Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

1 in 10 Windows PCs Still Vulnerable to the Conficker Worm, 1 in 25 infected
Rueters ^ | 04/08/2010

Posted on 04/08/2010 4:17:47 PM PDT by Swordmaker

More than a year after doomsday reports hinted that the Conficker worm would bring down the Internet, one-in-10 Windows PCs still have not been patched to plug the hole the worm wriggles through, new data shows.

And 25 of every 1,000 systems are currently infected with the worm.

According to Qualys, a security risk and compliance management provider, about 10% of the hundreds of thousands of Windows systems it monitors for customers have not yet applied Microsoft's MS08-067 security update. MS08-067, an out-of-band release that shipped in October 2008, patched a bug in the service Windows uses to connect to file and print servers.

Just 11 days after Microsoft delivered the emergency update, antivirus vendors said a worm, variously tagged as Conficker and Downadup, was using the Windows vulnerability , as well as other methods, to aggressively attack PCs and build a massive botnet. By January 2009, some security firms estimated that Conficker had compromised millions of PCs .

(Excerpt) Read more at reuters.com ...


TOPICS: Business/Economy; Computers/Internet; Conspiracy
KEYWORDS: bug; conficker; confickerworm; infected; microsoft; security; update; virus; windows; worm

1 posted on 04/08/2010 4:17:47 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

Even with all the auto-patches and stuff it can’t help those that are completely clueless.

It would be nice if companies could force patch your system but then they’d get sued.


2 posted on 04/08/2010 4:19:12 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies]

To: for-q-clinton
A link could be useful...

Smug might be self gratifying though.

3 posted on 04/08/2010 4:27:07 PM PDT by MileHi ( "It's coming down to patriots vs the politicians." - ovrtaxt)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker
YEAH!


4 posted on 04/08/2010 4:27:14 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: for-q-clinton

I have all my auto updates off, because that constant running in the back ground drives me nuts. It slows my system down. But, I have a little app that I can add reminders to and it’ll pop up a window to remind me to update. I do updates on my virus scanner ever few days and my other patches I check about once a month unless I get some kind of notice. Maybe I should do it more often, but, I don’t.


5 posted on 04/08/2010 4:27:31 PM PDT by MsLady (If you died tonight, where would you go? Salvation, don't leave earth without it!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: for-q-clinton

Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008.[1] It uses flaws in Windows software and Dictionary attacks on administrator passwords to co-opt machines and link them into a virtual computer that can be commanded remotely by its authors. Conficker has since spread rapidly into what is now believed to be the largest computer worm infection since the 2003 SQL Slammer,[2] with more than seven million government, business and home computers in over 200 countries now under its control. The worm has been unusually difficult to counter because of its combined use of many advanced malware techniques


6 posted on 04/08/2010 4:28:52 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 2 | View Replies]

To: for-q-clinton

Technology companies and experts across the globe have been working together to halt the spread of Conficker, disrupt its communications and uncover who created the worm. Microsoft has even issued a $250,000 bounty for information leading to the arrest and conviction of Conficker’s authors. Despite the security sector’s best efforts, very little is known about the origins of Conficker or its purpose. Nevertheless, some breakthroughs have been achieved. On March 30, Security experts with the Honeynet Project discovered a flaw in Conficker that makes it much easier to detect infection. IBM researcher Mark Yayson also believes he has discovered a way to “detect and interrupt the program’s activities,” according to The New York Times.


7 posted on 04/08/2010 4:33:20 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 2 | View Replies]

To: JoeProBono

That’s not really true and that’s all I will say about that. I can’t legally go further than that.


8 posted on 04/08/2010 4:41:12 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 7 | View Replies]

To: for-q-clinton

I don’t blame you.


9 posted on 04/08/2010 4:42:29 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 8 | View Replies]

To: MsLady

Yes you should check more often or at least subscribe to security alerts from the software vendors whose software you run.

An out-of-band security patch is typically something you would want to get patched immediately. Microsoft has something called patch tuesdays where they issue their hotfixes once per month. But when they release a hotfix that doesn’t come out on the scheduled patch Tuesday it means it’s a real threat and it needs to get patched ASAP.


10 posted on 04/08/2010 4:43:45 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 5 | View Replies]

To: for-q-clinton
I can’t legally go further than that

Unless your real name is for-q-clinton, why not?

11 posted on 04/08/2010 4:46:53 PM PDT by Lancey Howard
[ Post Reply | Private Reply | To 8 | View Replies]

To: Lancey Howard

It could be an NDA or a security clearance or that I don’t know what I’m talking about. Feel free to take your pick and I won’t be commenting more than this on the issue.


12 posted on 04/08/2010 4:52:49 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 11 | View Replies]

To: for-q-clinton

Thanks for the info. I’ll go over to microsoft and check out the hotfix email notice.


13 posted on 04/08/2010 5:00:50 PM PDT by MsLady (If you died tonight, where would you go? Salvation, don't leave earth without it!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: for-q-clinton

” I won’t be commenting more than this on the issue.”

I don’t blame you!


14 posted on 04/08/2010 5:08:49 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 12 | View Replies]

To: for-q-clinton

BTW - aren’t you taking chances with your screen name?


15 posted on 04/08/2010 5:11:33 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

Isn’t 25:1000 1:40?


16 posted on 04/08/2010 5:19:00 PM PDT by Brellium ("Thou shalt not shilly shally!" Aron Nimzowitsch)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Wouldn't 25 out of a 1000 translate to 1 out of 40 rather than 1 out of 25?
17 posted on 04/08/2010 5:28:38 PM PDT by dangerdoc
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #18 Removed by Moderator

To: dangerdoc
Wouldn't 25 out of a 1000 translate to 1 out of 40 rather than 1 out of 25?

didn't stop to calculate... just repeated the article... should have. Still WAY TOO MANY...

19 posted on 04/09/2010 2:48:43 AM PDT by Swordmaker (Remember, the proper pronunciation of IE isAAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 17 | View Replies]

To: for-q-clinton; JoeProBono
That’s not really true and that’s all I will say about that. I can’t legally go further than that.

We wish it WERE true... that same report popped up in mid February... and nothing came of it. I think it's one of those worms that the only way to get rid of it is to shut down the members of the bot and wipe them... if you can find them.

20 posted on 04/09/2010 2:53:12 AM PDT by Swordmaker (Remember, the proper pronunciation of IE isAAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 8 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson