On CBS.com: You a Race Fan?Play Amazing Race Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet

March 30th, 2009

German researchers score Conficker detection breakthrough

Posted by Ryan Naraine @ 7:06 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Malware, Microsoft, Patch Watch, Research, Responsible disclosure, Viruses and Worms, Vulnerability research, Windows Vista

Tags:

Just days ahead of an April 1st activation date for the Conficker worm squirming through the Windows operating system, security researchers at the Honeynet Project have scored a major breakthrough, finding a way to fingerprint the malware on infected networks.

Now, with the help of Dan Kaminsky and Rich Mogull, off-the-shelf network scanning vendors have the ability remotely (and anonymously) detect Conficker infections.

“You can literally ask a server if it’s infected with Conficker, and it will tell you,” Kaminsky explained.  “Usually, we get to scan for a vulnerability but, because Conficker actually changes the way that Windows looks on a network, we now get to scan and get a “this box is infected” message which is pretty rare.”

[ SEE: CBS 60 Minutes covers Conficker, malware epidemic ]

All the credit for the breakthrough goes to the Honeynet Project’s Tillmann Werner and Felix Leder, two German researchers who figured out that malware tries to patch the same security flaw (MS08-067) that it exploited during the initial infection.  Conficker uses a binary patch — NetpwPathCanonicalize() works quite a bit differently — which means that network scanners can pinpoint the existence of the malware.

The Honeynet Project has released proof of concept scanner and, later today (March 30th), enterprise-class scanners are expected to follow suit.  They will include Tenable (Nessus), McAfee/Foundstone, nmap, ncircle, and Qualys, Kaminsky said.

The nmap scanner is freely available.

The Conficker malware is programmed to generate thousands of domain names a day and, on April 1st, infected machines will start calling home to the authors for further instructions.  However, as Joe Stewart explains, this does not mean there will be a computer meltdown on April 1.

Here’s why you shouldn’t fear the worm’s activation date:

  • Conficker.C is already able to receive updates via its P2P protocol today, so focusing on the April 1st date is misguided.
  • Don’t underestimate the reach of the Conficker Working Group. These are the security industry’s heavy-hitters, and you can be sure they are working diligently to mitigate the domain issue.
  • Even though there are 50,000 domains to look at, they are being closely monitored, and if any malicious servers do appear, they will likely be taken down or null-routed very quickly.
  • If the author(s) of Conficker planned some massive update of malicious code, they certainly wouldn’t do it on the one day everyone is watching for it.

For the best analysis of what Conficker is — and isn’t — read this detailed analysis by SRI International.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 90 Talkback(s)
RE: German researchers score Conficker detection breakthrough
Is that guys name for real ? Rich Mogull ? thats good ! (Read the rest)
Posted by: sprocket2 Posted on: 04/23/09 You are currently: a Guest | | Terms of Use
I think they meant March 30  neppechr@... | 03/30/09
Yes, March 30  Ryan NaraineZDNet Moderator | 03/30/09
Congratulations  kozmcrae | 03/30/09
It should be obvious:  Qbt | 03/30/09
re: It should be obvious to you  n0neXn0ne | 03/30/09
What goes against logic  GuidingLight | 03/30/09
re: What goes against logic ...  n0neXn0ne | 03/30/09
Really???  storm14k | 03/30/09
Really!!  Too Old For IT | 03/30/09
We could train the CEO's admin  alpyne2@... | 03/30/09
Done  CTRLurself | 03/30/09
Get over it!  InAction Man | 03/30/09
Must suck...  justanitguy | 03/30/09
Microsoft are unable to secure Windows machines.  Amelioration | 03/31/09
safe machines  erik.soderquist | 03/30/09
could just put a mac user in charge to make inoperable  Pembo | 03/30/09
Except that ...  MisterMiester | 03/30/09
Linux is good.  kozmcrae | 03/30/09
Because it allows users to do what they want to do...  DevJonny | 03/30/09
re: Because it allows users ...  n0neXn0ne | 03/30/09
You realize, of course  NickNielsen | 03/30/09
I realize, of course, that you are way off topic ...  n0neXn0ne | 03/30/09
I just read it.  InAction Man | 03/30/09
Can't stand criticism huh?  InAction Man | 03/30/09
Allowing users to do what they want to do  Too Old For IT | 03/30/09
It doesn't matter what you can compile if you can't run it.  Zogg | 03/30/09
No ...  Amelioration | 03/31/09
$600 vs $2500, logic...  Pembo | 03/30/09
*Not a fanboy*  CTRLurself | 03/30/09
What do these statements achieve  jntshumaker@... | 03/30/09
Agreed  pbcasey | 03/30/09
I Agreed too ...  n0neXn0ne | 03/30/09
Those who lose the contest will always complain. of course.  InAction Man | 03/30/09
That's an interesting justification.  InAction Man | 03/30/09
right  dcdavy | 03/30/09
"The adults need to get back to work now . . ."  brian ansorge | 03/30/09
Sor of...  riltle | 03/30/09
You clearly don't understand that contest  DeusExMachina | 03/30/09
You are totally right  NonZealot | 03/30/09
ad hominem  DeusExMachina | 03/30/09
A safe windows machine is a powered-off windows machine.  InAction Man | 03/30/09
actually, you're wrong  dcdavy | 03/30/09
No external connection & no removable media  alpyne2@... | 03/30/09
Is this kind of like...  John L. Ries | 03/30/09
Link for nmap would be appreciated  ancientt@... | 03/30/09
nmap  reason2008 | 03/30/09
Thanks and a reference link  ancientt@... | 03/30/09
Also this...  JCitizen | 03/31/09
RE: German researchers score Conficker detection breakthrough  warnerc3 | 03/30/09
RE: German researchers score Conficker detection breakthrough  deanders | 03/30/09
Best way to check one's computers quickly?  alanmcrae@... | 03/30/09
Yes!  Alan Balkany | 03/30/09
The best (fastest) way to check  Ryan NaraineZDNet Moderator | 03/30/09
Is the reverse true?  rapson | 03/30/09
If you use Linux...  kozmcrae | 03/30/09
way to check  reason2008 | 03/30/09
This surprises you?  wcb42ad | 03/31/09
RE: German researchers score Conficker detection breakthrough  alvinc6689@... | 03/30/09
Check?  cretanion | 03/30/09
Kaspersky  davidhite | 03/30/09
But can they reverse the damage?  Too Old For IT | 03/30/09
RE: German researchers score Conficker detection breakthrough  thezipperr@... | 03/30/09
Payload is triggered on & AFTER April 1st!  jeanpaul.fernandes@... | 03/30/09
changing the date on your PC will NOT work... here is why  SecurityQNow | 03/30/09
what does one do if their PC is infected by this code?  lwvirden | 03/30/09
Get an Apple  cretanion | 03/30/09
Go here..  JCitizen | 03/31/09
Dan Kaminsky and The Germans Save the day  dunn@... | 03/30/09
let's track down the bad guys and hang them!  AtlantaTerry | 03/30/09
Nice exageration  Erroneous | 03/30/09
Hangin' is too good for their kind!  Too Old For IT | 03/30/09
reward was $250,000.00 US for the *arrest*  SecurityQNow | 03/30/09
When will we make hosting companies responsible?  No_Ax_to_Grind | 03/30/09
*virii (or: please god make it stop!!!) REPRISE  DeusExMachina | 03/30/09
Thank you.  kozmcrae | 03/30/09
Yes, they should be responsible and start blocking all windows clients  InAction Man | 03/30/09
Easier said than done  CobraA1 | 03/30/09
RE: German researchers score Conficker detection breakthrough  tender rouge | 03/30/09
Conficker clean-up tool on Sophos  elliemk@... | 03/30/09
You link doesn't work.  phatkat | 03/30/09
Just take the whack off the end  ejhonda | 04/09/09
Must Read the Report  DarienHawk67 | 03/30/09
we pull and push updates every tuesday. This just backs me up.  Been_Done_Before | 03/30/09
Yep!  davidhite | 03/30/09
RE: German researchers score Conficker detection breakthrough  kb0lkt@... | 03/30/09
RE: German researchers score Conficker detection breakthrough  Mnighthawk | 03/30/09
RE: German researchers score Conficker detection breakthrough  SecurityQNow | 03/30/09
RE: German researchers score Conficker detection breakthrough  SecurityQNow | 03/30/09
What, punish your precious Microsoft?  Bruizer | 03/31/09
RE: German researchers score Conficker detection breakthrough  sprocket2 | 04/23/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and