Share

Related Stories

  • Taking Down a Botnet
    This past February, Microsoft, along with industry partners and academic researchers, spearheaded an effort to take the Waledec botnet offline. Drew Amorosi provides a detailed account of just how the cooperative endeavor was able to halt – at least temporarily – the notorious spam serving network.
  • Batten down the hatches
    Due to the horrifying quantity of vulnerabilities, and often limited time and budget, application and database security can be quite a headache. Limiting privileges and access, however, is a good place to start, finds Danny Bradbury
  • The battle of the internet browsers
    Browsers are the hackers’ window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and why user education is one of the primary solutions for increased security
  • Battle of the Internet Browsers
    Browsers are the hacker’s window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and looks at why user education is one of the primary solutions for increased security
  • A Rotting Security Apple?
    Vendors, analysts, and commentators alike have long predicted a surge in malware affecting Apple’s products. Yet, until recently, these prognostications have failed to materialize. Drew Amorosi examines recent malware threats to Apple’s OS X operating system to find out if this is an anomaly, or a sign of things to come

Top 5 Stories

News

Conficker concern continues

05 March 2009

Conficker continued to garner attention from security vendors this month as it spread across the internet.

Estimates of how many computers the worm had affected varied, with companies such as F-Secure arguing that up to nine million had been affected. However Jeff Williams, principal group program manager at the Microsoft Malware Protection Center, said that the figure was more like three million.

"The measurements that happened early on were flawed in some pretty significant ways," he said. "They didn't take into consideration double counting. They didn't take into account researchers manipulating the count just to see what would happen. They didn't take into account things such as whether an infected system would only report the number of infected systems in its environments once, or multiple reinfections of the same machine."

That figure is still enough for the company to have put a $250 000 bounty on the head of the Conficker author. It joined with a collection of other companies including ICANN and VeriSign and formed the 'Conficker Cabal'. "We're putting our money where our mouth is," said Williams, adding that the FBI was working on several tip-offs. "We haven't done this very many times before, but when we have in the past, we have had success."

The coalition of vendors has been busy registering domains that are due to be visited by the malware for command and control purposes. The system works by generating pseudo-random URLs which it then visits at preset dates. Researchers believe that the malware authors then use the URLs to provide further instructions to the malware, giving them a constant means of contacting infected machines, even if some sites are taken down.

Most recently, Sophos identified some of the future command and control sites as legitimate ones. These include wnsux.com, owned by Southwest Airlines, which Sophos said diverts to the airline's landing page. The worm was due to hit the site on 13th March, said the antivirus company. At the time of writing the site was down, indicating that the company may have triaged it.

At the time of writing, the worm had still not been activated. It seems to have been in the infection phase, spreading far and wide without delivering a payload. Williams couldn't predict a likely payload. "That would be pure speculation but it's safe to say there's a monetary incentive," he said. "We're into the realm where criminals are enterprise. I am sure they have software development lifecycles and testing methodologies of their own".

In the past, spam and DDoS attacks have been two popular botnet payloads, especially when large, fast-spreading network worm-based botnets are involved. More targeted attacks have generally focused on lower-profile botnets, some of which flew under the radar for years until discovered recently.
However, a new variant of the worm, which Microsoft is calling Conficker.C, had been discovered. This variant leaves open the RPC flaw which previous versions patched on their victims' machines. Patching the flaw once infected enables the original infection to fend off subsequent variants from other malware groups, and this technique has been used in the past. However, leaving the flaw open while matching it against specific shell code enables the worm to accept new payloads via the original back door while blocking other malware’s attempts to infect the target system.

This article is featured in:
Internet and Network Security • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.