Jump to content
The Inquirer-Home

Conficker still defeats experts

Can't crack the code
Tuesday, 22 September 2009, 11:32

INSECURITY EXPERTS have admitted that the Conficker worm has baffled them.

The worm has infected more than five million computers in a botnet that could take out the Internet in some countries. The Sydney Morning Herald said Conficker was powerful enough to shut down the Internet in Australa, if the current government does not do it with its censorship software first.

Rodney Joffe, a director of the Conficker Working Group formed to defeat the worm said, "The general agreement in the security world is that Conficker is the largest threat facing us from a cyber crime point of view."

The worm, which spreads rapidly among personal computers by exploiting a flaw in Microsoft Windows, first surfaced last November.

According to Joffe, "it has proven to be extremely resilient. It's almost impossible to remove."

Infected PCs are dragooned into a "botnet" controlled by the Conficker worm's unknown authors, which security researchers fear could be used to launch cyber attacks over the Internet.

Conficker had built-in mechanisms to prevent people from scanning their computers with anti-virus software.

The worm also spreads without the users having to do anything other than switch on their computers.

If a network admin can disinfect 99 machines out of 100 and one is still infected, it will begin to try to reinfect the others again.

While other botnets are destroyed by disabling the command server, with Conficker the location of this server changes every day and state-of-the-art cryptography means it's almost impossible to crack.

"The best minds in the world have not managed to crack the code behind this yet," Joffe said. µ

 

Share this:

Comments
Ummm...

Isn't this the worm that was patched against last October, so the system admin should:

a) have done his bl**dy job a bit better in the first place
b) Take a machine off the network, remove conficker, then apply the patch, before reconnecting it..
c) Go and find a job he knows how to do.

posted by : Steve, 22 September 2009 Complain about this comment
solution

Do not connect Windows computers to internet :)
There is no such thing as computer virus.
It is MS Windows virus.

posted by : nonsense, 22 September 2009 Complain about this comment
winmess

"The best minds in the world have not managed to crack the code behind this yet,"

And one of the richest corporations in the world can't be bothered to build their flagship product properly.
And you go on about Apple!

Simple answer to all this - switch to Linux/OSX. In fact, if Conflicker really can't be beat then switching will not be a choice, it will be a necessity.
And Microsoft's arrogance and laziness will bite them on the ass good and hard.

posted by : penguin-slapper, 22 September 2009 Complain about this comment
it's SKYNET

need i say more?

posted by : joey, 22 September 2009 Complain about this comment
Heh

IT IS SKYNET!!! :)

Just install Linux, stop paying the Microsoft tax. Things are so much better over on the Linux side of the fence!

posted by : WM, 22 September 2009 Complain about this comment
Ha

Nick, why are you publishing at all? SMH is a joke of a newspaper, i only use it to see whats happening in the world of cars).

This article is a joke.

posted by : Nick, 23 September 2009 Complain about this comment
@ Steve

Thanks for your vote of confidence, Steve.

For information, I have a computer on our site here which I have made numerous attempts to find the source of the continual reinfections and have failed. This is the first virus/worm/spyware infection which I've ever encountered without being able to remove it from this particular machine. It is not a complete reinfection, it is simply recreating files related to the virus.

Feel free to educate me as to what I'm missing, given that you know so much about it :).

posted by : Dave, 23 September 2009 Complain about this comment
nature of the beast

windows break, apples get worms, and penguins remain on the endangered species list

posted by : lurch, 23 September 2009 Complain about this comment
Nature of the development philosophy

In closed-source models (like Microsoft and Apple), the source code is a jealously-guarded secret, shared only in part with a few select, monitored individuals. These individuals may be exposed to less-than-optimal work environments (dodging flying chairs at Microsoft, avoiding Mr. Job's Ego at Apple), which apparently does not help one do one's best work.

Open source does away with these limitations: all the source code is available for audit and revision by all users. Millions of eyes (not hundreds) search for security and other problems and continually optimize and develop improvements to benefit the software and each other. And more and more people are now earning high salaries as Linux administrators and professional developers. So I think that is why Linux is so secure, and why it is Windows, not Linux, that is on the "endangered species list".

posted by : Linux = problem solved, 23 September 2009 Complain about this comment
Re: "that is why Linux is so secure"

I actually agree with the theory, but in practice I think it is more secure simply because no malware writer wants to waste time and money targetting 0.8% of what he could target.
And let's not forget one thing : the millions of eyeballs that are supposed to review open source code are looking for bugs, not questioning the architecture.
If the penguin OS gets 20% or more of the market (not before a loooong while), we'll see if it effectively resists the onslaught of malware writers once they get interested in hacking it.
Because those guys _are_ smart, and they have experience in their domain. I'm sure they'll find holes, and they'll know how to exploit them.

posted by : Pascal Monett, 23 September 2009 Complain about this comment
Dave

Well I don't have any specific conficker experience because I keep things patched up to date :-p
However, on the occasions zero-days have got onto a machine at work (usually stupid staff clicking links from messenger based infection) a very handy trick is to do a search for *.* across all the subdirectories sorted by date, then have a look at recently changed/added files.
Also may I recommend process explorer for viewing the path of anything running. Terminate as much as you can.
If you find something that is running, rename it and then create an empty file with it's original name with read only attribute. That will stop it putting it back.
Now check the registry run entry for any of the suspicious recent files and remove them.
Also when you have some of those filename, try a google for them, the intarweb may provide you with a removal tool.

Reboot the machine, and check again for recent files to see if anything comes back. If it does, you've missed something, try again!

Don't reconnect to the network until it's fixed, and patched! Even if you have to use a V92 modem to download them!

posted by : Steve, 23 September 2009 Complain about this comment
typo

you also forgot to correct the word "Australa".

posted by : ahmed, 23 September 2009 Complain about this comment
none

The problem isn't Windows, it's the virus. Just like the problem is a car thief, not the crappy GM lock mechanism.

posted by : none, 23 September 2009 Complain about this comment
@ Steve again

Ok, now please offer me some suggestions above and beyond what I consider standard procedure :).

All of our computers are kept updated through a SUS server and we only had three computers out of about 350 receive a conficker infection. One was a 2003 server which was NOT receiving SUS updates, the other two were 2k and XP machines - I'm not sure how they managed to get infected with the correct update already in place.

We cleaned up the 2003 server quite quickly and easily but the same process is not working on this XP computer. The 2k computer was discarded as it was due to be replaced anyway.

posted by : Dave, 23 September 2009 Complain about this comment
Pentagon?

Seeing that all conficker has done since it appeared is spread and evolve, it doesn't actually harm your operating systems, steal information or launch DoS attacks, i would probably not waste my time trying to remove it. Its probably operated and run by the Pentagon, the Russians use bots all the time to launch attacks at second world nations, this is washingtons, or beijings or tokyo's reply. Chances are this is run by a government and will only become active in the case of a war, which means it will be used against another country. Dont worry the five hundred dollars left on your savings account are safe.

posted by : E.Blair, 24 September 2009 Complain about this comment
From Hockey (NHL) to Madagascar!

"windows break, apples get worms, and penguins remain on the endangered species list"

But... Penguins are tough creatures in a very cold world, some youngs get eaten by gulls (scavengers of the computer world equivalent) They keep on going.

Not that I'm a hockey fan, but the Pittsburgh Penguins, won the Stanley Cup last season? And Hollywood is involving it's works in the penguin symbol too, with the clever group of fives cartoon MacGyvers, staring in
Madagascar.

Amiga's Unix technology has re-flowered under linux, free Amiga fish disks that instrumented linux penguins benefit.

posted by : Phil, 24 September 2009 Complain about this comment
government

That's exactly what I was thinking. This reminds me of an article I read (about 2 years ago) about a US government agency (I think it was the DoD) putting money into a new program related to this. Most of the comments were people laughing at such a little amount of money towards an almost impossible feat. I admit, at the time, I laughed too. :|

posted by : Rockabye, 24 September 2009 Complain about this comment
HOAX

this virus is a hoax. all you guys need to get a life. its the pentagon? lmao what losers.

posted by : Justin, 14 October 2009 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?