<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Feds Request DNSChanger Deadline Extension</title>
	<atom:link href="http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Tue, 21 May 2013 08:39:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: DaveMich</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-62368</link>
		<dc:creator>DaveMich</dc:creator>
		<pubDate>Fri, 02 Mar 2012 23:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-62368</guid>
		<description><![CDATA[It can be difficult for IT departments to track down rogue DNS traffic through within their network.  Taking the DNS servers offline would be the best thing to do - the infected NATd computers would no longer function and IT departments could easily track them down based on service calls.]]></description>
		<content:encoded><![CDATA[<p>It can be difficult for IT departments to track down rogue DNS traffic through within their network.  Taking the DNS servers offline would be the best thing to do &#8211; the infected NATd computers would no longer function and IT departments could easily track them down based on service calls.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-62335</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 02 Mar 2012 13:48:14 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-62335</guid>
		<description><![CDATA[I also would be shy of any click here to fix, however a redirect to an official looking FBI page (especially if the url is fbi.gov) explaining the situation and suggesting you do research on another machine would probably do the job without training users to blindly click.

Jay]]></description>
		<content:encoded><![CDATA[<p>I also would be shy of any click here to fix, however a redirect to an official looking FBI page (especially if the url is fbi.gov) explaining the situation and suggesting you do research on another machine would probably do the job without training users to blindly click.</p>
<p>Jay</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CW</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-62011</link>
		<dc:creator>CW</dc:creator>
		<pubDate>Tue, 28 Feb 2012 17:31:10 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-62011</guid>
		<description><![CDATA[Brian,

Do you know if there has been any thought to include DNSChanger detection in the monthly Microsoft Malicious Software Removal Tool?  I&#039;ve read security reports in the past, claiming that this tool has removed millions of various infections over the years.  Not sure if the DNSChanger malware is too embedded/complex to include in the monthly MS patch, but it&#039;s at least worth a little pondering.

http://support.microsoft.com/kb/890830]]></description>
		<content:encoded><![CDATA[<p>Brian,</p>
<p>Do you know if there has been any thought to include DNSChanger detection in the monthly Microsoft Malicious Software Removal Tool?  I&#8217;ve read security reports in the past, claiming that this tool has removed millions of various infections over the years.  Not sure if the DNSChanger malware is too embedded/complex to include in the monthly MS patch, but it&#8217;s at least worth a little pondering.</p>
<p><a href="http://support.microsoft.com/kb/890830" rel="nofollow">http://support.microsoft.com/kb/890830</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61871</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 27 Feb 2012 16:35:05 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61871</guid>
		<description><![CDATA[Sorry, that wasn&#039;t all in reply to Mark.]]></description>
		<content:encoded><![CDATA[<p>Sorry, that wasn&#8217;t all in reply to Mark.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61870</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 27 Feb 2012 16:34:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61870</guid>
		<description><![CDATA[Several of the early malware variants &quot;fail back&quot; to using the real DNS settings if the hacker DNS isn&#039;t available.

The version that hacked routers only seemed to change one of the DNS servers, the other was still the ISPs DNS server.  I don&#039;t know if that was specific to the router brand.

The version that established a rogue DHCP server caused immediate outages to side-impacted boxes in a typical (no DNS outbound) IT environment.

Most of you are idiots.

I wonder who will get these IP addresses next?  Whoever gets them will be sucking down a bit of unwanted traffic, and they will have a chance to create some mischief of their own.

&gt;&gt;Also why on Earth did this need to be handed to a private
&gt;&gt;company?!?!?!?!?!?

 Did you look at the list of companies and groups participating?  Some are recognizable security researchers who have done this type of thing on their own before, with no LEA involvement.

