Vulnerabilities / Threats
3/27/2009
02:07 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Conficker Worm Worries Exaggerated

The worm, which attempts to exploit a Microsoft vulnerability that was patched last October, has been evolving.

In a rare case of calm-mongering, computer security companies are offering reassurance that the world won't end on April 1.

That's when the Conficker/Downadup worm is supposed to get a code update that could make it even more difficult to control.

Since January, when the number of computers affected by the worm jumped from 2.4 million to 8.9 million in just four days, people have been understandably concerned about the botnet being built through Conficker infections. The worm has made enough of a splash to prompt a coordinated industry response and a $250,000 bounty from Microsoft for information leading to the capture of those responsible.

The worm, which attempts to exploit a Microsoft vulnerability that was patched (MS08-067) last October, has been evolving with the help of its creator or creators. Now in its fourth iteration, it has developed multiple avenues of infection, including USB devices. It also uses a variety of sophisticated techniques to evade detection and to maintain its command-and-control channel, including a pseudo-random algorithm for generating the domains it uses to receive commands.

The worm previous polled 250 domains daily for updates. On April 1, security researchers who have analyzed its code say it will start scanning 500 out of 50,000 domains for updates.

In a list of frequently asked questions posted to the blog of security company F-Secure, Mikko Hypponen, the company's chief research officer, says nothing really bad is going to happen on April 1 because of the worm. Most infected machines, he says, are variant B, which won't get updated in April. He adds that Windows users who have made sure their systems have been scanned, and Mac users (who are unaffected), have nothing to worry about.

Luis Corrons, director of PandaLabs, urges people not to get taken in by the panic.

"The infection level of the previous weeks has been reducing to low levels," he said in a blog post. "There [is] probably still malware infecting PCs but not at the levels we were seeing in the previous months."

F-Secure said that between 1 million and 2 million computers are actively infected. Those who think their computer might be among those compromised may wish to run either F-Secure Easy Clean or Panda ActiveScan, both of which recognize Conficker infections.


2009 marks the 12th year that InformationWeek will be monitoring changes in security practices through our annual research survey. Find out more and take part.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7392
Published: 2014-07-22
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

CVE-2014-2385
Published: 2014-07-22
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter t...

CVE-2014-3518
Published: 2014-07-22
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to exec...

CVE-2014-3530
Published: 2014-07-22
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via...

CVE-2014-4326
Published: 2014-07-22
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.