Crouching Tiger, Hidden DNS

Discussion in 'malware problems & news' started by Minimalist, Jun 2, 2016.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://www.welivesecurity.com/2016/06/02/crouching-tiger-hidden-dns/
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Easiest way to prevent crud like this is to use a firewall that monitors outbound connections. Then create an outbound rule for port 53 TCP/UDP with remote IP addresses set to the DNS servers you use. Make sure to also include the IPv6 addresses if your ISP is using it.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Isn't monitoring the registry keys related to the DNS settings enough to stop this?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.