 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; ms08-067</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/ms08-067/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Simple Conficker Scanner tool released &#8211; find the infected machines</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 15:32:22 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[detection]]></category>
		<category><![CDATA[diagnostic tools]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/</guid>
		<description><![CDATA[A Simple Conficker Scanner (SCS) tool has been released by members of the Honeynet Project. This tool can be run under linux or Windows. It runs a specially crafted RPC query against a host or range of IP addresses. The tool will tell if systems are clean or potentially infected. I am running this tool [...]]]></description>
				<content:encoded><![CDATA[<p>A <a href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/" target="_blank">Simple Conficker Scanner (SCS)</a> tool has been released by members of the <a href="http://www.honeynet.org/" target="_blank">Honeynet Project</a>. This tool can be run under linux or Windows. It runs a specially crafted RPC query against a host or range of IP addresses. The tool will tell if systems are clean or potentially infected. I am running this tool against hosts on my network and I found a Windows 2000 server apparently infected by Conficker. I am in the process of clean-up on that host. It looks like a couple of things contributed to the infection on this computer:</p>
<p>1. Out of date anti-virus. The antivirus signatures had not been updated since January 2008.</p>
<p>2. Microsoft patches not applied.</p>
<p>Folks, the advice about maintaining up-to-date AV and applying patches is good advice. Heed the warnings and save yourself some troubles of clean-up. I will be having a discussion with my operations team about this situation and make it clear that we should have been prepared for this and this situation should not have arisen.</p>
<p>I am also following the advice from McAfee on <a href="http://download.nai.com/products/mcafee-avert/documents/combating_w32_conficker_worm.pdf" target="_blank">Combating the Conficker worm</a></p>
<p>For more details on how the Conficker worm actually works, follow the links in my blog</p>
<h2><a title="Permanent Link to The Conficker Analysis - are you ready for April 1?" rel="bookmark" href="../the-conficker-analysis-are-you-ready-for-april-1/">The Conficker Analysis &#8211; are you ready for April 1?</a></h2>
<p>Thanks for reading. Let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
