Posts tagged as:

Conficker

Cybersecurity: Network Threats and Policy Challenges
Hearings -Subcommittee on Communications, Technology, and the Internet
May 01, 2009

Witness List

  • Greg Nojeim, Senior Counsel, Center for Democracy and Technology
  • Dan Kaminsky, Director of Penetration Testing, IOActive
  • Larry Clinton, President and CEO, Internet Security Alliance
  • Rodney L. Joffe, Senior Vice President and Senior Technologist, Neustar

Rodney Joffe, is also a founder of the unofficial Conficker Working Group

I have identified at least 300 critical medical devices from a single manufacturer that have been infected with Conficker. These devices are used in large hospitals, and allow doctors to view and manipulate high-intensity scans (MRI, CT Scans etc), and are often found in or near ICU facilities, connected to local area networks that include other critical medical devices.

After the manufacturer and hospitals were notified, government regulations prevented hospital staff from fixing the systems for a period of 90 days.

Testimony of Rodney L. Joffe (PDF)

{ 0 comments }

Conficker active, updates via P2P

by certifiedbug on April 9, 2009

in Internet Security

Various reports say the Conficker botnet has received a binary file via a known Conficker P2P IP node hosted in Korea.

Story at CNet: http://news.cnet.com/8301-1009_3-10215678-83.html

http://certifiedbug.com/blog/tag/conficker/

Update

This latest Conficker variant self-terminates on May 3, 2009.
http://www.microsoft.com/security/portal/Entry.aspx?name=Worm:Win32/Conficker.E

Is There a Conficker E? Waledac makes a move…

{ 0 comments }

Conficker Working Group Wiki

April 3, 2009

Added link to Bookmarks:
http://www.confickerworkinggroup.org/wiki/
F-Secure:
Post April 1st Conficker Q&A

Read the full article →

Media whips users into Conficker frenzy

March 31, 2009

With April 1st around the corner sensational Conficker “journalism” is rampant in the media.
Better to be informed by reliable security researchers, Please, the world is NOT ending on April 1 and Microsoft, Protect yourself from the Conficker computer worm
Ed Bott: McAfee fails the Conficker test
Update
F-Secure: Conficker’s domain routine has already started
http://certifiedbug.com/blog/tag/conficker/

Read the full article →

Conficker -April 1st distraction

March 27, 2009

60 Minutes airs a report Sunday, March 29, 2009 on Conficker, entitled “The Internet is Infected” with CBS reporter Lesley Stahl. Preview
“The best that the experts tell us that we can do is just buy security software, anti virus, anti worm software and just make sure it receives the update instructions,” said Stahl.
Presentation [...]

Read the full article →

Battling the Conficker Botnet

March 23, 2009

Worth reading.
The New York Times
Computer Experts Unite to Hunt Worm
SRI International Technical Report
An Analysis of Conficker’s Logic and Rendezvous Points
Conficker C Analysis
http://certifiedbug.com/blog/tag/conficker/

Read the full article →

Grab bag

March 13, 2009

Anti-Social Networking
Differences between IE8 Compatibility View and IE7
Completing the Windows Experience with Windows Live
TinyURL usage becoming more common in Phishing and IM Attacks – Harry Waldron – Corporate and Home Security
Conficker.C variant set for April 1st surprise, CA says
Security Updates available for Adobe Reader 9 and Acrobat 9
Foxit version 3.0 fixes serious vulnerabilities in its [...]

Read the full article →

Conficker Zombies

February 23, 2009

Hostexploit.com
If you are reading this article on a MS widows based PC and you have not upgraded your XP or Vista operating system since October 2008, there is a reasonable chance you are a zombie, or rather your PC is.
Before we see the regular smirks and responses from Mac and Linux users, stressing how safe [...]

Read the full article →

Microsoft – $250k bounty for Conficker author

February 12, 2009

Microsoft PressPass
Microsoft Collaborates With Industry to Disrupt Conficker Worm
REDMOND, Wash. — Feb. 12, 2009 — Today, Microsoft Corp. announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the Conficker (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the [...]

Read the full article →

Conflicker grounded French fighter planes

February 9, 2009

According to reports, the French military ignored Microsoft’s Security Bulletin MS08-067 Critical Update ‘out of cycle’ warning and failed to install the necessary security measures, resulting in French fighter planes unable to take off after military computers were infected by “Conficker”.
http://certifiedbug.com/blog/tag/conficker/
Naval officials said it suspected someone at the navy had used an infected USB key. [...]

Read the full article →