We have seen multiple instances where DHCP enabled workstations have had
their DNS reconfigured to point to two of the three addresses listed
below. Can anyone else confirm this? Incidents.org is reporting an
increase in port 53 traffic over the last two days. Are we looking at the
precursor to the next worm?
216.127.92.38
69.57.146.14
69.57.147.175
-KJH
++++++++++++++++++++++++++
Kevin J. Hansen
Architect
Global Network
Thomson Legal & Regulatory
kevin.hansen@thomson.com
651-687-8466
++++++++++++++++++++++++++