LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News
User Name
Password
Linux - News This forum is for original Linux News. If you'd like to write content for LQ, feel free to contact us.
All threads in the forum need to be approved before they will appear.

Notices


Reply
  Search this Thread
Old 03-27-2009, 06:06 PM   #1
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454
Blog Entries: 1

Rep: Reputation: 75
Fears of a Conficker Meltdown Greatly Exaggerated


Worries that the notorious Conficker worm will somehow rise up and devastate the Internet on April 1 are misplaced, security experts said Friday.

April 1 is the day that the worm is set to change the way it updates itself, moving to a system that is much harder to combat, but most security experts say that this will have little effect on most computer users' lives.

April 1 is what Conficker researchers are calling a trigger date, when the worm will switch the way it looks for software updates. The worm has already had several such trigger dates, including Jan. 1, none of which had any direct impact on IT operations, according to Phil Porras, a program director with SRI International who has studied the worm.

"Technically, we will see a new capability, but it complements a capability that already exists," Porras said. Conficker is currently using peer-to-peer file sharing to download updates, he added.

Gradually, the Conficker network will get updated, but this will take time, and nothing dramatic is expected to happen on April 1, according to Porras, Howard, and researchers at Secureworks and Panda Security.

"There is no clear evidence that the Conficker botnet will do anything dramatic," said Andre DiMino, cofounder of The Shadowserver Foundation, a volunteer security group. "It will change its domain usage to the larger pool and may attempt to drop another variant, but so far, that's about it."

Read full story.
 
Old 03-28-2009, 04:26 AM   #2
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Well darn, I was expecting it to do something dramatic, it looks like it will disappoint
 
Old 03-28-2009, 06:52 AM   #3
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454

Original Poster
Blog Entries: 1

Rep: Reputation: 75
Quote:
Originally Posted by H_TeXMeX_H View Post
Well darn, I was expecting it to do something dramatic, it looks like it will disappoint
I fear your day is coming, H- it's just a matter of when. What the experts don't know is what the authors are planning for this thing. Keep in mind, it may only take one 'update' to pass the instruction to wreak havoc, but they would need to select a later date to ensure all their bots are armed and ready. I think they may just be toying with the experts... at least for now.
 
Old 03-28-2009, 06:55 AM   #4
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware64 15; SlackwareARM-current (aarch64); Debian 12
Posts: 8,298
Blog Entries: 61

Rep: Reputation: Disabled
Let's all keep our fingers crossed that it will lead to the end of civilisation as we know it.
 
Old 03-28-2009, 06:58 AM   #5
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
lol, I dunno, you think it's possible ? How much damage could it cause ? It certainly looks like the creators are "evil geniuses" in a way. The way it works is truly something awesome, it's almost like the perfect worm.
 
Old 03-28-2009, 07:12 AM   #6
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454

Original Poster
Blog Entries: 1

Rep: Reputation: 75
Quote:
Originally Posted by H_TeXMeX_H View Post
It certainly looks like the creators are "evil geniuses" in a way. The way it works is truly something awesome, it's almost like the perfect worm.
Exactly.

All I can say is that I recall a few years ago when a 15 minute DDoS attack, generated by only a few thousand bots, booted Yahoo and affiliates offline for over 6 hours...
 
Old 03-28-2009, 07:27 AM   #7
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware64 15; SlackwareARM-current (aarch64); Debian 12
Posts: 8,298
Blog Entries: 61

Rep: Reputation: Disabled
When you think of how much we have come to depend on computers...
Whoever created that Conficker botnet/worm went to a great deal of trouble, so they must intend to use it for something big. I think all those experts are indulging in wishful thinking, they haven't any more idea about it than we have.
 
Old 03-28-2009, 07:49 AM   #8
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454

Original Poster
Blog Entries: 1

Rep: Reputation: 75
Quote:
Originally Posted by brianL View Post
When you think of how much we have come to depend on computers...
Whoever created that Conficker botnet/worm went to a great deal of trouble, so they must intend to use it for something big. I think all those experts are indulging in wishful thinking, they haven't any more idea about it than we have.
Well, they have decoded it, so they do know a little more than us.

But as far as what it will do, you are right. It's not in the code; it will have to come as an update. And to date, the botnet is over 10 million strong...
 
Old 03-28-2009, 07:49 AM   #9
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware64 15; SlackwareARM-current (aarch64); Debian 12
Posts: 8,298
Blog Entries: 61

Rep: Reputation: Disabled
Just found this:
http://www.theregister.co.uk/2009/03...ent_infection/
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Conficker will activate on April Fools H_TeXMeX_H Linux - News 13 05-01-2009 06:26 AM
LXer: Catching the Conficker Feckers LXer Syndicated Linux News 0 02-15-2009 07:30 AM
LXer: The reports of my death have been greatly exaggerated. -Mark Twain LXer Syndicated Linux News 1 10-10-2008 05:21 PM
LXer: Rumors of new Gnash functionality exaggerated LXer Syndicated Linux News 1 06-21-2007 08:46 PM
LXer: Rumored death of FreeDOS greatly exaggerated LXer Syndicated Linux News 0 07-03-2006 09:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - News

All times are GMT -5. The time now is 05:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration