Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 26th, 2006, 06:16 AM
R2D2's Avatar
R2D2 R2D2 is offline
Regular Poster
 
Join Date: Nov 2004
Location: Tatooine
Posts: 70
Default What kind of attack, malware is this?

I was just curious to what it could've been...

Recently, I was unable to access specific websites such as my yahoo email, CNN, and certain others. This went on for weeks, (until a reformat ). I know it wasn't because their servers were down or overloaded because it's a very slim chance that the same specific websites over a long period of time wouldn't be accessible.

Was this a Denial of Service attack?
Any ideas?

Jeff
__________________
May the force be with you!
/
  #2  
Old January 26th, 2006, 06:48 AM
SpikeyB SpikeyB is offline
Frequent Poster
 
Join Date: Mar 2005
Posts: 464
Default Re: What kind of attack, malware is this?

Maybe those websites had been added to your hosts file.
  #3  
Old January 26th, 2006, 07:31 AM
R2D2's Avatar
R2D2 R2D2 is offline
Regular Poster
 
Join Date: Nov 2004
Location: Tatooine
Posts: 70
Default Re: What kind of attack, malware is this?

Thanks SpikeyB!

Good to know.
I'll check that file's contents if it happens again.

Jeff
__________________
May the force be with you!
/
  #4  
Old January 26th, 2006, 12:14 PM
Notok's Avatar
Notok Notok is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Portland, OR (USA)
Posts: 2,960
Default Re: What kind of attack, malware is this?

Malware changing the HOSTS file is a very definite possibility.. there's a lot of worms and other malware out there that are still doing this to make it hard for you to disinfect (hard to disinfect when you can't get to a website to download a disinfection tool).. in addition some of these will attempt to kill security software and other tools used in remvoing malware.
__________________
Security is not a brand name.

NSA security configuration guides -- Best Practices for Securing a Home Network
  #5  
Old January 26th, 2006, 12:27 PM
R2D2's Avatar
R2D2 R2D2 is offline
Regular Poster
 
Join Date: Nov 2004
Location: Tatooine
Posts: 70
Default Re: What kind of attack, malware is this?

Hi Notok,

Yes, the HOSTS file is a popular target.
I guess I could make a backup copy of the file so that if it gets infected, just delete the infected file and reinstall the clean one in its place.

I thought my Spyware Doctor would protect the host file from infection.

Jeff
__________________
May the force be with you!
/
  #6  
Old January 26th, 2006, 10:36 PM
Notok's Avatar
Notok Notok is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Portland, OR (USA)
Posts: 2,960
Default Re: What kind of attack, malware is this?

If you have all the "On-Guard" settings on, it should.. I suppose it's possible that it got it when it was down, though. There are other possibilities, but that's the most common one.
__________________
Security is not a brand name.

NSA security configuration guides -- Best Practices for Securing a Home Network
  #7  
Old January 27th, 2006, 01:35 AM
chocolate doodle
 
Posts: n/a
Default Re: What kind of attack, malware is this?

spyware blaster can be keeping backups of hostfiles, so does spybot also winpatrol and spybot can lock host files from attack, i think..
  #8  
Old January 27th, 2006, 02:08 AM
R2D2's Avatar
R2D2 R2D2 is offline
Regular Poster
 
Join Date: Nov 2004
Location: Tatooine
Posts: 70
Default Re: What kind of attack, malware is this?

Quote:
Originally Posted by Notok
If you have all the "On-Guard" settings on, it should.. I suppose it's possible that it got it when it was down, though. There are other possibilities, but that's the most common one.

Oops, I don't think I had it set right , but fixed it.
Thanks Notok!

Quote:
Originally Posted by chocolate doodle
spyware blaster can be keeping backups of hostfiles, so does spybot also winpatrol and spybot can lock host files from attack, i think..

Thanks chocolate doodle. I didn't have any of those running when it happened but good info to have.

By the way, I just sent you a post to your thread, "What's the best download spot"

Thanks,
Jeff
__________________
May the force be with you!
/
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:14 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums