Beware: Conficker C!

Discussion in 'Archives' started by Benwise, Mar 25, 2009.

Thread Status:
Not open for further replies.
Beware: Conficker C!
  1. Unread #21 - Mar 30, 2009 at 11:24 PM
  2. yanti
    Joined:
    Sep 4, 2005
    Posts:
    56
    Referrals:
    0
    Sythe Gold:
    0

    yanti Member

    Beware: Conficker C!

    Taken from http://www.honeynet.org/papers/conficker

    Our "Know Your Enemy: Containing Conficker" whitepaper was released on March 30th as a PDF only. You can download the full paper from the link below.

    Paper Abstract

    The Conficker worm has infected several million computers since it first started spreading in late 2008 but attempts to mitigate Conficker have not yet proved very successful. In this paper we present several potential methods to contain Conficker. The approaches presented take advantage of the way Conficker patches infected systems, which can be used to remotely detect a compromised system. Furthermore, we demonstrate various methods to detect and remove Conficker locally and a potential vaccination tool is presented. Finally, the domainname generation mechanism for all three Conficker variants is discussed in detail and an overview of the potential for upcoming domain collisions in version .C is provided. Tools for all the ideas presented here are freely available for download including source code.

    In addition, as a result of this paper and the hard work of Dan Kaminsky, most vulnerability scanning tools (including Nmap) should now have a plugin or signatures that allow you to remotely detect infected Conficker systems on your networks. Finally, we would like to recognize and thank the tremendous help and input of the Conficker Working Group.

    Paper last updated March 30th 2009, 23:00 GMT (rev1)
    PDF MD5sum = 135ba75c33534327eb2800e98c8077e8 (KYE-Conficker.pdf)

    Attachment Size
    http://www.honeynet.org/files/KYE-Conficker.pdf 700.04 KB


    More information about how it operates and about how you can disinfect your machine can be found at http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/ This site provides info on the different techniques it uses to spread and how to use said techniques against it to detect it on your system and remove it.
     
  3. Unread #22 - Mar 30, 2009 at 11:32 PM
  4. redjazz96
    Joined:
    Mar 30, 2009
    Posts:
    9
    Referrals:
    0
    Sythe Gold:
    0

    redjazz96 Newcomer

    Beware: Conficker C!

    i remember reading something about that on Yahoo, but they said the program would go out on April 1st. So baically, i had no idea that it was out right now. I was warning people of it, but they didn't believe me.
     
  5. Unread #23 - Mar 30, 2009 at 11:41 PM
  6. Daily
    Joined:
    May 6, 2005
    Posts:
    4,425
    Referrals:
    18
    Sythe Gold:
    5

    Daily BANNED FROM MARKET
    Banned

    Beware: Conficker C!

  7. Unread #24 - Mar 30, 2009 at 11:42 PM
  8. Tgump
    Joined:
    Jan 21, 2007
    Posts:
    6,541
    Referrals:
    8
    Sythe Gold:
    0
    Two Factor Authentication User

    Tgump Hero
    Retired Global Moderator Zombie

    Beware: Conficker C!

    It would be so awesome if they redirected some top website to a shock site.
     
  9. Unread #25 - Mar 31, 2009 at 1:01 AM
  10. yanti
    Joined:
    Sep 4, 2005
    Posts:
    56
    Referrals:
    0
    Sythe Gold:
    0

    yanti Member

    Beware: Conficker C!

    Oh yeah! "That's a very interesting question timmy, let me just google the ans... OMG!! TIMMY LOOK AWAY!! LOOK AWAY!!"
     
  11. Unread #26 - Mar 31, 2009 at 1:11 AM
  12. cp
    Joined:
    Jan 30, 2007
    Posts:
    3,278
    Referrals:
    6
    Sythe Gold:
    0

    cp an cat
    Banned

    Beware: Conficker C!

    We can only hope it'll be that harmless. :)
     
  13. Unread #27 - Mar 31, 2009 at 10:54 AM
  14. brainss
    Joined:
    Jan 28, 2009
    Posts:
    128
    Referrals:
    1
    Sythe Gold:
    0

    brainss Active Member

    Beware: Conficker C!

    i am not sure i understand. how would your computer get the virus?
     
  15. Unread #28 - Mar 31, 2009 at 1:55 PM
  16. Wedel
    Joined:
    Mar 30, 2009
    Posts:
    1,063
    Referrals:
    1
    Sythe Gold:
    0

    Wedel Guru
    Banned

    Beware: Conficker C!

    I don't get it ? What does it do..
     
  17. Unread #29 - Mar 31, 2009 at 2:14 PM
  18. WinterDreamZ4
    Joined:
    Nov 8, 2007
    Posts:
    697
    Referrals:
    0
    Sythe Gold:
    0

    WinterDreamZ4 Apprentice
    Banned

    Beware: Conficker C!

    They don't know...
     
  19. Unread #30 - Mar 31, 2009 at 6:14 PM
  20. Skele
    Joined:
    Nov 4, 2007
    Posts:
    12,216
    Referrals:
    12
    Sythe Gold:
    0
    Tier 1 Prizebox

    Skele Heartbreak Kid
    $100 USD Donor Crabby Retired Global Moderator

    Beware: Conficker C!

    I guess we'll find out tomorrow, for anyone thats taking the chance.
     
  21. Unread #31 - Mar 31, 2009 at 6:38 PM
  22. SwiftSeller
    Joined:
    Jun 21, 2008
    Posts:
    2,461
    Referrals:
    0
    Sythe Gold:
    0

    SwiftSeller Grand Master
    Banned

  23. Unread #32 - Mar 31, 2009 at 6:41 PM
  24. WinterDreamZ4
    Joined:
    Nov 8, 2007
    Posts:
    697
    Referrals:
    0
    Sythe Gold:
    0

    WinterDreamZ4 Apprentice
    Banned

    Beware: Conficker C!

    Thank you for posting this...it has only been posted 100 times.
    Just 5 posts below for an example.
     
  25. Unread #33 - Mar 31, 2009 at 6:55 PM
  26. Jordan
    Joined:
    Nov 5, 2005
    Posts:
    798
    Referrals:
    25
    Sythe Gold:
    45

    Jordan Apprentice
    Banned

    Beware: Conficker C!

    Been on the News, and many articles. Anyways it's better warning others than to see them fade.
     
  27. Unread #34 - Apr 1, 2009 at 3:00 AM
  28. Damien0124
    Joined:
    Apr 30, 2006
    Posts:
    1,851
    Referrals:
    1
    Sythe Gold:
    0

    Damien0124 Guru
    Banned

    Beware: Conficker C!

    I saw it on the news this morning, I wonder what will happen today.
     
  29. Unread #35 - Apr 1, 2009 at 3:04 AM
  30. Cheese ftw
    Joined:
    Mar 27, 2009
    Posts:
    824
    Referrals:
    0
    Sythe Gold:
    0

    Cheese ftw Apprentice
    Banned

    Beware: Conficker C!

    Well it\s almost the end of april fools for me.
    Nothing happened to my computer :p
     
  31. Unread #36 - Apr 1, 2009 at 3:33 AM
  32. Costantino
    Joined:
    Feb 21, 2009
    Posts:
    66
    Referrals:
    0
    Sythe Gold:
    0

    Costantino Member
    Banned

    Beware: Conficker C!

    The best way to stop this infection is either to turn off internet, although this will not fully protect you, but a top quality virus scanner / internet protection program (Kapersky internet security) or just not have a computer, problem solved.
     
  33. Unread #37 - Apr 1, 2009 at 6:49 AM
  34. cp
    Joined:
    Jan 30, 2007
    Posts:
    3,278
    Referrals:
    6
    Sythe Gold:
    0

    cp an cat
    Banned

  35. Unread #38 - Apr 1, 2009 at 9:04 AM
  36. brainss
    Joined:
    Jan 28, 2009
    Posts:
    128
    Referrals:
    1
    Sythe Gold:
    0

    brainss Active Member

    Beware: Conficker C!

    so its an april fools joke? or has anything happened?
     
  37. Unread #39 - Apr 1, 2009 at 10:43 AM
  38. ignys5
    Joined:
    Apr 1, 2009
    Posts:
    1
    Referrals:
    0
    Sythe Gold:
    0

    ignys5 Newcomer

    Beware: Conficker C!

  39. Unread #40 - Apr 1, 2009 at 11:40 AM
  40. brainss
    Joined:
    Jan 28, 2009
    Posts:
    128
    Referrals:
    1
    Sythe Gold:
    0

    brainss Active Member

    Beware: Conficker C!

< Selling Karil | Just Plain Leg - False Accusation.. >

Users viewing this thread
1 guest
Thread Status:
Not open for further replies.


 
 
Adblock breaks this site