<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sephem&#039;s Ubulwembu (web) Blog &#187; Security</title>
	<atom:link href="http://www.ubulwembu.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ubulwembu.com</link>
	<description></description>
	<lastBuildDate>Tue, 31 Mar 2009 23:31:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Conficker: Powerfull or Powerless?</title>
		<link>http://www.ubulwembu.com/2009/03/23/conficker-powerfull-or-powerless/</link>
		<comments>http://www.ubulwembu.com/2009/03/23/conficker-powerfull-or-powerless/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 17:46:46 +0000</pubDate>
		<dc:creator>Sephem</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[squarespace]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://ubulwembu.com/?p=9</guid>
		<description><![CDATA[Conficker was first seen in October 2008, but has gone through a few variants called conficker.a conficker.b and now the one to be activated on 1 April 2009 called conficker.c
Is this new variant going to be a crisis in the world of computers, or is it just going to flop like a bad April fools [...]]]></description>
			<content:encoded><![CDATA[<p><span><span>Conficker</span> was first seen in October 2008, but has gone through a few variants called <span>conficker</span>.a <span>conficker</span>.b and now the one to be activated on 1 April 2009 called <span>conficker</span>.c</span></p>
<p><span class="full-image-float-right ssNonEditable"><span><img src="/storage/post-images/virus.jpg?__SQUARESPACE_CACHEVERSION=1237836562255" alt="" /></span></span>Is this new variant going to be a crisis in the world of computers, or is it just going to flop like a bad April fools joke? <img class="size-thumbnail wp-image-10 alignright" title="virus" src="http://ubulwembu.com/wp-content/uploads/2009/03/virus-150x150.jpg" alt="virus" width="150" height="150" /></p>
<p><span>The <span>conficker</span> worm spreads itself primarily through a buffer overflow vulnerability in the Server Service on Windows computers. The versions of windows that are affected are Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and even Windows 7 Beta. The security bulletin can be read </span><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">here</a>.</p>
<p><span>Once it is activated, it does a few things, like disabling some services like Windows Defender, Windows security center and windows automatic update service.</span></p>
<p><span>It also connects to a server over the internet and gets some instructions that can gather information, install other malware amongst other things.</span></p>
<p><span>According to The <a href="http://bits.blogs.nytimes.com/2009/03/19/the-conficker-worm-april-fools-joke-or-unthinkable-disaster">New York Times</a>, </span></p>
<blockquote><p>An estimated 12 million or more machines have been infected. However, many have also been  disinfected, so a precise census is difficult to obtain.<span> </span></p></blockquote>
<p><span>There is still little consensus as to whether <span>conficker</span>.c is going to be something or nothing, so we will just need to wait and see.</span></p>
<p><span>It is highly suggested to keep your windows up to date and to make sure that your anti-virus has the latest definitions.</span></p>
<p><span>Due to the fact that the new version of <span>conficker</span> has highly evolved means of removing most <span>anti-virus</span> software packages, being able to disable Microsoft&#8217;s Automatic update service, open ports on firewalls and to even block access to the update services of most security software it is highly advised to download some removal tools before the anticipated date of activation.</span></p>
<p>Here are a few links to some removal tools.</p>
<p><a href="http://www.microsoft.com/security/malwareremove/default.mspx">Microsoft® Windows® Malicious Software Removal Tool</a><br />
<a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99">Symantic W32.Downadup Removal Tool</a><br />
<a href="http://www.sophos.com/products/free-tools/conficker-removal-tool.html">Sophos Tool</a></p>
<p><span>For a more details report on <span>Conficker</span>, take a look at SRI Internationals Technical report at <a href="http://mtc.sri.com/Conficker/">http://<span>mtc</span>.<span>sri</span>.com/<span>Conficker</span>/</a></span></p>
<!-- AdSense Now V1.53 -->
<!-- Post[count: 2] -->
<div class="adsense adsense-leadout" style="text-align:center;margin: 12px;"><script type="text/javascript"><!--
google_ad_client = "pub-8955050316184832";
/* 468x60, created 3/23/09 */
google_ad_slot = "1602999595";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div>]]></content:encoded>
			<wfw:commentRss>http://www.ubulwembu.com/2009/03/23/conficker-powerfull-or-powerless/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
