[113042] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

The Confiker Virus hype and measures

daemon@ATHENA.MIT.EDU (Gadi Evron)
Mon Mar 30 08:51:06 2009

Date: Mon, 30 Mar 2009 15:43:53 +0300
From: Gadi Evron <ge@linuxbox.org>
To: Joe Blanchard <jbfixurpc@gmail.com>
In-Reply-To: <002d01c9b0c8$2382eb20$0101a8c0@E520>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

Joe Blanchard wrote:
> Anyone have a copy of this? Would like to analyze it and understand its
> propagation.
> 
> Thanks
> -Joe

I'm sure someone sent you a sample by now. As to the malware itself...

I haven't personally been following conficker as I've been busy with 
other issues (as much as possible, anyway, with all the hype it's hard 
to escape), but I've been asking questions. I can try and speak on the 
matter from what I've learned by asking.

Conficker is a real problem, but will the world end on April Fools?

The answer I gather to be the most accurate is:
"The conficker threat will be exactly the same as it is today, on April 
1st."

Perhaps putting a date on the threat makes people feel more comfortable. 
What if something happens on April 3rd? Whether we would be warned or 
not, we'll all likely ignore it if April 1st comes and goes quietly.

As to the unknown, the author's mind, who can really tell what they will 
do come the 1st?

But some of the hype I've seen is truly ridiculous. I am sure some of 
the protected hosting companies sold quite a bit with their "we defend 
against conficker" products.

Is conficker a problem? Yes. Can we potentially face hardship on the 
1xt? Yes. Is the rest complete bull? Yes.

	Gadi.


home help back first fref pref prev next nref lref last post