<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sekiur My Thoughts &#187; virus</title>
	<atom:link href="http://blog.sekiur.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:46:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Accurate Risk Assessments</title>
		<link>http://blog.sekiur.com/2009/06/accurate-risk-assessments/</link>
		<comments>http://blog.sekiur.com/2009/06/accurate-risk-assessments/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 21:39:44 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Risk assessment]]></category>
		<category><![CDATA[Single Loss Expectancy]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=818</guid>
		<description><![CDATA[<p>As professionals in security we are constantly researching new technologies to keep our skills sharp. The Internet Storm Center was formed to assist with keeping our peers aware of the fast paced changes in vulnerabilities, patches, hacks, worms, Trojans and threats in general.</p> <p>How we communicate these risks to our key decision makers sometimes can [...]]]></description>
			<content:encoded><![CDATA[<p>As professionals in security we are constantly researching new technologies to keep our skills sharp.  The Internet Storm Center was formed to assist with keeping our peers aware of the fast paced changes in vulnerabilities, patches, hacks, worms, Trojans and threats in general.</p>
<p>How we communicate these risks to our key decision makers sometimes can be a challenge.   A recent example would be the Conficker April 1st situation.  It was important for us to convey the sense of urgency we felt to have MS08-067 patched, as well as cross checking all our systems for updates being rejected, anti-virus definitions up-to-date and so on.  My question to you is “did you communicate the risk effectively”?  Were you able to give a complete and accurate risk assessment to your management?</p>
<p>Remember that risk assessment is the process of identifying a threat, understanding how that threat relates (vulnerability) to your organization, assessing the cost and providing that information to management.  The formula is simple, let’s break it down.</p>
<p style="text-align: center;"><strong>Risk = Threat x Vulnerability x Cost </strong></p>
<ol>
<li>State the threat in language that is easily understood.  It is your job to decrypt the threat for your management team.</li>
<li>Portray clearly and accurately what the threat could do and how it would possibly perform in your environment.</li>
<li>Identify the number of assets which may be affected by the threat.  What is percentage of vulnerable devices in relation to the total devices?  (Servers, workstations, operating systems, Internet exposure)</li>
<li>Identify the corrective measures which are available to be taken.</li>
<li>Calculate the SLE (Single Loss Expectancy).  What is the dollar value of the cost that equals the total cost of the risk?</li>
<li>State how the remediation would lower the exposure to the organization and give a cost for those actions.</li>
<li>Recalculate the SLE with projected remediation included.</li>
<li>Provide status of the protection mechanisms already in place (anti-virus definitions, IPS signature detections, patching statistics).</li>
<li>Then allow management to make an educated decision based on risk to the enterprise, not just the security event itself.</li>
</ol>
<p>By utilizing this concrete methodology, we can lessen the influence of media hype and provide a professional cost based opinion to those best equipped to make enterprise decisions.</p>
<p>Source:  http://www.dshield.org/diary.html?storyid=6223 by Mari Nichols</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.ethelthefrog.com/?p=1223"> Top Ten Ways to Know If You Have the Conficker Virus </a> (ethelthefrog.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ef877763-6f79-48a3-bd20-995a82ec0359/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ef877763-6f79-48a3-bd20-995a82ec0359" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/06/accurate-risk-assessments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Gets Ready To Strike</title>
		<link>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/</link>
		<comments>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 19:37:25 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downandup]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=758</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg"></a>Without a doubt the whole security professional community have their eyes on the Conficker.C variant which is designed to do something on April 1st.</p> <p>So what is that something? We&#8217;ll find out within 24 hours.</p> <p>What we do know is that this variant of Conficker has become better at preventing removal and others from [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg"><img class="alignleft size-full wp-image-759" title="24hours_day0" src="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg" alt="" width="120" height="107" /></a>Without a doubt the whole security professional community have their eyes on the Conficker.C variant which is designed to do something on April 1st.</p>
<p>So what is that something? We&#8217;ll find out within 24 hours.</p>
<p>What we do know is that this variant of Conficker has become better at preventing removal and others from taking control of the network of worm infected computers.</p>
<p>The Conficker worm will begin to poll 500 different domain names every day looking for updates to download doubling its current rate.</p>
<p>Interestingly enough one of my most popular posts is on the removal of the Conficker worm from a network environment <a href="http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/" target="_self">here</a> and over the last couple of days visitors have exploded exponentially.</p>
<p>In my two other posts in which I talk about the <a href="http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/" target="_self">Microsoft flaw</a> and the <a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self">Social Engineering</a> components of the worm, I take a rather passive approach to the problem which is based on having contingency plans to prevent, contain and remove the worm from infected computers.</p>
<p>A more pro-active approach would be to look for infected machines without waiting for the symptons to appear by actively scanning the network for computers which have been infected.</p>
<p>Locating computers which have been infected with Conficker using a network scan has kept me up multiple nights, until the guys at <a href="http://honeynet.org/" target="_self">Honeynet.org</a> came up with the <a href="http://honeynet.org/node/388" target="_self">tool here</a>. Thanks to <a href="http://www.dshield.org/" target="_self">DShield.org</a> for linking to it in their article on <a href="http://www.dshield.org/diary.html?storyid=6097" target="_self">locating Conficker</a>.<a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self"><br />
</a></p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><a href="http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/" target="_self">http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/</a><br />
<a href="http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/" target="_self">http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/</a><br />
<a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self">http://blog.sekiur.com/2009/01/worm-uses-social-engineering/</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.shankrila.com/tech-stuff/how-to-remove-conficker-worm/">Your Quick Guide to the Conficker Worm</a> (shankrila.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/article/09/02/13/With_global_effort_a_new_type_of_worm_is_slowed_1.html&amp;a=3158865&amp;rid=54f79576-6273-4d40-8fb9-001ff817cc48&amp;e=3bc0e6cf396bcb6a07b7981582904fa2">With global effort, a new type of worm is slowed</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.idiomag.com/peek/72863/crap">My Top Security and Maintenance Tools</a> (idiomag.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.technet.com/msrc/archive/2009/02/06/new-information-pages-on-conficker.aspx">New Information Pages on Conficker</a> (blogs.technet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://littlegreenfootballs.com/article/33216_Windows_PC_Worm_Set_to_Activate_on_April_1st">Windows PC Worm Set to Activate on April 1st</a> (littlegreenfootballs.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/54f79576-6273-4d40-8fb9-001ff817cc48/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=54f79576-6273-4d40-8fb9-001ff817cc48" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Step by Step In Dealing With Conficker</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/</link>
		<comments>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 23:03:35 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downandup]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=722</guid>
		<description><![CDATA[<p>This will turn out to be a &#8220;trojan horse&#8221; literally if actions are not taken to prevent it from spreading within the corporate network.</p> <p>Below are step by step instructions on mitigating the risk of the threat that &#8220;Conficker&#8221;/&#8221;Downandup&#8221; poses.</p> <p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/binary.jpg"></a></p> <p>Symptoms</p> <p>============</p> <p>Symptoms to help you determine if you are infected</p> Account lockout [...]]]></description>
			<content:encoded><![CDATA[<p>This will turn out to be a &#8220;trojan horse&#8221; literally if actions are not taken to prevent it from spreading within the corporate network.</p>
<p>Below are step by step instructions on mitigating the risk of the threat that &#8220;Conficker&#8221;/&#8221;Downandup&#8221; poses.</p>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/binary.jpg"><img class="aligncenter size-medium wp-image-724" title="binary" src="http://blog.sekiur.com/wp-content/uploads/2009/02/binary-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p><strong>Symptoms</strong></p>
<p>============</p>
<p>Symptoms to help you determine if you are infected</p>
<ul>
<li>Account lockout policies are being tripped</li>
<li>Automatic Updates, Background Intelligent Transfer Service, Windows Defender and Error Reporting Server Services are disabled</li>
<li>Errors related to SVCHOST</li>
<li>Domain Controllers are slow to respond to client requests</li>
<li> Network congestion</li>
<li> Various security related websites are not accessible including Windows Update.</li>
</ul>
<p><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'; color: #000000;">For  further details see the Microsoft Malware Protection Center write up for <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.B">Win32/Conficker.b</a>. or the Sekiur writeup </span><a title="Sekiur" href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_blank">here</a>.</p>
<p><strong>Solution</strong></p>
<p>=========</p>
<p>Ideally you want to not only automate the removal of the &#8220;Conficker&#8221;/&#8221;Downandup&#8221; worm from a large number of computers but also take steps to minimize the risk of them being infected again.</p>
<p>The following script will attempt to remove the &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  worm and prevent further infection by taking the following steps:</p>
<ol>
<li>Install patch <a href="http://support.microsoft.com/kb/958644" target="_blank">KB958644</a> for <a href="http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx" target="_blank">MS08-067</a> if not installed</li>
<li>Attempt to remove the &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  worm</li>
<li>Enable Hidden Setting</li>
<li>Delete all scheduled tasks</li>
<li>Stop and disable services. (lanmanserver, schedule)</li>
<li>Run MSRT &#8211; Malicious Software Removal Tool</li>
<li>Install Autorun hotfix if not installed</li>
<li>Install <a href="http://support.microsoft.com/kb/950582" target="_blank">KB950582</a> for vulnerability <a href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx" target="_blank">MS08-038</a></li>
<li>Re-enable TCP Receive Window Auto-tuning on Windows Vista and Windows Server 2008</li>
<li>Remove Hidden Setting</li>
<li>Enable Automatic Updates, Background Intelligent Transfer and Error Reporting Services</li>
<li>Restart</li>
<li>Install patch <a href="http://support.microsoft.com/kb/958644" target="_blank">KB958644</a> for <a href="http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx" target="_blank">MS08-067</a> and restart</li>
</ol>
<p>You will need to download the following files and batch script and drop them into the NetLogon share.</p>
<ul>
<li> Getver.exe &#8211; contained in ConfickerClean-v10.3.zip here ==> [Download not found] and script to remove &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  locally here ==> [Download not found].</li>
<li>SC.EXE &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>REG.exe &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>windows-kb890830-v2.6.exe &#8211; x86 version of MSRT, available <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en" target="_blank">here</a>.</li>
<li>windows-kb890830-x64-v2.6.exe &#8211; x64 version of MSRT, available <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=585D2BDE-367F-495E-94E7-6349F4EFFC74&amp;displaylang=en" target="_blank">here</a>.</li>
<li> sleep.exe &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>Hotfix update for Windows 2000, Windows XP and Windows 2003, download all updates listed in <a href="http://support.microsoft.com/kb/953252" target="_blank">http://support.microsoft.com/kb/953252</a>, except the Itanium update as this script does not support Itanium.</li>
<li>Place all 3 updates in the Netlogon directory.</li>
<li>Security update MS08-038 for Windows Vista and Windows Server 2008 &#8211; <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx" target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx</a><br />
This vulnerability is not being exploited, however, to disable Autorun properly this needs to be applied as it contains a fix related to autorun, same as the one listed above in <a href="http://support.microsoft.com/kb/953252" target="_blank">KB953252</a>.</li>
</ul>
<p>Now you will proceed to create and push a Group Policy to the domain.</p>
<ol>
<li>Edit the &lt;domain.com&gt; values in the script.</li>
<li>Rename it to .BAT and drop it in the \\%windir%\sysvol\sysvol\\scriptsfolder (aka, Netlogon share).</li>
<li> Create a Startup Script policy and reference this batch file.  This needs to be a Startup Script and not a Logon script, so that the script runs under the machine account.</li>
<li>Link the GPO with the Startup Script to the OU and Groups where you want it to apply.</li>
</ol>
<p><strong>Note:</strong></p>
<p><strong>Its not recommend you use this on DC&#8217;s or critical servers, those should be cleaned manually so that the services disabled below do not need to be left disabled for an extended period of time.</strong></p>
<p><strong>FAQ:</strong></p>
<p><strong>Why disable the Server service? </strong></p>
<p>This is due to Weak Passwords which the malware attempts to exploit. The password change will need to be accomplished via password policy for the domain, resetting any local and domain admin password to a complex password which includes at least 10 characters and contains, alpha-numeric characters and extended characters such as a question mark or exclamation point.</p>
<p><strong>Why disable the Task Scheduler service? </strong></p>
<p>This is because the malware creates several AT jobs that run every hour to reinfect the system.</p>
<p><strong>Why install MS08-067?</strong></p>
<p>This is the main attack vector of the malware.</p>
<p><strong>Why disable Autorun?</strong></p>
<p>This is because the malware drops a binary file called Autorun.inf on all removable drives.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>Sources:</p>
<p>All credit to Microsoft Support Engineering</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Worm Uses Social Engineering</title>
		<link>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/</link>
		<comments>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 19:27:27 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnera]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=704</guid>
		<description><![CDATA[<p>A new worm has hit the Internet and its taking its toll on computers worldwide. It has been reported that over 9 million computers have already been infected.</p> <p>The worm called &#8220;Downandup&#8221;, &#8220;Conficker&#8221; or &#8220;Kido&#8221; by different anti-virus vendors uses the Microsoft vulnerability which I blogged about here (<a rel="bookmark" href="../2008/10/worm-takes-advantage-of-microsoft-flaw/">Worm Takes Advantage Of Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p>A new worm has hit the Internet and its taking its toll on computers worldwide. It has been reported that over 9 million computers have already been infected.</p>
<p>The worm called &#8220;Downandup&#8221;, &#8220;Conficker&#8221; or &#8220;Kido&#8221; by different anti-virus vendors uses the Microsoft vulnerability which I blogged about here (<a rel="bookmark" href="../2008/10/worm-takes-advantage-of-microsoft-flaw/">Worm Takes Advantage Of Microsoft Flaw</a>) and here (<a rel="bookmark" href="../2008/10/microsoft-releases-emergency-patch/">Microsoft Releases Emergency Patch</a>).</p>
<p>The worm mostly spreads across networks, turning off the system restore and deleting the restore points, blocks access to security website, download additional malware from the author, attempts to infect other computers by scanning network shares and scheduled a task to re-infect the computer if removed.</p>
<p>What is interesting is that it can also spread by USB memory keys or devices making use of <a href="http://en.wikipedia.org/wiki/Social_engineering_(security)" target="_blank">social engineering</a> which makes it more dangerous to the untrained eye. When a USB drive is inserted it shows a modified AutoPlay screen seen below which will install the worm when the users inadvertently clicks on it.</p>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/windows_vista_open_folder_to_view_files.png"><img class="aligncenter size-full wp-image-705" title="windows_vista_open_folder_to_view_files" src="http://blog.sekiur.com/wp-content/uploads/2009/01/windows_vista_open_folder_to_view_files.png" alt="" width="400" height="550" /></a></p>
<p>According to <a title="SANS ISC" href="http://isc.sans.org/" target="_blank">SANS Internet Storm Center</a>, one of the reasons the worm is infecting so many machines is that &#8220;Conficker&#8221; uses multiple infection vectors:</p>
<ol>
<li>It exploits the MS08-067 vulnerability,</li>
<li>It brute forces Administrator passwords on local networks and spreads through ADMIN$ shares and finally</li>
<li>It infects removable devices and network shares by creating a special autorun.inf file and dropping its own DLL on the device.</li>
</ol>
<h4 class="tabsection-title">Characteristics -</h4>
<p>When executed, the worm copies itself using a random name to the %Sysdir% folder.</p>
<p><em>(Where %Sysdir% is the Windows system folder; e.g. C:\Windows\System32)</em></p>
<p>It modifies the following registry key to create a randomly-named service on the affected syetem:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\&#8221;ServiceDll&#8221; = &#8220;Path to worm&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\&#8221;ImagePath&#8221; = %SystemRoot%\system32\svchost.exe -k netsvcs</li>
</ul>
<p>Attempts connections to one or more of the following websites to obtain the public ip address of the affected computer.</p>
<ul>
<li>hxxp://www.getmyip.org</li>
<li>hxxp://getmyip.co.uk</li>
<li>hxxp://checkip.dyndns.org</li>
<li>hxxp://whatsmyipaddress.com</li>
</ul>
<p>Attempts to download a malware file from the remote website: (Rogue Russian site is up but not serving file anymore)</p>
<ul>
<li> hxxp://trafficconverter.biz/[Removed]antispyware/[Removed].exe</li>
</ul>
<p>Starts a HTTP server on a random port on the infected machine to host a copy of the worm.</p>
<p>Continuously scans the subnet of the infected host for vulnerable machines and executes the exploit. If the exploit is successful, the remote computer will then connect back to the http server and download a copy of the worm.</p>
<p>Later variants of w32/Conficker.worm are using scheduled tasks and Autorun.inf file to replicate on to non vulnerable systems or to reinfect previously infected systems after they have been cleaned.</p>
<h4 class="tabsection-title">Suggestions -</h4>
<ol>
<li>Disable AutoPlay in your environment.</li>
<li>Run a good security suite.</li>
<li>Keep your computer updated with the latest patches.</li>
<li>Be <strong>PROACTIVE</strong> and look for the worm in your environment.</li>
</ol>
<p>Sources:</p>
<p>http://www.nai.com</p>
<p>http://www.symantec.com</p>
<p>http://www.f-secure.com</p>
<p>http://isc.sans.org</p>
<ul></ul>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting up a Mail Relay on CentOS 5</title>
		<link>http://blog.sekiur.com/2008/09/setting-up-a-mail-relay-on-centos-5/</link>
		<comments>http://blog.sekiur.com/2008/09/setting-up-a-mail-relay-on-centos-5/#comments</comments>
		<pubDate>Sat, 27 Sep 2008 23:05:36 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[clamav]]></category>
		<category><![CDATA[mailscanner]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[postfix]]></category>
		<category><![CDATA[postgrey]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=271</guid>
		<description><![CDATA[<p>This will give you the capability to scan e-mails for spam, viruses and phishing using a variety of open source programs before they arrive to your e-mail server.</p> <p>From Sekipedia<br /> Jump to: navigation, search</p> <p>* Install CentOS 5.1 barebones (customizing the install with nothing checked.)</p> <p>* Update the system </p> <p>yum update</p> <p>* Install [...]]]></description>
			<content:encoded><![CDATA[<p>This will give you the capability to scan e-mails for spam, viruses and phishing using a variety of open source programs before they arrive to your e-mail server.</p>
<p>From Sekipedia<br />
Jump to: navigation, search</p>
<p>* <strong>Install CentOS 5.1 barebones</strong> (customizing the install with nothing checked.)</p>
<p>* <strong>Update the system </strong></p>
<p>yum update</p>
<p>* <strong>Install Additional packages </strong></p>
<p>yum install ntp</p>
<p>yum install vixie-cron crontabs</p>
<p>* <strong>Download and install Webmin </strong></p>
<p>cd /opt</p>
<p>wget http://prdownloads.sourceforge.net/webadmin/webmin-1.430-1.noarch.rpm</p>
<p>yum install perl-Net-SSLeay</p>
<p>rpm -ivh webmin-1.430-1.noarch.rpm</p>
<p>* <strong>Disabled unneeded services </strong></p>
<p>service iptables stop<br />
service ip6tables stop<br />
service netfs stop<br />
chkconfig iptables off<br />
chkconfig ip6tables off<br />
chkconfig netfs off</p>
<p>* <strong>Install Postfix </strong></p>
<p>yum install postfix</p>
<p>* <strong>Configure Postfix </strong></p>
<p>myhostname = titan.corp.com<br />
mydomain = localhost<br />
myorigin = $mydomain<br />
inet_interfaces = all<br />
mydestination = $myhostname, localhost.$mydomain, $mydomain<br />
mynetwork_style = class</p>
<p>* <strong>Configure Postfix to forward email </strong></p>
<p>relay_domains = lab.net</p>
<p>This tells Postfix which domains it should relay mail. All mail destined for this domain (and only this domain) will be forwarded to its remote SMTP server. You can put multiple domains here, just separate them with a comma or whitespace.</p>
<p>Add line to end of main.cf</p>
<p>transport_maps = hash:/etc/postfix/transport<br />
mailbox_size_limit = 20480000<br />
mailbox_size_limit = 20480000</p>
<p>This tells Postfix what method to use to resolve the destination address for relayed mail:</p>
<p>Add line to end of &#8220;/etc/postfix/transport&#8221;</p>
<p>lab.net		smtp:[192.168.2.225]</p>
<p>This command specifically maps the domain &#8220;lab.net&#8221; to the IP address 192.168.2.225 and tells Postfix to use SMTP as the transport. All mail destined for lab.net which is relayed through this Spam Gateway will be forwarded via SMTP to 192.168.2.225.</p>
<p>Then run command:</p>
<p>postmap /etc/postfix/transport</p>
<p>This command builds the hash table/file which Posfix will use to forward mail. If you don&#8217;t do this, it wont work.</p>
<p>Finally add this line to main.cf</p>
<p>append_at_myorigin = no</p>
<p>These lines will make sure your Spam Gateway does not add any of its own header domain info to the mail as it passes thru.</p>
<p>*<strong> Test Again </strong></p>
<p>Stop and start postfix to make sure all changes take.</p>
<p>service postfix stop<br />
service postfix start</p>
<p>I know this is redundant, but you really should test your system again before installing MailScanner. Make sure that mail gets passed through the system without problem. If you do encounter a problem, it will be a lot easier to fix it now than after you&#8217;ve installed MailScanner, SpamAssassin and ClamAV.</p>
<p>At this point incoming e-mail should go through the Mail Relay and be forwarded to the internal E-mail server.</p>
<p>* <strong>Install DAG&#8217;s GPG key </strong></p>
<p>rpm &#8211;import http://dag.wieers.com/rpm/packages/RPM-GPG-KEY.dag.txt</p>
<p>* <strong>Verify the package you have downloaded</strong></p>
<p>rpm -K rpmforge-release-0.3.6-1.el5.rf.*.rpm</p>
<p>Security warning: The rpmforge-release package imports GPG keys into your RPM database. As long as you have verified the package and trust Dag then it should be safe.</p>
<p>* <strong>Download and Install the package </strong></p>
<p>wget http://packages.sw.be/rpmforge-release/rpmforge-release-0.3.6-1.el5.rf.i386.rpm<br />
rpm -ivh rpmforge-release-0.3.6-1.el5.rf.*.rpm</p>
<p>This will add a yum repository config file and import the appropriate GPG keys. At this point, you can set the priority of the RPMForge repository, and also of the CentOS repositories if you have not done so yet.</p>
<p>* <strong>Test with this command: </strong></p>
<p>yum check-update</p>
<p>* <strong>Update the system </strong></p>
<p>yum update</p>
<p>* <strong>Install perl modules and dependencies for MailScanner </strong></p>
<p>yum install &#8211;enablerepo=rpmforge perl-Archive-Zip perl-Convert-BinHex perl-Convert-TNEF perl-DBD-SQLite perl-Filesys-Df perl-HTML-Parser</p>
<p>yum install &#8211;enablerepo=rpmforge perl-IO-stringy perl-MIME-tools perl-Net-CIDR perl-Sys-Hostname-Long perl-OLE-Storage_Lite</p>
<p>yum install tnef</p>
<p>* <strong>Download and Install MailScanner </strong></p>
<p>wget http://www.mailscanner.info/files/4/rpm/MailScanner-4.71.10-1.rpm.tar.gz</p>
<p>tar -zxvf MailScanner-4.71.10-1.rpm.tar.gz</p>
<p>cd MailScanner-4.71.10-1</p>
<p>rpm -ivh mailscanner-4.71.10-1.noarch.rpm</p>
<p>chkconfig postfix off</p>
<p>service postfix stop</p>
<p>chkconfig MailScanner on</p>
<p>* <strong>Configure MailScanner Settings </strong></p>
<p>Updates to postfix&#8217;s main.cf by adding this line:</p>
<p>header_checks = regexp:/etc/postfix/header_checks</p>
<p>In the file /etc/postfix/header_checks add this line:</p>
<p>/^Received:/ HOLD</p>
<p>Here are the edits to Mailscanner &#8211; place / update in /etc/MailScanner/MailScanner.conf</p>
<p>Run As User = postfix<br />
Run As Group = postfix<br />
Incoming Queue Dir = /var/spool/postfix/hold<br />
Outgoing Queue Dir = /var/spool/postfix/incoming<br />
MTA = postfix</p>
<p>Optional edits to MailScanner</p>
<p>Change %org-name%<br />
Change %org-long-name%<br />
Change %web-site%</p>
<p>Here&#8217;s some file permissions changes you&#8217;ll need to make:</p>
<p>chown postfix.postfix /var/spool/MailScanner/incoming<br />
chown postfix.postfix /var/spool/MailScanner/quarantine</p>
<p>service MailScanner start</p>
<p>Its a good idea to test the server now. Send a message to the remote server and see if it goes through. It should, and then you can move to installing SpamAssassin.</p>
<p>* <strong>Install perl modules for SpamAssassin </strong></p>
<p>yum install perl-Digest-SHA1 perl-Net-DNS perl-Archive-Tar perl-IO-Zlib</p>
<p>yum install &#8211;enablerepo=rpmforge perl-Encode-Detect perl-Mail-SPF perl-IP-Country perl-Mail-DKIM perl-Net-Ident</p>
<p>* <strong>Update the system </strong></p>
<p>yum update</p>
<p>* <strong>Install and Configure SpamAssassin </strong></p>
<p>yum install spamassassin</p>
<p>You don&#8217;t need to edit any of the SpamAssassin conf files because all of the configuration is done through MailScanner.</p>
<p>In /etc/MailScanner/MailScanner.conf we will make these changes:</p>
<p>Change this line:</p>
<p>Use SpamAssassin = no</p>
<p>to:</p>
<p>Use SpamAssassin = yes</p>
<p>Update the SpamAssassin User State Dir setting:</p>
<p>SpamAssassin User State Dir = /var/spool/MailScanner/spamassassin</p>
<p>and then run commands:</p>
<p>mkdir /var/spool/MailScanner/spamassassin<br />
chown postfix.postfix /var/spool/MailScanner/spamassassin</p>
<p>Restart MailScanner to make changes stick.</p>
<p>service MailScanner restart</p>
<p>* <strong>SELinux exception for Clamav </strong></p>
<p>setsebool -P clamd_disable_trans=1 or disable SELinux while Clamav is installed.</p>
<p>* <strong>Install ClamAV </strong></p>
<p>yum install clamav clamav-db &#8211;enablerepo=rpmforge</p>
<p>* <strong>Configure ClamAV and MailScanner Settings </strong></p>
<p>In /etc/freshclam.conf make the following edits:</p>
<p>Add &#8216;#&#8217; in front of the word &#8216;Example&#8217;</p>
<p>Do the same in /etc/freshclam.conf</p>
<p>Now you need to update ClamAV&#8217;s virus signature files</p>
<p>[root@smtp]# freshclam</p>
<p>ClamAV update process started at Fri Sep 19 12:45:42 2008<br />
main.cld is up to date (version: 48, sigs: 399264, f-level: 35, builder: sven)<br />
daily.cvd is up to date (version: 8287, sigs: 29596, f-level: 35, builder: arnaud)</p>
<p>Update MailScanner&#8217;s configuration file to use ClamAV</p>
<p>&#8216;Virus Scanners = clamav&#8217;</p>
<p>In MailScanner.conf, check the setting of &#8216;Monitors for ClamAV Updates&#8217; to ensure it matches the location of your ClamAV virus database files.</p>
<p>This should be &#8220;/var/clamav/*.cld /var/clamav/*.cvd&#8221;.</p>
<p>* <strong>Installing Postgrey </strong></p>
<p>yum install postgrey</p>
<p>*<strong> Configuring Postgrey </strong></p>
<p>Edit /etc/postfix/main.cf and add the following to smtpd_recipient_restrictions.</p>
<p>permit_mynetworks,<br />
reject_unauth_destination,<br />
reject_unlisted_recipient,<br />
check_policy_service unix:postgrey/socket</p>
<p>check_policy_service unix:postgrey/socket performs the greylisting while adding reject_unlisted_recipient before it enables Postfix to immediately reject unknown recipients instead of having clients go through the greylisting process before being informed that the recipient does not exist.</p>
<p>To disable greylisting for certain IP addresses or hostnames, add the IP address, hostname or regular expression to match hostnames into the file /etc/postfix/postgrey_whitelist_clients.local.</p>
<p>Hostnames are identified by performing a reverse DNS on the client’s IP address.</p>
<p>For sample entries, view the file /etc/postfix/postgrey_whitelist_clients.</p>
<p>* <strong>Update the system </strong></p>
<p>Make one last final update to make sure your system is updated.</p>
<p>yum update</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/09/setting-up-a-mail-relay-on-centos-5/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Swiss Army Knife for Your PC</title>
		<link>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/</link>
		<comments>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 19:29:22 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=169</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife.jpg"></a>Great article at <a href="http://lifehacker.com/397792/five-best-windows-maintenance-tools" target="_self">Lifehacker</a> on Windows maintenance tools that anyone wanting to run a healthy PC should have installed.</p> <p>Apart from <a href="http://www.ccleaner.com/" target="_blank">CCleaner</a>, <a href="http://www.revouninstaller.com/" target="_blank">Revo Uninstaller</a>, <a href="http://www.auslogics.com/disk-defrag" target="_blank">Auslogic Disk Defrag</a>, and <a href="http://www.safer-networking.org/en/spybotsd/index.html" target="_blank">Spybot</a> &#8211; Search &#38; Destroy, I would also add some in case virus/malware/spyware removal is required. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife.jpg"><img class="alignleft size-thumbnail wp-image-170" title="swiss-army-knife" src="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife-150x150.jpg" alt="" width="150" height="150" /></a>Great article at <a href="http://lifehacker.com/397792/five-best-windows-maintenance-tools" target="_self">Lifehacker</a> on Windows maintenance tools that anyone wanting to run a healthy PC should have installed.</p>
<p>Apart from <a href="http://www.ccleaner.com/" target="_blank">CCleaner</a>, <a href="http://www.revouninstaller.com/" target="_blank">Revo Uninstaller</a>, <a href="http://www.auslogics.com/disk-defrag" target="_blank">Auslogic Disk Defrag</a>, and <a href="http://www.safer-networking.org/en/spybotsd/index.html" target="_blank">Spybot</a> &#8211; Search &amp; Destroy, I would also add some in case virus/malware/spyware removal is required. <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx" target="_blank">RootKitRevealer</a>, <a href="http://lavasoft.com/" target="_blank">Ad-Aware</a>, <a href="http://www.majorgeeks.com/ATF_Cleaner_d4949.html" target="_blank">ATF-Cleaner</a>, <a href="http://swandog46.geekstogo.com/" target="_blank">Avenger</a>, <a href="http://majorgeeks.com/download3155.html" target="_blank">HijackThis</a> and <a href="http://www.simplysup.com/" target="_blank">Trojan Remover</a>.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

