Free Republic
Browse · Search
General/Chat
Topics · Post Article

Shout out to all IT / Cyber Freepers. Check your DNS config and admin.
1 posted on 01/23/2019 10:07:56 AM PST by taxcontrol
[ Post Reply | Private Reply | View Replies ]


To: dayglored; ShadowAce

p


2 posted on 01/23/2019 10:11:54 AM PST by bitt (forget the electric chair..we're gonna need electric bleachers!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: taxcontrol

5 posted on 01/23/2019 10:30:19 AM PST by COBOL2Java (Marxism: Trendy theory, wrong species)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; Ernest_at_the_Beach; martin_fierro; ...

6 posted on 01/23/2019 10:33:30 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: taxcontrol

FYI...here’s the Emergency Directive 19-01 itself:

https://cyber.dhs.gov/ed/19-01/

Excerpt/summary:

Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked services.

1.The attacker begins by compromising user credentials, or obtaining them through alternate means, of an account that can make changes to DNS records.

2.Next, the attacker alters DNS records, like Address (A), Mail Exchanger (MX), or Name Server (NS) records, replacing the legitimate address of a service with an address the attacker controls. This enables them to direct user traffic to their own infrastructure for manipulation or inspection before passing it on to the legitimate service, should they choose. This creates a risk that persists beyond the period of traffic redirection.

3.Because the attacker can set DNS record values, they can also obtain valid encryption certificates for an organization’s domain names. This allows the redirected traffic to be decrypted, exposing any user-submitted data. Since the certificate is valid for the domain, end users receive no error warnings.


8 posted on 01/24/2019 4:31:51 PM PST by MeganC (There is nothing feminine about feminism.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson