<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talk Tech To Me - GFI Blog &#187; conficker</title>
	<atom:link href="http://www.gfi.com/blog/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gfi.com/blog</link>
	<description>Brought to you by GFI Software</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:18:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Computer Security in the News</title>
		<link>http://www.gfi.com/blog/computer-security-news/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=computer-security-news</link>
		<comments>http://www.gfi.com/blog/computer-security-news/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 10:24:16 +0000</pubDate>
		<dc:creator>Clifford Farrugia</dc:creator>
				<category><![CDATA[Tech Zone]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=185</guid>
		<description><![CDATA[Viruses, Trojans, worms, spyware, malware, rootkits, phishing, botnets, cross-site scripting, vulnerabilities… the list of buzzwords goes on. These words all mean something to us in the security arena, but for the general public they’re just  indistinguishable words that geeks use. &#8230;]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-192" style="margin: 10px;" title="computer-security-conficker-virus" src="http://www.gfi.com/blog/wp-content/uploads/2009/06/computer-security-conficker-virus-300x200.jpg" alt="" width="240" height="160" />Viruses, Trojans, worms, spyware, malware, rootkits, phishing, botnets, cross-site scripting, vulnerabilities… the list of buzzwords goes on. These words all mean something to us in the security arena, but for the general public they’re just  indistinguishable words that geeks use.</p>
<p>Every few months, some new threat sparks up in the news and every other journalist that doesn’t really know what the threat is about wants to write an article about it to raise awareness. I remember one instance when I was younger, on 31st March of some year in the last millennium, my sister had told me not to turn on the computer on 1st April because we’d get a virus. My reaction was “Huh? Can’t we get a virus every day?” to which the reply was “Maybe, but I’ve heard that whoever uses the computer on 1st April will get a virus.”</p>
<p>All these years have passed and I couldn’t believe I was experiencing the same thing againI’m obviously talking about the Conficker worm. I’m not saying that awareness is a bad thing or that malware threats should not be reported. However, I think that it’s about time that the general public is educated in another manner.</p>
<p><span id="more-185"></span>Conficker infected millions of machines by exploiting a vulnerability in the NetBIOS implementation in Windows. What most people never got to know was that this vulnerability was fixed by Microsoft when Security Bulletin MS08-067 was released on 23rd October 2008. The first variant of Conficker was discovered on November 20th – almost a whole month after this vulnerability was fixed. What this means is that if  all users kept their systems up to date, then this worm would never have started to propagate, thus relieving the worldwide panic that resulted afterwards.</p>
<p>It’s time that everyone starts to think about protecting their systems all year round and not just reacting to overhyped news.  You wouldn’t leave the doors and windows of your house open and then panic if some intruder enters the building! People have had front doors for thousands of years;  so, why should the security of a computer be treated differently? It’s about time that even grandma understands that a computer connected to the Internet is like a house connected to the ground – if you leave it open, intruders from outside can come in.</p>
<p>So what can the average person do?</p>
<p>First thing, keep your software up to date, especially the Operating System. If all systems are kept up to date, most malware outbreaks would never occur. Secondly, some form of anti-virus technology should be present. In a home environment, normally the only thing that can be used is a client-based AV; in companies, emails can be scanned at the gateway, and so can web downloads. Thirdly, every computer user should be educated, and by this I don’t just mean a one-time boring speech that is delivered and forgotten, but continuous reminders on what is safe and what isn’t. Don’t we get adverts warning us not to drink and drive? So why shouldn’t companies put up notices warning their users not to download animated emails to watch singing kittens?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gfi.com/blog/computer-security-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker, at the airbase and hospital near you…</title>
		<link>http://www.gfi.com/blog/conficker-airbase-hospital-near-you/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=conficker-airbase-hospital-near-you</link>
		<comments>http://www.gfi.com/blog/conficker-airbase-hospital-near-you/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 08:45:32 +0000</pubDate>
		<dc:creator>Miro Stauder</dc:creator>
				<category><![CDATA[Tech Zone]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=4</guid>
		<description><![CDATA[Old news: Fighter jets grounded, base infected with Conficker! Recent news: Hospital equipment infected by Conficker worm! What? How can a supposedly secure environment like a military installation or a hospital catch a worm? Panic everywhere. Why is everyone so &#8230;]]></description>
			<content:encoded><![CDATA[<p>Old news: <a href="http://www.telegraph.co.uk/news/worldnews/europe/france/4547649/French-fighter-planes-grounded-by-computer-virus.html" target="_blank">Fighter jets grounded, base infected with Conficker!</a><br />
Recent news: <a href="http://news.cnet.com/8301-1009_3-10226448-83.html" target="_blank">Hospital equipment infected by Conficker worm!</a></p>
<p><strong>What?</strong> How can a supposedly secure environment like a military installation or a hospital catch a worm? <a href="http://www.wired.com/threatlevel/2009/03/will-conficker/" target="_blank">Panic everywhere</a>.</p>
<p><a class="lightbox" title="worm" href="http://www.gfi.com/blog/wp-content/uploads/2009/05/worm.png"><img class="alignright size-medium wp-image-98" style="margin: 10px;" title="Conficker worm" src="http://www.gfi.com/blog/wp-content/uploads/2009/05/worm-300x300.png" alt="" width="240" height="240" /></a>Why is everyone so scared of Conficker? The worm basically does nothing! It only tries to dig in and wait. According to a build in the timer something should have happened on April 1st 2009. April 1st came and went, and nothing happened. Everyone was expecting a doomsday scenario, where the worm was expected to do something horrific, but nothing happened apart from an update to a newer version, and more waiting for commands. So far there have been 5 versions of the worm observed, labelled as A, B, C, D and E. They seem to be modifications of the original, as the author tries to get things right and build a bigger bot army.</p>
<p><span id="more-4"></span>Only the latest version E was observed as actually doing something: send spam, and install scareware. Technically, it’s not Conficker itself that does this, it’s the payload that it downloads and executes on demand.</p>
<h2>So why is it so dangerous?</h2>
<p>The <strong>payload </strong>is the keyword. The infected machine is at the disposal of the attacker to do anything he wants. An unknown payload executed on demand could be anything from DOS attacks to extortion, spamming to spying. It also updates itself, to enhance its own capabilities, and plugs entry points to avoid infection from competing worms. Very flexible isn’t it? All this is secured by hash signatures and encryption.</p>
<h2>How does the thing actually spread?</h2>
<p>It spreads in two ways:</p>
<ul>
<li>Network</li>
<li>Removable Storage</li>
</ul>
<p>The worm tries to attack a known vulnerability in the DCE-RPC service running on port 445, also used for various services needed by Windows file sharing. A patch for this hole was released in October 2008 – MS08-067; regardless, the worm still succeeded in spreading. Another way of spreading is old fashioned copying. It places a copy of itself on removable storage, and uses the autorun feature for infection. Also worth mentioning is a dictionary attack on administrative network shares, but this might not have been a very successful infection vector, because it seems to be missing in the latest versions of the worm.</p>
<h2>How to spot the infection?</h2>
<p>Conficker uses a number of self defense mechanisms, which are a giveaway. It disables a number of services -  Automatic Update, Security Center, Defender and Error Reporting. It also creates its own service to stay resident. The name is constructed from two random words from titles of other services. Another type of self-defense employed is the <a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html" target="_blank">redirection of domain names</a> related to AV products and the Windows Update.</p>
<p>An infection can also be spotted using a professional product. Most AV vendors offer a stand alone tool to detect a Conficker infection. <a href="http://www.gfi.com/lannetscan">GFI LANguard 9</a> is also capable of detecting infected machines remotely as well as detecting missing patches regardless of infection. Once an infection is detected a removal tool should be employed and the systems should be patched to avoid repeated infection.</p>
<p>Back to the question, how can this worm spread into supposedly secure institutions? Well, the problem mostly lies in people &#8211; People who are naïve or who do not follow the security guidelines set by the organization.</p>
<ul>
<li><strong>Developers:</strong> Environment choices, running a whole Windows system on an embedded black box such as an MRI or a heart monitor might not be the best choice.</li>
<li><strong>Administrators:</strong> Not updating systems as required by choice; in some cases not being able to do it because of the black box nature of a system where only the vendor is allowed to update, thus leading to substantial delays in updating that might leave the system vulnerable.</li>
<li><strong>End users:</strong> Not following rules, and trying everything to work around restrictions.</li>
</ul>
<p>So, what can we expect to see of Conficker in the future? According to <a href="http://www.viruslist.com/en/weblog?weblogid=208187675" target="_blank">some research</a>, there are now only around 200,000 infected machines. However, this might be just the tip of the iceberg, because this includes only the latest version of the worm - version E.</p>
<p>Version E is set to <a href="http://www.securecomputing.net.au/News/142643,conficker-e-set-to-become-dormant-on-may-3.aspx" target="_blank">expire on 3rd May 2009</a>, but not the previous versions. Are all versions destined to eventually upgrade to E and retire? Did it serve its purpose? Is it going to be replaced by something else?</p>
<p>More questions than answers. The future will tell. The moral of the story so far – <strong>keep your systems updated</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gfi.com/blog/conficker-airbase-hospital-near-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

