Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Government Networking Security IT

FBI To Shut Down DNSChanger Servers Monday -- But Should It Cut Off 300k PCs? 140

nk497 writes "The FBI is set to pull the plug on DNSChanger servers on Monday, leaving as many as 300,000 PCs with the wrong DNS settings, unable to easily connect to websites — although that's a big improvement from the 4m computers that would have been cut off had the authorities pulled the plug when arresting the alleged cybercriminals last year. The date has been pushed back once already to allow people more time to sort out their infected PCs, but experts say it's better to cut off infected machines than leave them be. 'Cutting them off would force them to get ahold of tech support and reveal to them that they've been running a vulnerable machine that's been compromised,' said F-Secure's Sean Sullivan. 'They never learn to patch up the machine, so it's vulnerable to other threats as well. The longer these things sit there, the more time there is for something else to infect.'"
This discussion has been archived. No new comments can be posted.

FBI To Shut Down DNSChanger Servers Monday -- But Should It Cut Off 300k PCs?

Comments Filter:
  • by Todd Knarr ( 15451 ) on Wednesday July 04, 2012 @04:50PM (#40544493) Homepage

    The FBI didn't change any settings. The malware did that, it alters the infected computer's DNS settings to use a set of servers run by the malware authors. What the FBI did was take over those servers and replace the malicious software running on them with software that does normal DNS so infected computers were no longer being redirected to the malware author's sites. And now the FBI's looking at shutting down the servers entirely, which would leave the infected computers with no DNS servers at all.

  • by John Bokma ( 834313 ) on Wednesday July 04, 2012 @04:57PM (#40544555) Homepage
    DNS servers don't return pages. What you probably mean is to return the same IP address for each and every DNS request, an IP address that hosts a web server that tells people that their computer has been infected. Might be possible to do the same for other protocols, e.g. POP3 will return daily a new email that their computer has been infected, etc.
  • by nuckfuts ( 690967 ) on Wednesday July 04, 2012 @05:10PM (#40544651)
    The DNSChanger malware can change DHCP server settings on some routers [fbi.gov]. If your home router has been tampered with, it may continue to provide rogue DNS settings even after your PC has been cleaned or reinstalled.
  • by kriston ( 7886 ) on Thursday July 05, 2012 @12:13AM (#40547801) Homepage Journal

    It really does matter for the underserved internet community who rely on affordable and sometimes outdated DSL modems for their access to the internet in rural areas. Many of these DSL modems have been infected by a scary variant of the DNSChanger Zlob trojan that actually changes the DSL modem's DNS settings and changes the DSL modem's password to an unguessable value. The most detrimental effect of this infection is a virtually irreversible firmware change in an unknown but probably high number of DSL modems worldwide which are permanently affixed to the rogue DNS servers, now siezed and run by the FBI as clean, boring caching DNS servers. They will be shut down July 9 because the FBI doesn't want to be an ISP, which has the effect of cutting off an unknown number of people from the internet.

    It's not a small problem. It's a big problem. The cost of help desk calls alone will be devastating to the disadvantaged and underserved internet community, i.e., rural America, who may be using the affected DSL modems infected by this Zlob trojan variant.

    The most important note you must realize about this problem is that DNSChanger actually changed the DNS servers on the DSL modem. Just in case you don't realize this: the DSL modem provides the DNS server info to the computer in the home. While the computer may no longer be infected, the DSL modem is configured to use the DNSChanger rogue DNS servers which the FBI siezed and will shut down on July 9.

    It's a really big deal and we should treat it like that.

    You can check more out here: http://www.dns-ok.us/ [dns-ok.us]

"When it comes to humility, I'm the greatest." -- Bullwinkle Moose

Working...