<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; kido</title>
	<atom:link href="http://www.darknet.org.uk/tag/kido/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New Conficker Variant More Aggressive</title>
		<link>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/</link>
		<comments>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 09:38:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[enigma software]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1605</guid>
		<description><![CDATA[Conficker has gotten quite a lot of news recently with it growing so fast and Microsoft offering a bounty for the authors. It seems like the Conficker authors are really serious about retaining control of their botnet and expanding it further without hindrance from the companies trying to stop them. It&#8217;s quite likely they are [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a> has gotten quite a lot of news recently with it <a href="http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/">growing so fast</a> and <a href="http://www.darknet.org.uk/2009/02/microsoft-offers-250k-bounty-for-conficker-author/">Microsoft offering a bounty for the authors</a>.</p>
<p>It seems like the Conficker authors are really serious about retaining control of their botnet and expanding it further without hindrance from the companies trying to stop them.</p>
<p>It&#8217;s quite likely they are netting some serious cash from the network of infected computers, with estimates at over 10 million now that&#8217;s a large collection of computers for brute forcing, e-mail spam or DDoS attacks.</p>
<blockquote><p>The authors of the latest variant of the Conficker worm are upping the ante against security vendors who are working to stop the spread and threat of the persistent program.</p>
<p>Conficker.C shuts down security services, blocks computers from connecting to security Web sites, and downloads a Trojan. It also is programmed to begin connecting to 50,000 different domains on April 1 to receive updated copies or other malware, as opposed to connecting to 250 domains a day as previous versions are doing, Ben Greenbaum, senior research manager for Symantec Security Response, said on Friday.</p>
<p>The authors of the code are &#8220;strengthening their hold on their collection of infected machines at the same time they are attempting to strengthen their ability to control those machines by moving to 50,000 domains,&#8221; he said.</p>
<p>A self-described &#8220;cabal&#8221; of companies, including Microsoft, Symantec, and a host of domain registration providers, have been trying to thwart the efforts of Conficker by pre-registering and locking up the domain names being used by the worm to distribute updates.</p></blockquote>
<p>They are getting sneaky now, targeting security software and services on an infected PC and blocking it from accessing related sites that could help a user fix the infection.</p>
<p>Plus they have expanded their &#8216;update&#8217; domains to 50,000 &#8211; which will take a huge effort to get all of the domains blocked.</p>
<p>I wonder what the next step will be in protecting again this?</p>
<blockquote><p>Now that Conficker.C is targeting 50,000 domains, the group has its work cut out for it, Greenbaum said. Regardless, &#8220;it&#8217;s unknown at this point whether (boosting the domains) is an effective sidestep around the cabal&#8217;s actions,&#8221; he said.</p>
<p>The worm, also called Kido or Downadup, was first detected in November and is believed to have infected more than 10,000 computers. The first two versions exploit a vulnerability that Microsoft patched in October.</p>
<p>The second variant, Conficker.B, was detected last month. It added the ability to spread through network shares and via removable storage devices, like USB drives, through the AutoRun function in Windows.</p>
<p>Among the domains targeted by Conficker was that of Southwest Airlines, which was expected to see an increase in traffic from the botnet on Friday, Sophos said last week. However, a Southwest spokesman said there had been no impact to the site from any additional traffic as a result of Conficker. </p></blockquote>
<p>I hope this stays as just Conficker, if there&#8217;s another large scale breakout we might be in trouble again. There is a way to remove it though, so if you know anyone that has managed to get themselves infected you can give them the below links:</p>
<ul>
<li><a href="http://www.enigmasoftware.com/support/conficker-removal/">Enigma Software Group Conficker Removal Tool</a></li>
<li><a href="http://www.downadup.org/">BitDefender Conficker Removal Tool</a></li>
</ul>
<p></p>
<p>Source: <a href="http://news.cnet.com/8301-1009_3-10196122-83.html">Cnet</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=New+Conficker+Variant+More+Aggressive+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1605+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;t=New+Conficker+Variant+More+Aggressive" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F03%2Fnew-conficker-variant-more-aggressive%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/</link>
		<comments>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 16:34:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker virus]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware infections]]></category>
		<category><![CDATA[malware outbreak]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus infection]]></category>
		<category><![CDATA[virus outbreak]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417</guid>
		<description><![CDATA[There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines! It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines!</p>
<p>It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as whatever countermeasures come out, it can just download itself the latest version and bypass them.</p>
<p>It also has multiple infection vectors including traveling via USB drives.</p>
<blockquote><p>Infections of a worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is &#8220;skyrocketing&#8221;.</p>
<p>The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008. Anti-virus firm F-Secure estimates there are now 8.9m machines infected.  Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft&#8217;s MS08-067 patch.  In its security blog, F-Secure said that the number of infections based on its calculations was &#8220;skyrocketing&#8221; and that the situation was &#8220;getting worse&#8221;.</p>
<p>Speaking to the BBC, Graham Cluley, senior technology consultant with anti-virus firm Sophos, said the outbreak was of a scale they had not seen for some time.</p></blockquote>
<p>The virus targets the services.exe process (Server service) by exploiting the vulnerability associated with the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067</a> patch.</p>
<p>This was a serious remote execution flaw carried out by making a malformed RPC request, apparently it was reported &#8216;privately&#8217;. But now it seems that perhaps the details of the exploit weren&#8217;t that private after all.</p>
<blockquote><p>According to Microsoft, the worm works by searching for a Windows executable file called &#8220;services.exe&#8221; and then becomes part of that code.</p>
<p>It then copies itself into the Windows system folder as a random file of a type known as a &#8220;dll&#8221;. It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.</p>
<p>Once the worm is up and running, it creates an HTTP server, resets a machine&#8217;s System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker&#8217;s web site. Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down. But Conficker does things differently. </p></blockquote>
<p>It quite advanced even taking system restore out of the picture and downloading new files to update itself and to infect the machine further. It&#8217;s sneaky as it downloads from a bunch of seemingly randomly generated URLs making it very difficult to track and stop.</p>
<p>Many machines are infected in China, Brazil, Russia, and India &#8211; personally I think this is because piracy is rife in these areas and Microsoft doesn&#8217;t allow pirated copies of Windows to use Windows Update (especially with the WGA tool or Windows Genuine Advantage).</p>
<p></p>
<p>Source: <a href="http://news.bbc.co.uk/2/hi/technology/7832652.stm">BBC News</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1417+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;t=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fconficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

