Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen
  1. #1
    lists@NGSEC
    [NGSEC] AntiPharming v1.00 FREE
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    [NGSEC] AntiPharming v1.00 FREE


    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Hello,

    NGSEC is proud to announce the new release of our new product
    AntiPharming v1.00 [1] TOTALLY FREE for non-commercial use.

    What is Pharming?

    "(...)Pharming is the exploitation of a vulnerability in the DNS
    server software that allows a hacker to acquire the Domain Name
    for a site, and to redirect traffic to that web site to another
    web site. DNS servers are the machines responsible for resolving
    internet names into their real addresses - the "signposts" of the
    internet.

    If the web site receiving the traffic is a fake web site, such
    as a copy of a bank's website, it can be used to "phish" or steal
    a computer user's passwords, PIN number or account number.

    AntiPharming Configuration For example, in January, 2005, the Domain
    Name for a large New York ISP, Panix, was hijacked to a site in
    Australia. In 2004 a German teenager hijacked the eBay.de Domain Name.
    Secure e-mail provider Hushmail was also caught by this attack on
    24th of April 2005 when the attacker rang up the domain registrar
    and gained enough information to redirect users to a defaced
    webpage(...)" (Source WikiPedia).

    What is AntiPharming?

    AntiPharming uses active and passive protections for identifying and
    stopping Pharming (Phising variant) attacks.

    AntiPharming will actively protect your windows server from pharming
    attacks by:

    * Denying any user (even Administrator) to write to the hosts file.
    * Denying any user (even Administrator) to change your DNS settings.

    AntiPharming will passively protect your windows server from pharming
    attacks by sniffing on each netowrk interface for DNS replies (both
    TCP and UDP) and recheck them against at least with three secure DNS
    nameservers.

    AntiPharming is TOTALLY FREE for non-commercial use.

    This e-mail has been signed with labs@NGSEC PGP key available at:

    http://www.ngsec.com/pgp/labs.asc

    [1] http://www.ngsec.com/ngproducts/antipharming/

    Best Regards,

    - ---
    NEXT GENERATION SECURITY, S.L. [NGSEC]
    C\ O'donnell 46, 3º B
    28009 - Madrid, SPAIN
    Tel: +34 91 435 56 27
    Fax: +34 91 577 84 45

    http://www.ngsec.com
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (GNU/Linux)

    iD8DBQFCrrwBKrwoKcQl8Y4RAsO5AJwIJ1Ngm38IT0JCujagcA z4oWgUUwCgl0Lv
    vWvO9R/kd5Skb/vzeER7kls=
    =XCYN
    -----END PGP SIGNATURE-----


  2. #2
    Joel Esler
    [NGSEC] AntiPharming v1.00 FREE
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [NGSEC] AntiPharming v1.00 FREE

    " * Denying any user (even Administrator) to write to the hosts file.
    * Denying any user (even Administrator) to change your DNS settings."
    =20
    Then who is going to modify the settings?
    =20
    =20
    =20
    =20
    =20
    > On 6/14/05, lists @ NGSEC <lists@ngsec.com> wrote:
    > > =20
    > > -----BEGIN PGP SIGNED MESSAGE-----
    > > Hash: SHA1
    > >=20
    > > Hello,
    > >=20
    > > NGSEC is proud to announce the new release of our new product
    > > AntiPharming v1.00 [1] TOTALLY FREE for non-commercial use.
    > >=20
    > > What is Pharming?=20
    > >=20
    > > "(...)Pharming is the exploitation of a vulnerability in the DNS
    > > server software that allows a hacker to acquire the Domain Name
    > > for a site, and to redirect traffic to that web site to another
    > > web site. DNS servers are the machines responsible for resolving=20
    > > internet names into their real addresses - the "signposts" of the
    > > internet.
    > >=20
    > > If the web site receiving the traffic is a fake web site, such
    > > as a copy of a bank's website, it can be used to "phish" or steal=20
    > > a computer user's passwords, PIN number or account number.
    > >=20
    > > AntiPharming Configuration For example, in January, 2005, the Domain
    > > Name for a large New York ISP, Panix, was hijacked to a site in
    > > Australia. In 2004 a German teenager hijacked the eBay.de Domain Name.
    > > Secure e-mail provider Hushmail was also caught by this attack on
    > > 24th of April 2005 when the attacker rang up the domain registrar
    > > and gained enough information to redirect users to a defaced=20
    > > webpage(...)" (Source WikiPedia).
    > >=20
    > > What is AntiPharming?
    > >=20
    > > AntiPharming uses active and passive protections for identifying and
    > > stopping Pharming (Phising variant) attacks.
    > >=20
    > > AntiPharming will actively protect your windows server from pharming=20
    > > attacks by:
    > >=20
    > > * Denying any user (even Administrator) to write to the hosts file.
    > > * Denying any user (even Administrator) to change your DNS settings=

    ..
    > >=20
    > > AntiPharming will passively protect your windows server from pharming=

