Perimeter

Guest Blog // Selected Security Content Provided By Sophos
What's This?
4/1/2009
01:20 AM
Graham Cluley
Graham Cluley
Security Insights
50%
50%

All's Quiet On The Conficker Front

It's 6:30 a.m. on April Fool's Day here in the U.K., and so far we've not seen any evidence of the Conficker worm "melting your computer," turning off the nation's air defenses, or dialing the local pizza company. My guess is that -- as widely predicted by the security vendors -- Conficker and April 1st was mostly abou

It's 6:30 a.m. on April Fool's Day here in the U.K., and so far we've not seen any evidence of the Conficker worm "melting your computer," turning off the nation's air defenses, or dialing the local pizza company. My guess is that -- as widely predicted by the security vendors -- Conficker and April 1st was mostly about hype rather than havoc.Nevertheless, Conficker remains out there on a lot of computers. If you haven't already done so, download one of the free Conficker removal tools available from your favorite security vendor. (Be careful that you get it from a legitimate site because some hackers are taking advantage of the pandemonium to hide their malware as an anti-Conficker.)

In addition, use this opportunity to review your security in other ways, too. For instance, do you have the latest security patches in place? Have you implemented a policy to control the use of USB drives, or at least prevented AutoRun from allowing code to automatically execute when USB drives are inserted in Windows? Have you toughened your passwords, and made sure that users aren't using dictionary words or dumb numerical sequences?

If you're smart, then you can turn Conficker day into a day to better secure your computer systems for the future.

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website you can find him on Twitter at @gcluley. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Now about that mortgage refinance offer from Wells Fargo .....
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7097
PUBLISHED: 2018-08-14
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow cross-site request forgery.
CVE-2018-7098
PUBLISHED: 2018-08-14
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.
CVE-2018-7099
PUBLISHED: 2018-08-14
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.
CVE-2018-7100
PUBLISHED: 2018-08-14
A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allow local disclosure of sensitive information.
CVE-2018-7077
PUBLISHED: 2018-08-14
A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive information.