<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>jim80.net &#187; conficker</title>
	<atom:link href="http://blog.jim80.net/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jim80.net</link>
	<description></description>
	<lastBuildDate>Mon, 16 Jan 2012 04:15:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Conficker Update Part 3</title>
		<link>http://blog.jim80.net/2009/06/12/conficker-update-part-3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=conficker-update-part-3</link>
		<comments>http://blog.jim80.net/2009/06/12/conficker-update-part-3/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 15:56:36 +0000</pubDate>
		<dc:creator>jim</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virii]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://blog.jim80.net/?p=231</guid>
		<description><![CDATA[According to http://forum.drweb.com/index.php?showtopic=277240 , Win32.HLLW.Shadow.based is a a variant of Conficker/downadup. Symptom: Every available port from 1024-5000 is used to connect to various servers on destination port 445. Basically, the worm opens these connections to download and wait for malicious binaries. The removal tools at http://www.bdtools.net/ does not detect this variant, and you have to [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://forum.drweb.com/index.php?showtopic=277240">http://forum.drweb.com/index.php?showtopic=277240</a> , Win32.HLLW.Shadow.based is a a variant of Conficker/downadup.</p>
<p><strong>Symptom:</strong> Every available port from 1024-5000 is used to connect to various servers on destination port 445. Basically, the worm opens these connections to download and wait for malicious binaries.</p>
<p>The removal tools at <a href="http://www.bdtools.net/">http://www.bdtools.net/</a> does not detect this variant, and you have to use Dr.Web&#8217;s <a href="ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe">Cureit</a> to detect and remove it. According to them, the recommended procedure is to install the following hotfixes:<br />
* MS08-067<br />
(<a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx">http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx</a>);</p>
<p>* MS08-068<br />
(<a href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx</a>);</p>
<p>* MS09-001<br />
(<a href="http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx</a>).</p>
<p>And then run <a href="ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe">Cureit</a>, a fully functional shareware app.</p>
<p>In case you&#8217;re reading this from an infected server, I&#8217;ve downloaded and included some of these files <a href="ftp://www.jim80.net/">here</a> (because if you&#8217;re infected, you won&#8217;t be able to access certain sites, drweb.com being one).</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.jim80.net/2009/06/12/conficker-update-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Update Part Deuce</title>
		<link>http://blog.jim80.net/2009/04/14/conficker-update-part-deuce/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=conficker-update-part-deuce</link>
		<comments>http://blog.jim80.net/2009/04/14/conficker-update-part-deuce/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 00:54:16 +0000</pubDate>
		<dc:creator>jim</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virii]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://blog.jim80.net/?p=188</guid>
		<description><![CDATA[UPDATE 11 Jun 2009: Locally hosted bdtools removal tools (availabe at downadup.org for single computers and network. Cheers =D Our favorite worm got an update 8 April according to Network World. Read more here&#8230; And of course, at downadup.org.]]></description>
			<content:encoded><![CDATA[<p>UPDATE 11 Jun 2009: Locally hosted bdtools removal tools (availabe at <a href="http://downadup.org">downadup.org</a> for <a href='ftp://www.jim80.net/bdtools.net/'>single computers and network</a>. Cheers =D</p>
<p>Our favorite worm got an update 8 April according to Network World. Read more <a href="http://www.networkworld.com/news/2009/041009-conficker-awakens-starts.html?ts0hb&amp;story=ts_confkr">here&#8230;</a><br />
And of course, at <a href="http://downadup.org">downadup.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.jim80.net/2009/04/14/conficker-update-part-deuce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Update</title>
		<link>http://blog.jim80.net/2009/04/01/conficker-update/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=conficker-update</link>
		<comments>http://blog.jim80.net/2009/04/01/conficker-update/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 15:13:35 +0000</pubDate>
		<dc:creator>jim</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[PPP]]></category>

		<guid isPermaLink="false">http://blog.jim80.net/?p=115</guid>
		<description><![CDATA[Update: An excellent resource list is available at the Internet Storm Center. The headline at dailymail.co.uk read &#8220;April Fool&#8217;s Day computer virus is activated&#8230; but fails to cause internet chaos.&#8221; I guess the rumors were unfounded. However, it&#8217;s important to note that the virus is still rampant and speculation on the potential uses of such [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><em>Update: An excellent resource list is available at the <a href="http://www.dshield.org/conficker">Internet Storm Center</a>.</em></p>
<address style="text-align: center;"> </address>
<p>The headline at <a href="http://www.dailymail.co.uk/sciencetech/article-1166077/April-Fools-Day-virus-activated--fails-cause-internet-chaos.html" target="_blank">dailymail.co.uk</a> read &#8220;April Fool&#8217;s Day computer virus is activated&#8230; but fails to cause internet chaos.&#8221;</p>
<p>I guess the rumors were unfounded. However, it&#8217;s important to note that the virus is still rampant and speculation on the potential uses of such a huge botnet are as well. Some surmise that it might be used to DDOS the crap out of some poor server(s). It might also be used to crack passwords or encryption. Check out <a href="http://downadup.org/">http://downadup.org</a> to read more and for removal tools. It&#8217;s also a good idea to prepare your network for the potentiality of attack. Don&#8217;t be a soft target.</p>
<p>Here&#8217;s a couple (read non-comprehensive) ideas on how to not be a soft target:</p>
<ul>
<li>Backup, backup, backup
<ul>
<li>Have systems ready to leap into action if necessary, and keep at least one form of backup offline in case of <a href="http://blog.jim80.net/2009/03/24/webhostingtalk-hacked-hardcore-but-still-online/" target="_self">worst-case scenarios</a>.</li>
<li>If you don&#8217;t already have a backup strategy in place, it&#8217;s time to implement one.</li>
</ul>
</li>
<li>Control access to your critical services
<ul>
<li>Enforce strong passwords &#8211; or better yet, employ multi-factor authentication. <a href="http://blog.jim80.net/2009/03/15/multi-factor-authentication-for-cheap/" target="_self">PPP</a> is a strong candidate for the thrifty.</li>
<li>Audit your users &#8211; does that guy who quit last year still have an active user account? Do your non-administrative users have access to critical servers?</li>
<li>Use fail2ban or iptables to detect and drop password-guessing attacks &#8211; even with 10 million + IP&#8217;s to choose from, it&#8217;s not easy to crack a password/one-time password combination when you only get 3 tries per IP.</li>
</ul>
</li>
<li>Watch your traffic (not really a botnet vulnerability, but good practice in general):
<ul>
<li>Control your legacy services &#8211; seriously, it&#8217;s time to retire <a href="http://www.milw0rm.com/exploits/8055">telnet</a> and other services that transmit passwords in cleartext.</li>
<li>https &gt; http &#8211; especially when it comes to passwords. Don&#8217;t allow users the ability to transmit passwords over http.</li>
</ul>
</li>
<li>etc&#8230;</li>
</ul>
<p>I&#8217;ve hardly compiled a comprehensive list, and I welcome comments for other good practices, but the most important takeaway is to be cognizant of your security stance. Don&#8217;t make it easy for the bad guys.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.jim80.net/2009/04/01/conficker-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

