|
![]() |
|
| Author |
|
|||||||
|
Damo
Posts: 3348
Location: Brisbane, Queensland
|
Worm infects millions of computers http://www.theage.com.au/world/worm-infects-millions-of-computers-20090121-7mq1.html |
|||||||
| #0 11:38am 22/01/09 |
|
|||||||
|
system
|
--
|
|||||||
| #0 |
|
|||||||
|
TiT
Posts: 1882
Location: Brisbane, Queensland
|
yes read this yesterday.... i we have had to format 3 computers in the last couple of days :(
|
|||||||
| #1 12:06pm 22/01/09 |
|
|||||||
|
trog
AGN Admin
Posts: 25919
Location: Brisbane, Queensland
|
Is this from an as-yet unpatched hole in Windows or was it already fixed in a recent Windows update? I spose that'd be a bit hard for The Age to research, only having a handful of journalists. |
|||||||
| #2 12:07pm 22/01/09 |
|
|||||||
|
Fireblood
Posts: 9058
Location: Brisbane, Queensland
|
Yeah well Ebay sent me an email today saying that my account had been comprimised, and that perhaps my email had been as well if i didn't receive any messages from ebay.
Which, personally I think is either this worm, or a complete load of bulls***. Have a totally up to date virus scanner/firewall and Windows...and did a scan last night! |
|||||||
| #3 12:13pm 22/01/09 |
|
|||||||
|
Alt_F4
Posts: 695
Location: Brisbane, Queensland
|
Is this from an as-yet unpatched hole in Windows or was it already fixed in a recent Windows update? I spose that'd be a bit hard for The Age to research, only having a handful of journalists. This worm was around back in October i think, and Microsoft released a patch for it sometime back then. Pretty sure this is old news, and the only reason the article just surfaced is because an anti-virus company released the 9m figure. |
|||||||
| #4 12:23pm 22/01/09 |
|
|||||||
|
trog
AGN Admin
Posts: 25920
Location: Brisbane, Queensland
|
Yeah well Ebay sent me an email today saying that my account had been comprimised, and that perhaps my email had been as well if i didn't receive any messages from ebay.I get about a million of those emails a day and I don't use ebay and afaik don't have an ebay account. It's usually pretty easy to tell if they're scams, just mouseover the links and see if they go to ebay.com.. picking one ebay email at random from my spamfilter it tries to send me to home.doramail.com/qustion/0099888.html which I DONT THINK IS EBAY!@# |
|||||||
| #5 12:25pm 22/01/09 |
|
|||||||
|
Spook
Posts: 23959
Location: Brisbane, Queensland
|
is it an ms issue?
they are obviously aware of the problem Microsoft says it is aware of the Conficker "worm family" and has modified its free Malicious Software Removal Tool to detect and get rid of infections. |
|||||||
| #6 12:28pm 22/01/09 |
|
|||||||
|
simul
Posts: 380
Location: Brisbane, Queensland
|
Hasn't seem to hit my unfirewalled unvirusprotected computer which is setup as a dmz :) Mac FTW.
|
|||||||
| #7 12:32pm 22/01/09 |
|
|||||||
|
Pinky
Posts: 437
Location: Melbourne, Victoria
|
If worms/virii are such a threat there should be an independent dept in Computer Science at some University - asking a commercial company that makes virus scanners for a living if there is a virus threat is a joke and ridiculous reporting on behalf of The Age. I love The Age, I used to work there and it's my preferred news source, however I am noticing more and more sensationalist journalism which irks me. It isn't "reporting" - it's opinion, and there's a section for that. **EDIT** Correction to above - poor editing on behalf of The Age to include a badly scripted AFP report. My mistake. |
|||||||
| #8 12:51pm 22/01/09 |
|
|||||||
|
thermite
Posts: 810
Location: Brisbane, Queensland
|
I love how the article doesn't point out that the Microsoft Windows Operating System is the vulnerable thing about the infected computers. They only mention it in a backhand kind of way:
takes advantage of networks or computers that haven't kept up to date with security patches for Windows Remote Procedure Call Server service. The question is whether this was out of ignorance for other operating systems, or from the knowledge that if there is a virus, there is windows. |
|||||||
| #9 01:50pm 22/01/09 |
|
|||||||
|
simul
Posts: 382
Location: Brisbane, Queensland
|
RPC? Interesting, isn't that what Blaster used to get through? You'd think they would secure the hell out of it after the Blaster crap.
|
|||||||
| #10 05:48pm 22/01/09 |
|
|||||||
|
Alt_F4
Posts: 698
Location: Brisbane, Queensland
|
It isn't necessarily Windows fault that it gets ravaged by virii. It is impossible to close every loophole, it's just that Windows is the OS most people use so is obviously the best target for hackers.