 The DNS servers are being run by the ISC.  I&#039;m sure you&#039;re familiar with them.]]></description>
		<content:encoded><![CDATA[<p>Several of the early malware variants &#8220;fail back&#8221; to using the real DNS settings if the hacker DNS isn&#8217;t available.</p>
<p>The version that hacked routers only seemed to change one of the DNS servers, the other was still the ISPs DNS server.  I don&#8217;t know if that was specific to the router brand.</p>
<p>The version that established a rogue DHCP server caused immediate outages to side-impacted boxes in a typical (no DNS outbound) IT environment.</p>
<p>Most of you are idiots.</p>
<p>I wonder who will get these IP addresses next?  Whoever gets them will be sucking down a bit of unwanted traffic, and they will have a chance to create some mischief of their own.</p>
<p>&gt;&gt;Also why on Earth did this need to be handed to a private<br />
&gt;&gt;company?!?!?!?!?!?</p>
<p> Did you look at the list of companies and groups participating?  Some are recognizable security researchers who have done this type of thing on their own before, with no LEA involvement.</p>
<p> The DNS servers are being run by the ISC.  I&#8217;m sure you&#8217;re familiar with them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thegreyfoxx</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61752</link>
		<dc:creator>thegreyfoxx</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:19:41 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61752</guid>
		<description><![CDATA[...  or trust the government agency whose IT systems manager  can&#039;t clean up their systems in the 9 months already allowed.  
I say, &quot;shut &#039;em down March 8&quot;.  
That will prompt the mess clean up pronto...!!
Affected Agencies should, uhhhm,  &quot;re-assign&quot; their IT managers to the parking lot janitorial squad detail.]]></description>
		<content:encoded><![CDATA[<p>&#8230;  or trust the government agency whose IT systems manager  can&#8217;t clean up their systems in the 9 months already allowed.<br />
I say, &#8220;shut &#8216;em down March 8&#8243;.<br />
That will prompt the mess clean up pronto&#8230;!!<br />
Affected Agencies should, uhhhm,  &#8220;re-assign&#8221; their IT managers to the parking lot janitorial squad detail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nikol</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61641</link>
		<dc:creator>nikol</dc:creator>
		<pubDate>Sun, 26 Feb 2012 00:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61641</guid>
		<description><![CDATA[Checking Home Routers for Infections

Coming soon
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 
also i get this clicking on Home Routers]]></description>
		<content:encoded><![CDATA[<p>Checking Home Routers for Infections</p>
<p>Coming soon<br />
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!</p>
<p>also i get this clicking on Home Routers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61608</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sat, 25 Feb 2012 17:36:50 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61608</guid>
		<description><![CDATA[I wouldn&#039;t want to have to deal with the change of venue hearings. They may want to keep the servers going until they&#039;ve got the jury sequestered somewhere they won&#039;t hear the howls of agony when people can&#039;t visit FB from work.]]></description>
		<content:encoded><![CDATA[<p>I wouldn&#8217;t want to have to deal with the change of venue hearings. They may want to keep the servers going until they&#8217;ve got the jury sequestered somewhere they won&#8217;t hear the howls of agony when people can&#8217;t visit FB from work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hayton</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61595</link>
		<dc:creator>Hayton</dc:creator>
		<pubDate>Sat, 25 Feb 2012 08:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61595</guid>
		<description><![CDATA[&quot;I can see why the state department would want to delay shutting down the DNS servers until they’ve actually completed the extradition of the Estonian perps&quot;

Perhaps the plan is to shut the servers down during their trial, to make a point. And hope that none of the jurors has an infected PC and is suddenly cut off from the internet ....]]></description>
		<content:encoded><![CDATA[<p>&#8220;I can see why the state department would want to delay shutting down the DNS servers until they’ve actually completed the extradition of the Estonian perps&#8221;</p>
<p>Perhaps the plan is to shut the servers down during their trial, to make a point. And hope that none of the jurors has an infected PC and is suddenly cut off from the internet &#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2012/02/feds-request-dnschanger-deadline-extension/comment-page-1/#comment-61592</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sat, 25 Feb 2012 06:07:54 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13921#comment-61592</guid>
		<description><![CDATA[I can see why the state department would want to delay shutting down the DNS servers until they&#039;ve actually completed the extradition of the Estonian perps. Half a million angry people disconnected from the internet in one fell swoop in the middle of a business day?  A lot of European countries won&#039;t extradite criminals to the US if they could potentially face a death penalty. ;)]]></description>
		<content:encoded><![CDATA[<p>I can see why the state department would want to delay shutting down the DNS servers until they&#8217;ve actually completed the extradition of the Estonian perps. Half a million angry people disconnected from the internet in one fell swoop in the middle of a business day?  A lot of European countries won&#8217;t extradite criminals to the US if they could potentially face a death penalty. <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 21/22 queries in 0.002 seconds using memcached
Object Caching 387/403 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-21 05:04:53 by W3 Total Cache -->