Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 7th, 2011, 05:26 AM
expert expert is offline
Infrequent Poster
 
Join Date: Sep 2011
Posts: 1
Default Detected DNS cache poisoning attack

Hi All,

It has only been 2 days so far since I have installed Eset SS v5.0.84.0 rc and I have been seeing the "Detected DNS cache poisoning attack" on average about 10-20 times a day so far.

The IP shown is from my own router.
Is this a known issue or should I be concerned about a genuine attack?

Cheers.
Attached Images
 
  #2  
Old September 7th, 2011, 09:14 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,897
Default Re: Detected DNS cache poisoning attack

Hello,

Perhaps your router is refreshing the cache it uses to store DNS information? I suspect it may be a false positive alarm, but if you contact ESET's technical support department directly, they should be able to investigate the issue further with you to confirm this.

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #3  
Old September 7th, 2011, 09:24 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,858
Lightbulb Re: Detected DNS cache poisoning attack

@ agoretsky

It would be Very helpful to people in future if you post the actual www link and/or email address for things such as ESET's technical support department etc. Not everybody would automatically know them, or how to get them !

Regards
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #4  
Old September 7th, 2011, 09:35 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,897
Default Re: Detected DNS cache poisoning attack

Hello,

The URLs vary by country, but in North America, ESET contact information can be found at http://www.eset.com/us/about/contact/, or the company reached toll-free at +1 (866) 343-3738.

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #5  
Old September 13th, 2011, 02:18 AM
stratoc
 
Posts: n/a
Default Re: Detected DNS cache poisoning attack

This small yet annoying problem is what caused me to cancel my renewal, simply because Eset don't know what it is. You also get a pop up with version 5.
When v4 was launched I would get a detected dns poisoning notification in the firewall log about every 30 minutes, I would also get one each time any online game was closed. I was on adsl then I am on cable now with a different router.
The first time I contacted support they said it was a known problem on some configurations and told me to disable it in settings, they would not tell me what it meant, after 3 times of contact I am sure they really have no idea.
All I wanted to know was what it actually meant, had it blocked something? was it information only? what did it mean, I never got an answer on here or from support.
It was fixed (for me) in version 4.2, and now it's back with pop ups.
If it has pop ups does it require intervention? Is it for information? Nobody told me 3 years ago I guess nobody will now.
I am hard wired by ethernet to a virgin media super hub now 100 meg fibre optic, I was hard wired to a bt home hub before. It is a fp, and only a small problem, it was supports complete lack of knowledge it displayed that made me lose confidence and not renew my license of 7 years, I can't live with a pop up each time my router refreshes when nobody can explain and don't see why I should turn features off when support cannot even tell me what it means!
Good luck.
  #6  
Old September 13th, 2011, 03:20 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: Detected DNS cache poisoning attack

The erroneous "DNS cache poisoning attack" detections should be fixed in the next build of the firewall module (1072 probably). They used to occur when responses from a DNS server did not match queries.

Last edited by Marcos : September 13th, 2011 at 04:20 AM.
  #7  
Old September 13th, 2011, 04:12 AM
stratoc
 
Posts: n/a
Default Re: Detected DNS cache poisoning attack

Thanks for the reply, I will watch for the next firewall module.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:08 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums