<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Teh Tech &#187; MS08-067</title>
	<atom:link href="http://tehtech.com/tag/ms08-067/feed/" rel="self" type="application/rss+xml" />
	<link>http://tehtech.com</link>
	<description>Being an Admin is Hard Enough</description>
	<lastBuildDate>Wed, 14 Jul 2010 16:14:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Conficker; What is it? How to Prevent and clean It.</title>
		<link>http://tehtech.com/conficker-what-is-it-how-to-prevent-and-clean-it/</link>
		<comments>http://tehtech.com/conficker-what-is-it-how-to-prevent-and-clean-it/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 17:12:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Conflicker]]></category>
		<category><![CDATA[MS08-067]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Windows update]]></category>

		<guid isPermaLink="false">http://tehtech.com/?p=262</guid>
		<description><![CDATA[What is it?: Conflicker is a virus that has been spreadingÂ  for about 2 months infecting an estimated 15-20 million computers worldwide. Â Systems running windows 2000, server 2000, windows XP (all variations), Vista (all variations), server 2003, server 2008 and even windows 7 areÂ susceptible. Â TheÂ detailsÂ of what exactly the virus does are a bit sketchyÂ becauseÂ of the [...]]]></description>
			<content:encoded><![CDATA[<p>What is it?: Conflicker is a virus that has been spreadingÂ  for about 2 months infecting an estimated 15-20 million computers worldwide. Â Systems running windows 2000, server 2000, windows XP (all variations), Vista (all variations), server 2003, server 2008 and even windows 7 areÂ susceptible. Â TheÂ detailsÂ of what exactly the virus does are a bit sketchyÂ becauseÂ of the way the virus is created. Â At this time it appears that the virus isÂ dormantÂ in the computer and waiting to download theÂ remainderÂ of its payload code Â on April 1st.Â  Right nowÂ it isÂ presumed that the worm spreads itsself through the RPC service and through http, network shares, USB and removable media, and even FTP. Â The worm has the ability to modify open port exceptions on windows firewall as well as theÂ abilityÂ to stop svchost.exe, services.exe, and explorer.exe. Â It has a built in P2P application so that the virus can bothÂ communicateÂ code betweenÂ each otherÂ andÂ web serversÂ andÂ coordinate. Â This is where the fear of Â fastÂ changingÂ polymorphic code comes from as well as the ability of the virus to use host computers in a zombie like fashion to attack other computers or servers. Â </p>
<p>Symptoms of the virus are expected to include and have been confirmed to include:</p>
<ul>
<li>ServicesÂ disablingÂ on their own. Namely windows defender, BITS, windows firewall, and some third party antivirus services such as live update.</li>
<li>Massive increase in network traffic. Â Up to a 10-15% increase in total network traffic isÂ expectedÂ on infected networks. This is due to attacks on shares and accounts, as well as spreading of the virus and payload.</li>
<li>Account lockouts reset. Â If the virus is on a DC it will dictionary attack the adminÂ accountÂ and admin shares, if the account locks out, it will automatically reset the lockout.</li>
<li>Lastly some or all AV websites, security websites, and windows update sites areÂ inaccessible. Â they reply to ping and answer to telnet on port 80, but they are notÂ accessibleÂ to any browser. Â This appears to be done through a virtual proxy system.</li>
</ul>
<p><span id="more-262"></span><br />
Microsoft has teamed up with ICANN, AOL, Symantec and other big names in computer security and networkÂ technologiesÂ to attempt to curtail the infestation of the virus. Â A $250,000 reward isÂ availableÂ for anyone that can provide information leading to the arrest of the coder. Â <br />
<script type="text/javascript"><!--
google_ad_client = "pub-2740910196434334";
google_ad_slot = "5492961778";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
Microsoft released a patchÂ MS08-067 on october 15th 2008, that fixes this exploitÂ however,Â it is estimated thatÂ aboutÂ 30% of computers do not have this patch installed. Â This patch isÂ availableÂ fromÂ MicrosoftÂ <a title="MS08-067" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" onclick="pageTracker._trackPageview('/outgoing/www.microsoft.com/technet/security/Bulletin/MS08-067.mspx?referer=');">HERE</a>. Â The patch isÂ availableÂ for windows 2000 sp4 &#8211; windows server 2008 with the exception of windows xp service pack 1 (service pack one has reached its end of support). Â Windows 7 has the patch integrated in it already. Â Many antivirus makers are releasing removal tools for the virus already. Â Microsoft has a removal toolÂ availableÂ <a title="Conflicker and malware cleaner from microsoft" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en" onclick="pageTracker._trackPageview('/outgoing/www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356_amp_displaylang=en&amp;referer=');">HERE</a>. Â And bit defender has a network/domain removal tool <a title="bdtool" href="http://www.bdtools.net/" onclick="pageTracker._trackPageview('/outgoing/www.bdtools.net/?referer=');">HERE</a>.</p>
<p>What you can do to limit and prevent conflicker spread as a network administrator.</p>
<ul>
<li>Follow best practice passwords. Â Require password that include specialÂ charactersÂ and are at least 6Â characters long. Â This makes brute forcing the password very difficult. Â </li>
<li>Turn off all unnecessary network shares. Â Any computer on the network that has a opened share is aÂ vulnerability. Check <a title="EnumShare" href="http://technet.microsoft.com/en-us/sysinternals/bb897442.aspx" onclick="pageTracker._trackPageview('/outgoing/technet.microsoft.com/en-us/sysinternals/bb897442.aspx?referer=');">this</a> out to discover shares.</li>
<li>Turn off auto run. Â You don&#8217;t need it in most cases. Â Turn it off, it allows for theÂ potentialÂ executionÂ of code.</li>
<li>Update antivirus. Â Make sure you have the last definitions and scan engine. Â Note that sometimes the scanÂ engineÂ is not an auto update and may require manual processing. Â Also make sure that all of your computers are showing in the antivirus console. Â If not you might have a potential issue.Â Â Look into it ASAP before it becomes a problem. Â </li>
<li>Windows update. Â Update everything. Â Every computer should have every critical rated patch, always. Â Check out my past post on autopatcher, and check <a title="baseline" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=F32921AF-9DBE-4DCE-889E-ECF997EB18E9&amp;displaylang=en" onclick="pageTracker._trackPageview('/outgoing/www.microsoft.com/downloads/details.aspx?FamilyID=F32921AF-9DBE-4DCE-889E-ECF997EB18E9_amp_displaylang=en&amp;referer=');">this</a> out for aÂ alternativeÂ way to investigate the security of your network.</li>
<li>Be a bouncer. Â Do not allow people to bring in homeÂ computers, set up wireless, connect external harddrives and otherÂ strangeÂ stuff to the network. Â  They are not on the domain, notÂ subjectÂ to group policy, and they might not have AV or patches. Â This is a hugeÂ vulnerabilityÂ that often goes unnoticed, but it allows for another way to accidently introduce an infection into a network.</li>
</ul>
<p>April 1st will be interesting at the least. Â I have taken a ton ofÂ percautions so I can just sit back and watch the news all day while my network stands strong.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-2740910196434334";
google_ad_slot = "5492961778";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://tehtech.com/conficker-what-is-it-how-to-prevent-and-clean-it/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

