Author Topic: April 1st - What Will Really Happen?  (Read 1201 times)

Offline dannjr

  • Main Certifiable NutcAsE
  • Administrator Nut
  • Certifiable Nut
  • *****
  • Posts: 6339
  • Gender: Male
  • Share your life. Be a organ donor other Bday 1998
    • DSLnuts | Broadbandnuts | Cablenut
April 1st - What Will Really Happen?
« on: March 30, 2009, 02:35:31 pm »
Per sans.org http://isc.sans.org/diary.html?storyid=6091

Published: 2009-03-29,
Last Updated: 2009-03-30 14:55:59 UTC
by Chris Carboni (Version: 2)
0 comment(s) Facebookacebook witter

As reports and the belief of impending problems from the April 1st changes to Conficker contine to grow and spread this seems like a good time to separate fact from fiction.
 
Here is what we know:
 
This is not an April Fools joke or hoax.
 
The Conficker worm (also known as Downadup) will begin to poll 500 different domain names every day looking for updates as opposed to the 250 per day it is now looking at.
 
The P2P update functionality reported in the new version, already exists today.
 
SRI as a very nice write up on the new Conficker variant available here
 
In addition f-secure as a very nice Q&A article here  and a nice description of the variant here
 
Based on these facts and a wealth of other information, we at the Internet Storm Center beleive that April 1st we be more or less, business as usual.
 
This is not to say that we will not be monitoring the situation.
 
We will be watching events very closely, speaking with industry and other contacts (including the Conficker Working Group) as well as monitoring other indications of potential malicious activity (shameless plug for Dshield data) so that we can provide appropriate guidance should it be needed.
 
And as always, should you notice anything unusual on your network (Conficker related or not) feel free to contact us and let us know.
 
Update: The HoneyNet project has a nice write-up on how to detect the presence of Conficker over the network (by scanning). They also offer a script to help with the scanning.
 
http://isc.sans.org/diary.html?storyid=6091
Be a Organ Donor. A chance at life.
This site never spams or sells its list to anyone. No pop up's or scams
An inconvenience, but if you want to make omelettes, you have to break some eggs.