[113045] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: The Confiker Virus.

daemon@ATHENA.MIT.EDU (Paul Ferguson)
Mon Mar 30 13:29:26 2009

In-Reply-To: <000001c9b0cc$c6126100$52372300$@com>
Date: Mon, 30 Mar 2009 10:27:15 -0700
From: Paul Ferguson <fergdawgster@gmail.com>
To: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun, Mar 29, 2009 at 5:16 PM, Richard Golodner
<rgolodner@infratection.com> wrote:

>
>        Joe said earlier today:
>> Thanks, the only thing is that these, like most, websites are very vague
> about the mechanics behind the infiltration
>
>        Joe, the SRI report would be right up your alley as it is the most
> technical in its analysis of the variants A and B as well as an
> explanation of the algorithm it uses to determine domain names for future
> use of some kind.
>
> http://mtc.sri.com/Conficker/
>

Something folks might be interested in -- a way to detect
Conficker-infected hosts in your network:

https://www.honeynet.org/node/389

FYI,

- - ferg


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFJ0QDjq1pz9mNUZTMRAm7SAJ9MZo33Vok1uvyB4H7DML1gUKRlPQCggWtC
bL4g6kI0sc75IDu/fYzv8yI=
=HpOH
-----END PGP SIGNATURE-----


-- 
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawgster(at)gmail.com
 ferg's tech blog: http://fergdawg.blogspot.com/


home help back first fref pref prev next nref lref last post