<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million</title>
	<atom:link href="http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: dblackshell</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125437</link>
		<dc:creator>dblackshell</dc:creator>
		<pubDate>Sun, 25 Jan 2009 18:05:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125437</guid>
		<description>Jhon
&lt;blockquote&gt;Apparently it uses a complex algorithm that is able to mutate or change makeing it hard to track&lt;/blockquote&gt;
When I read stuff like this it makes me laugh, because If malware authors would have to learn something from virus authors, than they should have learned Polymorphism, Metamorphism.

As for this case, I quite wonder of the &quot;complexity&quot; of the algorithm. I&#039;m no algorithm guru, but have studied some polymorphic viruses till now, so I would be hardly surprised.</description>
		<content:encoded><![CDATA[<p>Jhon</p>
<blockquote><p>Apparently it uses a complex algorithm that is able to mutate or change makeing it hard to track</p></blockquote>
<p>When I read stuff like this it makes me laugh, because If malware authors would have to learn something from virus authors, than they should have learned Polymorphism, Metamorphism.</p>
<p>As for this case, I quite wonder of the &#8220;complexity&#8221; of the algorithm. I&#8217;m no algorithm guru, but have studied some polymorphic viruses till now, so I would be hardly surprised.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jhon</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125432</link>
		<dc:creator>Jhon</dc:creator>
		<pubDate>Fri, 23 Jan 2009 17:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125432</guid>
		<description>I have a few friends who have caught this virus as they have found files on their USB that just appeared but when it gets inside your computer as the article says it alters itself. Apparently it uses a complex algorithm that is able to mutate or change makeing it hard to track. But according to the BBC the worst is yet to come. If the hackers decide to use the virus they can take full control over the systems. Thats if they choose to do it.</description>
		<content:encoded><![CDATA[<p>I have a few friends who have caught this virus as they have found files on their USB that just appeared but when it gets inside your computer as the article says it alters itself. Apparently it uses a complex algorithm that is able to mutate or change makeing it hard to track. But according to the BBC the worst is yet to come. If the hackers decide to use the virus they can take full control over the systems. Thats if they choose to do it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Extremesecurity</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125429</link>
		<dc:creator>Extremesecurity</dc:creator>
		<pubDate>Fri, 23 Jan 2009 10:31:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125429</guid>
		<description>Did Downadup/conficker attack your network? I&#039;ve created a batch file for system administrators to clean/patch/cure infected systems in their networks.

check it out here:

http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html</description>
		<content:encoded><![CDATA[<p>Did Downadup/conficker attack your network? I&#8217;ve created a batch file for system administrators to clean/patch/cure infected systems in their networks.</p>
<p>check it out here:</p>
<p><a href="http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html" rel="nofollow">http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Olafur</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125422</link>
		<dc:creator>Olafur</dc:creator>
		<pubDate>Wed, 21 Jan 2009 10:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125422</guid>
		<description>I must say that hackers to day, that do this are insanly smart :P 

But this virus, and every virus. Can they travel to your computer for no reason (saying you didn&#039;t click on a download), like finding your IP and just going into your computer ? 
Just wondering because I haven&#039;t had a virus protection on my computer for the last year and not a single virus, just simple cookies ?</description>
		<content:encoded><![CDATA[<p>I must say that hackers to day, that do this are insanly smart :P </p>
<p>But this virus, and every virus. Can they travel to your computer for no reason (saying you didn&#8217;t click on a download), like finding your IP and just going into your computer ?<br />
Just wondering because I haven&#8217;t had a virus protection on my computer for the last year and not a single virus, just simple cookies ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125420</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Tue, 20 Jan 2009 23:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125420</guid>
		<description>I am of the opinion if you can&#039;t afford/don&#039;t want to pay for windows then go Linux. At least then you get updates, and will have less issues. Windows is good, but if you don&#039;t get updates due to a cracked version then you are part of the problem.
All my windows machines have this update, and I have seen this virus in the wild on a USB stick, it is a nasty one.</description>
		<content:encoded><![CDATA[<p>I am of the opinion if you can&#8217;t afford/don&#8217;t want to pay for windows then go Linux. At least then you get updates, and will have less issues. Windows is good, but if you don&#8217;t get updates due to a cracked version then you are part of the problem.<br />
All my windows machines have this update, and I have seen this virus in the wild on a USB stick, it is a nasty one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125410</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Mon, 19 Jan 2009 20:00:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125410</guid>
		<description>There appears to be some discrepancies at to the true number of infected machines, with some reports citing 500,000 unique IP addresses infected.

I don&#039;t think it matters too much whether it was reported privately or not; once the hotfix is released it will be diffed to see what was fixed from the previous version. From there it is not difficult to work out how to exploit the vulnerability.

I am not suprised that such a large number of machines are unpatched, given the WGA. Microsoft is damned if they do and damned if they don&#039;t. If all Windows was patched, there would be little effect from this but that would mean Microsoft would have to accept that there are unlicensed copies out there. As it is, there is now more ammo for the &#039;Microsoft is insecure&#039; brigade due to the fact that Microsoft won&#039;t allow patches for rogue systems.
That said, I was talking to a guy whose organisation had been hit and their copies of Windows were licensed unfortunately, their patching policy was &#039;ineffective&#039;!</description>
		<content:encoded><![CDATA[<p>There appears to be some discrepancies at to the true number of infected machines, with some reports citing 500,000 unique IP addresses infected.</p>
<p>I don&#8217;t think it matters too much whether it was reported privately or not; once the hotfix is released it will be diffed to see what was fixed from the previous version. From there it is not difficult to work out how to exploit the vulnerability.</p>
<p>I am not suprised that such a large number of machines are unpatched, given the WGA. Microsoft is damned if they do and damned if they don&#8217;t. If all Windows was patched, there would be little effect from this but that would mean Microsoft would have to accept that there are unlicensed copies out there. As it is, there is now more ammo for the &#8216;Microsoft is insecure&#8217; brigade due to the fact that Microsoft won&#8217;t allow patches for rogue systems.<br />
That said, I was talking to a guy whose organisation had been hit and their copies of Windows were licensed unfortunately, their patching policy was &#8216;ineffective&#8217;!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comment-125409</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Mon, 19 Jan 2009 17:15:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417#comment-125409</guid>
		<description>cheers!! :)</description>
		<content:encoded><![CDATA[<p>cheers!! :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

