146.14 & 69.57.147.175.

It appears you are not the only one experiencing this. A similar event was posted to Bugtraq last night and there are other eports as well. A copy of the bugtraq post appears below:

¬> Google newsgroups

... Comment