|
|||||||
| #11 06:06pm 22/01/09 |
|
|||||||
|
pARODY
Posts: 216
Location: Brisbane, Queensland
|
MS08-067 is the hole most of the 900+ variants of this virus/worm uses. Its quite difficult to isolate as it uses http and dns traffic to communicate. This makes it difficult to analyze and identify before it infects a machine.
http://isc.sans.org/diary.html?storyid=5695 lists much of the detail about how it works. http://support.microsoft.com/kb/953252 lists how to disable autorun properly. |
|||||||
| #12 09:36pm 22/01/09 |
|
|||||||
|
Chickens***
Posts: 281
Location: Brisbane, Queensland
|
This is f***ing awesome. I hope this thing spreads out of control and actually starts doing something.
|
|||||||
| #13 09:50pm 22/01/09 |
|
|||||||
|
Crunch
Posts: 1004
Location: Perth, Western Australia
|
oh man my work got hammered with this thing the last few days. Good thing we have an IT guy who has worked at the same company for 20 years, has no qualifications and is generally inept at what he does (if google doesn't list a solution, it can't be solved!).
|
|||||||
| #14 10:06pm 22/01/09 |
|
|||||||
|
Scorp
Posts: 312
Location: Brisbane, Queensland
|
why the f*** is Conficker being so overtalked? any virus that is being talked about MS AND the antivirus companies already know about and therefore if your not one of those tards using a hacked version of win xp without so much as one update (because its hacked) or an antivirus (because your a moron) or firewall (because your less tech savy) then you'll get it... if your not then your fine. out of the 700+ computers we run, not one has got this bloody virus.
if you want to worry about something, worry about the viruses that hackers make that are never talked about. worry about that malware that gets onto your windows box that the av and malware endpoint protection doesnt pickup on. hell a good 1 hour google around hacking sites will give you the framework code that any year 10 it student can hack around, add a payload, compile and spam to begin his own botnet that he can sell for us $10 per 100 drones per hour. sigh. |
|||||||
| #15 10:20am 23/01/09 |
|
|||||||
|
Spook
Posts: 23965
Location: Brisbane, Queensland
|
cracked os's are fine for updates
|
|||||||
| #16 12:02pm 23/01/09 |
|
|||||||
|
Scorp
Posts: 313
Location: Brisbane, Queensland
|
howd you get around the windows genuine advantage crap spook?
|
|||||||
| #17 02:43pm 23/01/09 |
|
|||||||
|
Spook
Posts: 23973
Location: Brisbane, Queensland
|
there are ways around that work permanently
|
|||||||
| #18 03:02pm 23/01/09 |
|
|||||||
|
Scorp
Posts: 314
Location: Brisbane, Queensland
|
wow thats really fail on microsofts behalf. i was always under the impression if you didnt have a legit key after that last service pack came through you couldnt use the windows update website...
if you mean how you can download a program that downloads all updates and installs them for you then meh... to much effort and not reliable enough (0day) imo |
|||||||
| #19 03:11pm 23/01/09 |
|
|||||||
|
Spook
Posts: 23975
Location: Brisbane, Queensland
|
nope, just do a small setup, and get updates as per normal
|
|||||||
| #20 03:13pm 23/01/09 |
|
|||||||
|
Crakaveli
Posts: 3061
Location: USA
|
there are ways around that work permanently i don't recall having to do anything special to get around, just ran the verification program and it worked. GJ MS lol. |
|||||||
| #21 03:14pm 23/01/09 |
|
|||||||
|
Midda
Posts: 3055
Location: Brisbane, Queensland
|
howd you get around the windows genuine advantage crap spook? In my experience, WGA hasn't been a problem. I was running a cracked version of Vista once, but WGA thought it was legit. I didn't do anything to get around it, it just worked. |
|||||||
| #22 03:20pm 23/01/09 |
|
|||||||
|
casa
Thimes
Posts: 3157
Location: Brisbane, Queensland
|
On a personal level, virus' are f***en lol. People can hax my files man, look at my pr0ns and delete my fielz. Nothing a format won't fix. |
|||||||
| #23 03:51pm 23/01/09 |
|
|||||||
|
pARODY
Posts: 217
Location: Brisbane, Queensland
|
The thing with conficker is that its main payload has not been released yet. We have some general ideas about what it could contain and none of them are good. So patch up. :]
|
|||||||
| #24 06:33pm 23/01/09 |
|
|||||||
|
Tollaz0r!
Posts: 9473
Location: Brisbane, Queensland
|
I thought one of the ideas is that it could contain nothing. That is good. |
|||||||
| #25 06:45pm 23/01/09 |
|
|||||||
|
system
|
--
|
|||||||
| #25 |
|
|||||||
|
| ||||||||