Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Conficker flaw reveals which computers are infected
CNET ^ | March 30, 2009 1:54 PM PDT | Elinor Mills

Posted on 04/02/2009 6:55:26 PM PDT by Ernest_at_the_Beach

Even worm creators write buggy software.

Once it infects a computer, the Conficker worm closes the hole in Windows that it used to get onto the system so no other malware can get in. This also makes it difficult for organizations to detect which computers have the legitimate Microsoft patch and which have the fake Conficker patch.

However, Conficker's "patch" has a weakness that can be used to distinguish between patched computers and infected computers that look patched, according to the nonprofit Honeynet Project.

Some of the researchers have released a proof-of-concept scanner that can be used to detect Conficker. The tool is being integrated into the free nMap vulnerability scanner, as well as scanning tools from companies including Qualys, nCircle, and Tenable. The tools are designed for use by network administrators at companies and not consumer users.

"What we've found is pretty cool: Conficker actually changes what Windows looks like on the network, and this change can be detected remotely, anonymously, and very, very quickly. You can literally ask a server if it's infected with Conficker, and it will tell you," Dan Kaminsky, director of penetration testing at IOActive who worked with The Honeynet Project, wrote on his blog. "We figured this out on Friday, and got code put together for Monday. It's been one heck of a weekend."

Qualys' remote-detection Conficker scanner is automatically available to its subscribers and will be available to others soon, said Wolfgang Kandek, Qualys' chief technology officer.

The worm has been around since November, but the most recent variant is programmed to connect to other computers on April 1 and as a result has triggered mass confusion and a media frenzy.

The worm exploits a vulnerability in Windows that ...was patched in October...

(Excerpt) Read more at news.cnet.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: conficker; malware
Just came across this...link...Microsoft patched in October, .......
1 posted on 04/02/2009 6:55:26 PM PDT by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

fyi


2 posted on 04/02/2009 6:56:15 PM PDT by Ernest_at_the_Beach (What happened to my IRAs)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
Fast and easy test to see if Conficker has compromised your computer:

http://www.freerepublic.com/focus/f-news/2220870/posts.

3 posted on 04/02/2009 6:57:20 PM PDT by justlurking (The only remedy for a bad guy with a gun is a good guy with a gun.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Bump for later...


4 posted on 04/02/2009 7:04:33 PM PDT by rightwingextremist1776
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
...to detect which computers have the legitimate Microsoft patch and which have the fake Conficker patch.

Is there a difference? Har, har, har. :D

5 posted on 04/02/2009 7:06:32 PM PDT by library user (Rod Blagojevich should have been TIME MAGAZINE'S "Person of the Year.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: library user

Standard Micro$oft procedure. “What once was a bug, is now a feature.”


6 posted on 04/02/2009 7:13:49 PM PDT by lrb111 (Ø resist)
[ Post Reply | Private Reply | To 5 | View Replies]

To: lrb111
Standard Micro$oft procedure. “What once was a bug, is now a feature.”

A critical part of the next service pack, no doubt. LOL


7 posted on 04/02/2009 7:34:24 PM PDT by Viking2002 (FUBO. Just....................FUBO.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

8 posted on 04/03/2009 5:35:20 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
director of penetration testing

That sounds like a fun job. How does one get it? I did do quite a bit of penetration testing in college, but I'm not sure I got enough credits to qualify me for a job in the field.

9 posted on 04/03/2009 6:02:32 AM PDT by KevinB (Those who love sausage and respect the law should never watch either being made.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson