On MovieTome: First Look: Jessica Alba in 'Machete'!
BNET Business Network:
BNET
TechRepublic
ZDNet

March 31st, 2009

McAfee fails the Conficker test

Posted by Ed Bott @ 8:55 am

Categories: Security

Tags: McAfee Inc., Security, Ed Bott

Update: 31-Mar, 4PM PDT: McAfee has corrected the errors on the web pages associated with its Stinger downloads. Joris Evers, McAfee’s director of worldwide PR, writes via e-mail: ” It’s unfortunate that you don’t like the way we present the Conficker information on our Web site, but there is a lot out there including a front page banner that leads to a landing page that went live early this week.” He points to the company’s main landing page for Conficker information, which contains a link to a Conficker-specific version of the Stinger tool, and to a 15-page PDF document entitled “Finding W32/Conficker.worm,” He also notes that McAfee’s Avert Labs has “blogged numeroius times about conficker.”

The hysteria over the Conficker worm is reaching a fever pitch, with mainstream media doing their bit to whip Windows users into an unjustified panic over something that will affect a tiny fraction of the user community, made up almost entirely of people who were too stupid or negligent to apply a Windows patch issued nearly six months ago.

Ironically, many security professionals are in the amusing position of having to tamp down the hysteria. See, for example:

The trouble with virus scares is that they do a wonderful job of driving people directly into the arms of rogue security vendors (thank you, F-Secure). What makes this phenomenon even worse is when one of the largest security companies in the world creates a website filled with sloppy mistakes that make it look exactly like a rogue vendor.

Yes, I’m talking about you, McAfee. Let’s go through the list.

For starters, McAfee’s W32/Conficker.worm information page is hosted at a very strange URL: http://vil.nai.com/vil/content/v_153464.htm. Now, an old-timer like me will remember that McAfee Inc. used to be Network Associates, Inc. (NAI) until about five years ago. So I didn’t find that nai.com domain too alarming. But a casual computer user certainly won’t know that obscure bit of corporate history, and the McAfee logo and name are splashed all over that page, even though the domain name is completely unrelated. You know, like rogue security sites do.

On its home page, under a bold red “BREAKING ADVISORY” head, McAfee has also helpfully noted that it has “posted a W32/Conficker-specific version of our Stinger tool.” Following that link takes you to the Avert Tools download page and then to a download page for the tool itself (many third-party sites link directly to this page). Like the  Conficker info page, the Stinger download page is hosted at nai.com even though the McAfee name is the only one used on the page. One IT pro I spoke with was convinced this was a bogus download after he went to the Stinger page, clicked the About Us link, and saw … well, see for yourself:

Sloppy website design or a rogue site? If you’re a nervous Windows user who’s been told that the world’s most dangerous computer worm is going to strike tomorrow, do you trust this site? Me neither.

And as long as we’re picking on sloppy web designers, take another look at the McAfee Secure logo in the upper right corner of that page. According to the logo, this page was last tested by the McAfee Secure service on November 5 (2008, I presume, but who knows?). For the record, that’s nearly five months ago. McAfee’s home page carries a current date in this spot.

Security is serious business, and details matter. When a company as large as McAfee is this sloppy with its public response to a high-profile issue, it makes you wonder how tightly the engineering, development, and support sides of the business are being operated.

My advice: If you’re looking for a reliable source of security information, skip McAfee.

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 129 Talkback(s)
And if millions of people are turning it off..
There must be SOMETHING wrong with it. Perceived or otherwise. (Read the rest)
Posted by: AzuMao Posted on: 04/07/09 You are currently: a Guest | | Terms of Use
Reliable Security Source  JT82 | 03/31/09
Reliable Security Source  Amelioration | 03/31/09
Oh snap  Ed BottZDNet Moderator | 03/31/09
I have done better than that.  Amelioration | 03/31/09
Waiting here...  Ed BottZDNet Moderator | 03/31/09
or...  wormtowndj | 03/31/09
Wormful Windows ...  Amelioration | 03/31/09
So would you agree  notsofast | 03/31/09
just downloaded the "latest" Stinger & it's old!  ITSecurityGuy | 04/01/09
pulsating platypus here... (nt)  pgit | 04/01/09
Or maybe Titilated Trouser Trout...? n/t  Wolfie2K3 | 04/02/09
Yeah - I tried Ubuntu...  TheWerewolf | 03/31/09
You can't get work done on Ubuntu?  Amelioration | 03/31/09
Or you could use boiling water, which is free...  DevJonny | 03/31/09
What was it exactly that you found was missing in Ubuntu?  InAction Man | 03/31/09
Lotsa half-baked software  Tony R. | 04/01/09
What a good little surfer!  marks055@... | 03/31/09
Photoshop? Is that the only arrow in your quiver?  Amelioration | 03/31/09
Good developers, you say?  jl2009 | 04/02/09
Take away Photoshop and what do they have?  hasta la Vista, bah-bie | 04/03/09
Talking to yourself?  InAction Man | 03/31/09
LOL  chas_2 | 04/01/09
Oh snap  AzuMao | 04/01/09
Oh, you mean the affected users  ITSecurityGuy | 04/01/09
Huh?  Ed BottZDNet Moderator | 04/01/09
Not only that but...  Wolfie2K3 | 04/02/09
Re: Huh?  AzuMao | 04/04/09
Oh Please  yumadome@... | 04/01/09
RE: Oh Please  computer_freak_8 | 04/01/09
Worth adding ...  Adrian Kingsley-HughesZDNet Moderator | 03/31/09
The patch will prevent infection via autoplay.  ye | 03/31/09
Autoplay affects  LiquidLearner | 03/31/09
And of course...  Ed BottZDNet Moderator | 03/31/09
Antivirus won't block something it doesn't know about  georgeou | 04/03/09
My assumption was Vista which would limit...  ye | 03/31/09
So that's why autoplayis not working on my machine!  Lerianis | 03/31/09
Microsoft Autoplay Repair Wizard  zmud | 03/31/09
Microsoft Autoplay Repair Wizard Repair Wizard.  Amelioration | 03/31/09
You just described the windoze ecosystem and their way of doing things.  InAction Man | 03/31/09
RE: McAfee fails the Conficker test  rpearson62@... | 03/31/09
Nope, not fixed  Ed BottZDNet Moderator | 03/31/09
So noted...  rpearson62@... | 03/31/09
McAfee fails period  jacarter3 | 03/31/09
The more things change...  Ed BottZDNet Moderator | 03/31/09
The more things change...  Amelioration | 03/31/09
Uh, no  Ed BottZDNet Moderator | 03/31/09
No I'm not afraid.  Amelioration | 03/31/09
Unless you use Netgear cards...  Sleeper Service | 03/31/09
My ethernet cards always worked, my wireless cards work  Amelioration | 03/31/09
IBM Rational Development Environment is...  DevJonny | 03/31/09
You must be living in an alternate reality  InAction Man | 03/31/09
Weird..  AzuMao | 04/01/09
I'm speaking from personal experience...  Sleeper Service | 04/02/09
I'm also speaking from personal experience...  AzuMao | 04/04/09
Whoopty doo  notsofast | 03/31/09
Black and white?  AzuMao | 04/01/09
linux  mizsaggy | 04/01/09
Sure Ubuntu must have some vulnerabilities just don't compare it with M$  InAction Man | 03/31/09
As, indeed, is the user volume.  Sleeper Service | 04/02/09
So.. Linux users are typically this illogical?  TheWerewolf | 03/31/09
"if you don't care about the end customer you don't survive"  Amelioration | 03/31/09
You say "Windows clearly isn't for everyone"??? Heresy.  InAction Man | 03/31/09
McAfee always fails... Period.  gamefreak9310 | 03/31/09
So, you based your decision on ONE virus!  ITSecurityGuy | 04/01/09
RE: McAfee Fails Period  denverjomo@... | 04/01/09
Can we just get rid of Symantec and McAfee?  TheWerewolf | 03/31/09
People say NAV is much better now.  LeoD | 03/31/09
I stopped using NAV and went to SEP.  NoThomas | 03/31/09
Yeah what he said  gcerny12 | 03/31/09
Surprisingly  LiquidLearner | 03/31/09
Another failure: The exe is not signed!  LeoD | 03/31/09
...plus they link to a PDF to provide a simple list.  LeoD | 03/31/09
Break out the latest beta compile of Nmap!  no_zd_user_name | 03/31/09
10 seconds of research  Joe_Raby | 03/31/09
"too stupid"...  mmagliaro | 03/31/09
Oh the windoze ecosystem. Isn't it fantastic?  InAction Man | 03/31/09
And how is this different than any other OS?  ye | 03/31/09
202 patches. How many of those were security patches?  InAction Man | 03/31/09
Here you go:  ye | 03/31/09
Very good, but how many of those were security patches?  InAction Man | 03/31/09
I gave you the means to answer your question.  ye | 03/31/09
How many?  InAction Man | 04/01/09
Argue with ye or with a traffic light, same result.  InAction Man | 04/01/09
@InAction Man: Again: I have provided you with all you need...  ye | 04/01/09
The crucial difference  AzuMao | 04/01/09
What a bogus claim!  ITSecurityGuy | 04/01/09
Nope  AzuMao | 04/04/09
Another wives tale.  ye | 04/01/09
More like deductive reasoning.  AzuMao | 04/04/09
Those who choose to turn it off  Ed BottZDNet Moderator | 04/05/09
And if millions of people are turning it off..  AzuMao | 04/07/09
So on your trips to Mexico  LiquidLearner | 03/31/09
"It's not stupidity or negligence."  Sleeper Service | 04/02/09
A "tiny fraction", Ed???  hasta la Vista, bah-bie | 04/02/09
Yup, a tiny fraction  rtk | 04/02/09
What are you talking about  hasta la Vista, bah-bie | 04/03/09
I could ask the same question.  rtk | 04/03/09
It was Ed who said a "tiny fraction" with certanity, not me  hasta la Vista, bah-bie | 04/03/09
Correct, but then you claimed a majority.  rtk | 04/03/09
Absolutely  hasta la Vista, bah-bie | 04/05/09
Ironically  rtk | 04/06/09
Hey I can't help it...  hasta la Vista, bah-bie | 04/06/09
Maybe there are.  AzuMao | 04/04/09
I'll do this slowly so you can understand  Ed BottZDNet Moderator | 04/04/09
RE: McAfee fails the Conficker test  gcerny12 | 03/31/09
Mcfee is the 2nd worst A/V we carry....  devlin_X | 03/31/09
McAfee reached its acme on DOS  Tony R. | 04/01/09
RE: McAfee fails the Conficker test  ing.chatboy@... | 03/31/09
hey Ed the link works ...... but mcafee still sucks  goldenpirate@... | 03/31/09
What if ......  goldenpirate@... | 03/31/09
Windows Fails the conflicker test.  Alan Smithie | 04/01/09
Alan fails the spelling test.  Sleeper Service | 04/02/09
And you pass the Muppet Test  Alan Smithie | 04/03/09
RE: McAfee fails the Conficker test  mwherman@... | 04/01/09
The screenshot text looks to be from a template from hostgator  shaddup | 04/01/09
Lorem ipsum is common "greek" text  Ed BottZDNet Moderator | 04/01/09
No, it isn't  cgiannac | 04/01/09
Picky, picky...  chas_2 | 04/01/09
Yes it is  Owen3.141 | 04/01/09
Well put, Ed!  chas_2 | 04/01/09
LOL  chas_2 | 04/01/09
Don't forget Avast!  chas_2 | 04/01/09
4 yrs, Avast hasn't let me down. My favorite Norton replacement.  invmgr@... | 04/01/09
I will 2nd that thought  Chris Z | 04/01/09
Avast 4.8 caused problems; 4.7 is OK  bobpeg | 04/01/09
I think they've fixed that issue now...  Sleeper Service | 04/02/09
RE: McAfee fails the Conficker test  weborglodge | 04/01/09
When will companies get it...  ITSecurityGuy | 04/01/09
I wish this was the only thing McAfee failed  YSB49 | 04/01/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement
Click Here

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and