<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Open Source Software and Linux &#187; downadup</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/linux-lotus-domino/tag/downadup/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino</link>
	<description></description>
	<lastBuildDate>Thu, 02 May 2013 21:07:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>And you thought conficker was dead</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 18:55:02 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[Conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/</guid>
		<description><![CDATA[The conficker worm that infected millions of computers starting last October was believed to be at bay. Not so according to Vincent Weafer, vice president of Symantec&#8217;s security response group. Computers infected with this worm are being updated with a stronger variant. The variant is designed to sidestep security measures attempting to cut the connection [...]]]></description>
				<content:encoded><![CDATA[<p>The conficker worm that infected millions of computers starting last October was believed to be at bay.  Not so according to Vincent Weafer, vice president of Symantec&#8217;s security response group.</p>
<p>Computers infected with this worm are being updated with a stronger variant.  The variant is designed to sidestep security measures attempting to cut the connection between infected machines and it&#8217;s hacker controllers.  An estimated 20 technology companies, including Microsoft, have joined together to try and counter the stronger variant.</p>
<p>They are attempting to stop the worm by pre-registering domains that they believe the worm will use.  According to Symantec and others in the group the worm can register up to 50,000 domain names a day.  The domains are used to band together the infected computers and route the worm to other computers for infection.</p>
<p>The new worm is also better at resisting eradication.  &#8220;It&#8217;s turning off a variety of security services,&#8221; Weafer said, as well as tools often used by security companies to dig into malware.</p>
<p>Weafer also believe that the number of infected computers has peaked.  &#8220;The number of infected machines is constantly dropping, so we&#8217;re dealing with a much smaller pool [of devices] that are potentially getting this update,&#8221; Weafer said.</p>
<p>There is bright side to all of this.  Linux users don&#8217;t have to worry about this.  We don&#8217;t need to download Microsoft&#8217;s patch to fix our machines.  What is really glaring is that so far as I know there are no open source companies joined to the group to protect the Windows computer.  Maybe they should consult with them and teach them how to write software that is not so susceptible to attacks like this.</p>
<p>This whole thing started because of a security vulnerability in the Microsoft OS.  When are Microsoft users and companies going to wake up and realize how expensive it is to continue using this brain dead OS?  FWIW my definition of brain dead is an OS that has users, administrators and anyone else who uses the machine pointing and clicking to set up the OS and not knowing what they just did.  No wonder that OS gets attacked so much.</p>
<p>If you have a Microsoft machine that is infected what you need is the MS08-067 security update.  You&#8217;ll have to look it up yourself &#8211; I have no need for it.  You can read more about this fiasco <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9129239&amp;intsrc=hm_list">here</a>.</p>
<p>I&#8217;ll stick with my Linux and Open Source software thank you very much.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft offers $250,000 for conviction of Conficker authors</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/microsoft-offers-250000-for-conviction-of-conficker-authors/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/microsoft-offers-250000-for-conviction-of-conficker-authors/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 14:00:02 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[downup]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/?p=168</guid>
		<description><![CDATA[Microsoft has announced a $250,000 reward for the arrest and conviction of the authors of the Conficker worm, also known as Downadup. Apparently Microsoft feels that not enough is being done by Windows administrators to stop the infestation and propagation of this worm. F-Secure, an anti-virus software vendor, reported in January of this year that [...]]]></description>
				<content:encoded><![CDATA[<p>Microsoft has announced a $250,000 reward for the arrest and conviction of the authors of the Conficker worm, also known as Downadup.</p>
<p>Apparently Microsoft feels that not enough is being done by Windows administrators to stop the infestation and propagation of this worm.  F-Secure, an anti-virus software vendor, reported in January of this year that almost 9 million PCs had been infected.  The worm was released in the fall of 2008.</p>
<p>The worm exploits a buffer overflow in the Windows Server Service.  By doing so it attacks the Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting services. Afterwards it connects to an external server where it receives instructions to further propagate.   While connected to the external server it downloads more malware that affects other Windows processes including svchost.exe, explorer.exe and services.exe.</p>
<p>Microsoft released a patch (MS08-067) in the fall of 2008 to fix the vulnerability.  Microsoft, Symantec and Kaspersky Labs also have patches to repair systems.  McAfee offers an on demand scan to remove the worm.  The virus can spread via any drive that uses autorun including USB drives.  Many vendors are recommending disabling the AutoRun feature for external media through modifying the Windows Registry.  Note that if you are using anything earlier than Windows XP Service Pack 2 or Windows 2000 SP4 a patch is not available.  Sorry.</p>
<p>Linux and Mac computers are not affected by this worm.  It is designed to exploit only computers running the Windows operating system.</p>
<p>Now that we have the background two questions come to mind.  Why are the adminstrators not repairing these systems and, an even bigger question, how in the world are these infected machines able to provide the network services that they have been set up to perform?</p>
<p>I think that I&#8217;ll stick with my Linux and Solaris machines where the chances of something like this happening are slim.  And if it does the patches generally aren&#8217;t limited to a certain version of the operating system especially if you are using enterprise grade software such as Red Hat, CentOS, Ubuntu, SuSE or Solaris.  These companies all offer 5 to 7 years of security patches on their enterprise versions.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/microsoft-offers-250000-for-conviction-of-conficker-authors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
