Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow Conficker
EH-Net
May 19, 2013, 03:16:18 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Conficker  (Read 15521 times)
0 Members and 1 Guest are viewing this topic.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« on: March 27, 2009, 08:39:06 PM »

I'm surprised there isn't a discussion on this yet (aside from the one there was a while ago) in light of the stuff about April 1.

Here are a few good links I saw come across the GIAC list that had some pretty good information:

Q&A: http://www.f-secure.com/weblog/archives/00001636.html

Detailed Analysis: http://mtc.sri.com/Conficker/addendumC/

Detection: http://blog.commandlinekungfu.com/2009/03/episode-16-got-that-patch.html

Everyone all patched up? Taking any other precautions? I might just un-plug my network at home for the day just to stay on the safe side in case some crazy ends up happening, lol. Fortunately (or boringly? Is that a word?) in my current/new role for work, I don't really have much to do on this Undecided

BillV
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #1 on: March 30, 2009, 07:04:37 AM »

Bill,

good post, I had seen the others, but had not looked at Pauls command line Fu page.
Thats probably a useful little command for the home user, who doesnt have enterprise management tooling.

I personally dont think much is going to happen. Obviously if your infected and not patched already your at the same risk level, if not I cant see a mass infection spread happening.

Time will tell I guess, I am sure the media will provide some entertainment.
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #2 on: March 30, 2009, 07:09:30 AM »

Speaking of the media...  from last night's 60 minutes:

http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053.shtml
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #3 on: March 30, 2009, 07:34:35 AM »

I just found out Nessus and NMAP should have updated definitions to identify the Conficker signature to identify infected machines.

So I am going to setup a machine to do some scanning.

I have not had a proper look, but I assume its going to be something like :

« Last Edit: March 30, 2009, 07:39:50 AM by dalepearson » Logged

crk
Newbie
*
Offline Offline

Posts: 49


View Profile
« Reply #4 on: March 30, 2009, 10:51:02 AM »

I really don't think it'll be a big deal at all. I think that at this point so many people have gone to such lengths to secure their networks that whatever's gonna happen won't even be worth mentioning.

However, just to be sure, my systems are fully patched Grin
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #5 on: March 30, 2009, 12:17:50 PM »

dale, I saw that too about nmap/nessus/et al.

Here's the link to some useful tools.

Hats off to the guys at The Honeynet Project! Smiley

BillV
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #6 on: March 30, 2009, 01:59:28 PM »

For those of you interested, Fyodor should be posting an NMAP update in the next few hours so keep a look out http://seclists.org/nmap-dev/2009/q1/index.html

If you want to do some manual tweaking, there is some availability here http://www.skullsecurity.org/blog/?p=209
Logged

dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #7 on: March 31, 2009, 03:41:45 AM »

Guys,

just so you know NMAP has been updated:

Nmap 4.85BETA5

o Ron (in just a few hours of furious coding) added remote detection
  of the Conficker worm to smb-check-vulns. It is based on new
  research by Tillmann Werner and Felix Leder.  You can scan your
  network for Conficker with a command like: nmap -PN -T4 -p139,445 -n
  -v --script=smb-check-vulns --script-args safe=1 [targetnetworks]

http://nmap.org/download.html
Logged

Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #8 on: March 31, 2009, 04:04:29 AM »

I have these and a few others posted here on my site:

http://www.securityaegis.com/?p=262

lets see what happens tomorrow :/
Logged

dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #9 on: March 31, 2009, 09:21:49 AM »

Anyone know how to specify a txt file of IPs to work with this Simple Conficker Scanner?

I seem to get better results out of this than with NMAP, so wanted to do some validation, but obviously dont want to do a single IP at a time.
Logged

dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #10 on: March 31, 2009, 09:30:55 AM »

Anyone know how to specify a txt file of IPs to work with this Simple Conficker Scanner?

I seem to get better results out of this than with NMAP, so wanted to do some validation, but obviously dont want to do a single IP at a time.

Using the scanner you can download from here, this is possible.
http://www.doxpara.com/scs2.zip

I have tested this and it seems to be running fine. Hope it helps someone.
Logged

ethicalhack3r
Full Member
***
Offline Offline

Posts: 139


View Profile WWW
« Reply #11 on: March 31, 2009, 03:47:05 PM »

What timezone is conflicker set to?
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #12 on: March 31, 2009, 06:47:05 PM »

Hmm, well I thought part of it syncs with UTC, which will be April 1 in about 15 minutes...

but this article makes it seem like it depends on the local system time:

Conficker worm wakes up overseas, but its quiet.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #13 on: March 31, 2009, 06:49:01 PM »

Also, ISC has some info up and seems to be following...

Quote
There are also several reports of malicious software masquerading as detection and cleaning tools for Conficker-infected computers.

Figured that was coming soon...
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #14 on: April 01, 2009, 03:41:13 AM »

All quite from here, the intertubes are still working and the sky hasn't fallen.

Anyone seen anything or has it passed by as a non-event?
Logged

Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.081 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.