 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; tdss</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/tdss/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>MS10-015 Reboots Solved?</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/ms10-015/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/ms10-015/#comments</comments>
		<pubDate>Sat, 13 Feb 2010 03:56:04 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[ms10-015]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[tdss]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=51</guid>
		<description><![CDATA[After a lot of discussion on the sans diary ( sans.isc.sans.org )  it appears the MS10-015 rebooting machines have been traced back to a root kit (Tdss), more information about it can be found at http://www.prevx.com/blog/139/Tdss-rootkit-silently-owns-the-net.html .  Emergingthreats.net has had signatures since Oct &#38; Jan 09 and from some of the reports out, the major [...]]]></description>
				<content:encoded><![CDATA[<p>After a lot of discussion on the sans diary ( sans.isc.sans.org )  it appears the MS10-015 rebooting machines have been traced back to a root kit (Tdss), more information about it can be found at http://www.prevx.com/blog/139/Tdss-rootkit-silently-owns-the-net.html .  Emergingthreats.net has had signatures since Oct &amp; Jan 09 and from some of the reports out, the major AV vendors are able to detect it as long as it is not running on the infected OS.</p>
<p>Now it&#8217;s going to be a race between system administrators to apply the MS10-015 to detect the root kit and the malware authors to update it so the patch won&#8217;t cause the system to blue screen and reveal the infection.</p>
<p>The number of reports of users having issues with the blue screen is surprising, cases like this are excellent reasons to have effective NIDS deployed.  Malware like Tdss needs to check in and when it does that it cannot hide anymore.</p>
<p>The full discussion is available here http://isc.sans.org/diary.html?storyid=8209#comment .</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/ms10-015/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
