Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
4/1/2009 3:06:19 AM EDT


Good information on what it is – and how it spreads:









Removal tool – (should you need it)









There are many website out there claiming to have a tool for conficker. Be careful! Please download only trusted known providers such as Symantec, homeland security or e-eye. Here are some more tool links:









http://www.eeye.com/html/downloads/other/ConfickerScanner.html
I see a nice write up on the free OpenDNS service about conficker and blocking all variants and phone home sites.











I looked on SonicWall’s site – and found this:





https://www.mysonicwall.com/SonicAlert/index.asp?ev=article&id=116
Look at Cisco’s very informative security center report on Conficker: (They do have IPS signatures to prevent this – but only available on ASA5510 and higher models with IPS module)











They are “Professional Grade”







See the difference? Look at the level of detail and info….



Bits of write up from Cisco:



The worm starts an HTTP server by opening a randomly chosen port between 1024 and 10000 and listens for incoming connections. The worm accomplishes this by using APIs to bypass the Windows Firewall. The worm also terminates the Internet connection sharing service.



This is why it is important to block all outgoing ports on firewall – and only allow the necessary ones.



Good luck










4/1/2009 5:14:37 AM EDT
[#1]
Thanks.  I saved the links to a doc just in case.
4/1/2009 5:23:27 AM EDT
[#2]
What time is it supposed to strike if it actually does anything?
4/1/2009 6:14:10 AM EDT
[#3]
Thanks for the info,  tough to weed through all the joke stuff today.
4/1/2009 6:16:17 AM EDT
[#4]
The patch was out in October. More bandwidth is used by people downloading detection tools (see nmap - their 100mb connection was saturated yesterday!) than by conficker.





Yes, there are plenty of infected machines but this is more hype than anything.



Nmap scanner http://insecure.org/

Patch from Microsoft http://technet.microsoft.com/en-us/security/dd452420.aspx




 
4/1/2009 6:17:13 AM EDT
[#5]
TAG
4/1/2009 6:20:13 AM EDT
[#6]
I'll put my tinfoil hat on and say there is no way I am going to download a "tool" from Homeland Security.

I got mine from Malewarebytes, which is probably the best out there.

Eric  
4/1/2009 6:32:09 AM EDT
[#7]
McAfee Stinger is also a good app for removal.
4/1/2009 6:41:24 AM EDT
[#8]
Very Thoughtful, thanks.
4/1/2009 6:42:54 AM EDT
[#9]
Thanks for the info. Tagged just in case its needed.
4/1/2009 6:57:03 AM EDT
[#10]



Quoted:


What time is it supposed to strike if it actually does anything?


if you have to ask, it is already too late










 
4/1/2009 7:01:02 AM EDT
[#11]
posted a thread in team yesterday to avoid the "april fools" stuff, but thanks, the more people who know, the fewer potential bots there are
4/14/2009 6:17:20 AM EDT
[#12]
http://www.baylor.edu/its/security/conficker/