Networking Forums

Networking Forums > Computer Networking > Windows Networking > q: How does ping hijacking work?

Reply
Thread Tools Display Modes

q: How does ping hijacking work?

 
 
david
Guest
Posts: n/a

 
      12-12-2008, 09:19 AM
I'm cleaning out an infected computer, and I've realised that it doesn't
just have 'browser' hijacking, it has 'ping' hijacking as well: most sites
(or many sites) are identified as 127.0.0.1. This is not DNS hijacking: NS
lookup still works. It is not DNS client cache corruption: I've turned off
the cache. I don't know what it is. I'm curious: What can you do to Windows
to break networking at this level?

(david)


 
Reply With Quote
 
 
 
 
Alister
Guest
Posts: n/a

 
      12-12-2008, 10:44 AM
On Dec 12, 10:19 am, "david" <da...@nospam.au> wrote:
> I'm cleaning out an infected computer, and I've realised that it doesn't
> just have 'browser' hijacking, it has 'ping' hijacking as well: most sites
> (or many sites) are identified as 127.0.0.1. This is not DNS hijacking: NS
> lookup still works. It is not DNS client cache corruption: I've turned off
> the cache. I don't know what it is. I'm curious: What can you do to Windows
> to break networking at this level?
>
> (david)


Could be hosts file entries for common sites.

Alister
 
Reply With Quote
 
david
Guest
Posts: n/a

 
      12-14-2008, 09:41 PM
Nope, the hosts file is clean, unless it has been re-directed. hmmmm...
what's the reg entry to re-direct the hosts file?

(david)

"Alister" <(E-Mail Removed)> wrote in message
news:7c4f7707-cc9a-48a8-a249-(E-Mail Removed)...
> On Dec 12, 10:19 am, "david" <da...@nospam.au> wrote:
>> I'm cleaning out an infected computer, and I've realised that it doesn't
>> just have 'browser' hijacking, it has 'ping' hijacking as well: most
>> sites
>> (or many sites) are identified as 127.0.0.1. This is not DNS hijacking:
>> NS
>> lookup still works. It is not DNS client cache corruption: I've turned
>> off
>> the cache. I don't know what it is. I'm curious: What can you do to
>> Windows
>> to break networking at this level?
>>
>> (david)

>
> Could be hosts file entries for common sites.
>
> Alister



 
Reply With Quote
 
Alister
Guest
Posts: n/a

 
      12-15-2008, 09:54 AM
On Dec 14, 10:41 pm, "david" <da...@nospam.au> wrote:
> Nope, the hosts file is clean, unless it has been re-directed. hmmmm...
> what's the reg entry to re-direct the hosts file?
>
> (david)
>
> "Alister" <alister....@hotmail.co.uk> wrote in message
>
> news:7c4f7707-cc9a-48a8-a249-(E-Mail Removed)...
>
> > On Dec 12, 10:19 am, "david" <da...@nospam.au> wrote:
> >> I'm cleaning out an infected computer, and I've realised that it doesn't
> >> just have 'browser' hijacking, it has 'ping' hijacking as well: most
> >> sites
> >> (or many sites) are identified as 127.0.0.1. This is not DNS hijacking:
> >> NS
> >> lookup still works. It is not DNS client cache corruption: I've turned
> >> off
> >> the cache. I don't know what it is. I'm curious: What can you do to
> >> Windows
> >> to break networking at this level?

>
> >> (david)

>
> > Could be hosts file entries for common sites.

>
> > Alister


HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\T cpip\Parameters
\DataBasePath

Alister
 
Reply With Quote
 
david
Guest
Posts: n/a

 
      12-16-2008, 11:54 PM
Nope, not that either.

It doesn't create a new connector either. When there is no network
the redirection is not in effect.

Oh well.

(david)

"Alister" <(E-Mail Removed)> wrote in message
news:f939e46d-e57b-4b9e-8ea7-(E-Mail Removed)...
> On Dec 14, 10:41 pm, "david" <da...@nospam.au> wrote:
>> Nope, the hosts file is clean, unless it has been re-directed. hmmmm...
>> what's the reg entry to re-direct the hosts file?
>>
>> (david)
>>
>> "Alister" <alister....@hotmail.co.uk> wrote in message
>>
>> news:7c4f7707-cc9a-48a8-a249-(E-Mail Removed)...
>>
>> > On Dec 12, 10:19 am, "david" <da...@nospam.au> wrote:
>> >> I'm cleaning out an infected computer, and I've realised that it
>> >> doesn't
>> >> just have 'browser' hijacking, it has 'ping' hijacking as well: most
>> >> sites
>> >> (or many sites) are identified as 127.0.0.1. This is not DNS
>> >> hijacking:
>> >> NS
>> >> lookup still works. It is not DNS client cache corruption: I've
>> >> turned
>> >> off
>> >> the cache. I don't know what it is. I'm curious: What can you do to
>> >> Windows
>> >> to break networking at this level?

>>
>> >> (david)

>>
>> > Could be hosts file entries for common sites.

>>
>> > Alister

>
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\T cpip\Parameters
> \DataBasePath
>
> Alister



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hijacking a broadband connection The Todal Wireless Internet 247 10-12-2010 07:26 PM
Ping doesnt work Harry Windows Networking 1 10-27-2006 06:37 AM
Ping no Work TonyK Windows Networking 1 02-16-2006 10:03 AM
Weird problem - Ping and DNS work; nothing else does. fake Linux Networking 0 05-09-2004 10:47 PM
Ping work but not mapping josepe Windows Networking 2 11-18-2003 02:39 PM



1 2 3 4 5 6 7 8 9 10 11