DNS Poisoning Stats

The DNS spoofing attack on March 3rd redirected affected users to a set of compromissed web servers. Some of the administrators of these servers agreed to share logs collected during the attack (THANKS!). Based on these logs, we collected the following statistics:

o 1,304 domains poisoned (pulled from the referer entries in the HTTPD logs)
o 7,973,953 HTTP get attempts from 966 unique IP addresses.
o 75,529 incoming email messages from 1,863 different mailservers.
o 7,455 failed FTP logins from 635 unique IP addresses (95 unique user accounts).
o 7,692 attempted IMAP logins (805 unique users, 411 unique IP addresses).
o 2,027 attempted logins to 82 different webmail (HTTP) servers.