    =20
    > > attacks by sniffing on each netowrk interface for DNS replies (both
    > > TCP and UDP) and recheck them against at least with three secure DNS
    > > nameservers.
    > >=20
    > > AntiPharming is TOTALLY FREE for non-commercial use.
    > > =20
    > > This e-mail has been signed with labs@NGSEC PGP key available at:
    > >=20
    > > http://www.ngsec.com/pgp/labs.asc
    > >=20
    > > [1] http://www.ngsec.com/ngproducts/antipharming/
    > >=20
    > > Best Regards,
    > >=20
    > > - ---
    > > NEXT GENERATION SECURITY, S.L. [NGSEC]
    > > C\ O'donnell 46, 3=BA B
    > > 28009 - Madrid, SPAIN
    > > Tel: +34 91 435 56 27
    > > Fax: +34 91 577 84 45=20
    > >=20
    > > http://www.ngsec.com
    > > -----BEGIN PGP SIGNATURE-----
    > > Version: GnuPG v1.4.1 (GNU/Linux)
    > >=20
    > > iD8DBQFCrrwBKrwoKcQl8Y4RAsO5AJwIJ1Ngm38IT0JCujagcA z4oWgUUwCgl0Lv
    > > vWvO9R/kd5Skb/vzeER7kls=3D=20
    > > =3DXCYN
    > > -----END PGP SIGNATURE-----
    > >=20
    > >=20

    >=20
    >


  3. #3
    Lance James
    [NGSEC] AntiPharming v1.00 FREE
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [NGSEC] AntiPharming v1.00 FREE

    This technology can be thwarted by any malware that has access to the
    Layered Service Provider using the service provider interface. That and
    client side malware will also target the anti-pharming tool to modify or
    break the program. What happens if the target can not reach the "3
    secure" dns servers? Do we successfully DoS the user?

    Thoughts?

    lists@NGSEC wrote:
    > -----BEGIN PGP SIGNED MESSAGE-----
    > Hash: SHA1
    >
    > Hello,
    >
    > NGSEC is proud to announce the new release of our new product
    > AntiPharming v1.00 [1] TOTALLY FREE for non-commercial use.
    >
    > What is Pharming?
    >
    > "(...)Pharming is the exploitation of a vulnerability in the DNS
    > server software that allows a hacker to acquire the Domain Name
    > for a site, and to redirect traffic to that web site to another
    > web site. DNS servers are the machines responsible for resolving
    > internet names into their real addresses - the "signposts" of the
    > internet.
    >
    > If the web site receiving the traffic is a fake web site, such
    > as a copy of a bank's website, it can be used to "phish" or steal
    > a computer user's passwords, PIN number or account number.
    >
    > AntiPharming Configuration For example, in January, 2005, the Domain
    > Name for a large New York ISP, Panix, was hijacked to a site in
    > Australia. In 2004 a German teenager hijacked the eBay.de Domain Name.
    > Secure e-mail provider Hushmail was also caught by this attack on
    > 24th of April 2005 when the attacker rang up the domain registrar
    > and gained enough information to redirect users to a defaced
    > webpage(...)" (Source WikiPedia).
    >
    > What is AntiPharming?
    >
    > AntiPharming uses active and passive protections for identifying and
    > stopping Pharming (Phising variant) attacks.
    >
    > AntiPharming will actively protect your windows server from pharming
    > attacks by:
    >
    > * Denying any user (even Administrator) to write to the hosts file.
    > * Denying any user (even Administrator) to change your DNS settings.
    >
    > AntiPharming will passively protect your windows server from pharming
    > attacks by sniffing on each netowrk interface for DNS replies (both
    > TCP and UDP) and recheck them against at least with three secure DNS
    > nameservers.
    >
    > AntiPharming is TOTALLY FREE for non-commercial use.
    >
    > This e-mail has been signed with labs@NGSEC PGP key available at:
    >
    > http://www.ngsec.com/pgp/labs.asc
    >
    > [1] http://www.ngsec.com/ngproducts/antipharming/
    >
    > Best Regards,
    >
    > - ---
    > NEXT GENERATION SECURITY, S.L. [NGSEC]
    > C\ O'donnell 46, 3º B
    > 28009 - Madrid, SPAIN
    > Tel: +34 91 435 56 27
    > Fax: +34 91 577 84 45
    >
    > http://www.ngsec.com
    > -----BEGIN PGP SIGNATURE-----
    > Version: GnuPG v1.4.1 (GNU/Linux)
    >
    > iD8DBQFCrrwBKrwoKcQl8Y4RAsO5AJwIJ1Ngm38IT0JCujagcA z4oWgUUwCgl0Lv
    > vWvO9R/kd5Skb/vzeER7kls=
    > =XCYN
    > -----END PGP SIGNATURE-----
    >
    >



    --
    Best Regards,
    Lance James
    Secure Science Corporation
    www.securescience.com
    Author of 'Phishing Exposed'
    http://www.securescience.net/amazon/
    Have Phishers stolen your customers' logins? Find out with DIA
    https://slam.securescience.com/signup.cgi - it's free!


  4. #4
    Ansgar -59cobalt- Wiechers
    [NGSEC] AntiPharming v1.00 FREE
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [NGSEC] AntiPharming v1.00 FREE

    On 2005-06-14 Joel Esler wrote:
    > " * Denying any user (even Administrator) to write to the hosts file.
    > * Denying any user (even Administrator) to change your DNS settings."
    >
    > Then who is going to modify the settings?


    An administrator, because he/she can easily (re-)acquire those
    permissions.

    Regards
    Ansgar Wiechers
    --
    "All vulnerabilities deserve a public fear period prior to patches
    becoming available."
    --Jason Coombs on Bugtraq

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics