Archive for the ‘Virus’ Category

Using Linux to Detect Conficker

Wednesday, April 1st, 2009

I’ve got this from LinuxJournal. And to make the story short, install nmap-4.85BETA5 (download here) and run the command with parameters:

nmap -PN -d -p445 –script=smb-check-vulns –script-args=safe=1 [network_range]

where network range is either 192.168.10.1-255 or 192.168.10.0/24

and look for the results containing:

Host script results:
| smb-check-vulns:
| MS08-067: FIXED
| Conficker: Likely INFECTED
|_ regsvc DoS: VULNERABLE

or better yet, use grep to filter INFECTED and VULNERABLE

Conficker on April Fools’ Day

Tuesday, March 31st, 2009

I was surprised when I first read the news days ago and thought that it’s like a marketing stint from the developers/owners of Conficker (Downadup).

And to choose a release date that can cause confusion for some, is not funny. Really.

There are articles from Microsoft, Symantec, Dell and others stating that everyone has to be vigilant and ready for this new string of Conficker. Although some mentioned that its target are Windows XP and Vista, we can never tell.

Like always, there are preventive measures.

1. Update all security patches and AV definitions.
2. Be careful with what you do on the net.
3. Security, Firewall, Protection.

So now, let’s see what happens next. There’s nothing wrong with being ready for it rather getting caught unaware. Ayt!

Worm Threat Around the Globe

Wednesday, January 21st, 2009

The Corporate world is beginning to search for answers regarding a threatening news about Conficker, Kido, Downadup Worm that is infiltrating millions of Windows systems. Meanwhile, Microsoft released updates and patches to combat this issue. It is highly recommended to have updated systems and firewalls in order to prevent this from jeopardizing a business.

On the other hand, fear not my fellow Linux users. We are, somewhat, safe since Linux systems don’t have *.exe files in them that are used by this kind of threat.

And yet, good luck to all our Systems Administrators who might spend sleepless nights on restoring Windows Servers (if there are any) and to Technical Support Teams for clearing up Windows desktop computers that are infected and updating those that are yet to be.

Potential Friendster Virus

Saturday, December 27th, 2008

There have been Friendster Comments that seem to be rampant recently:

FS

And if you’ll notice your profile views, it doesn’t match with recent comments. Let me put it this way, on Tuesday, your profile views was 6. You checked your profile for any new comments then there’s none. The very next day, Wednesday, your profile views was still 6, then you checked again for comments and there you’ll see 1, 2 or more new entries and they are all the same but sent by different persons.

Correct me if I’m wrong but anyone won’t be able to add a testimonial/comment without viewing the person’s profile first. Unless Friendster’s counter is laid back.

In any case, the entries are somewhat suspicious. And if anyone here who thinks the same like I do or can share any information about it, please leave a comment on this post. It doesn’t hurt to be vigilant.

**Note: Please notice the word ‘potential’, this way I am not stating that this post is a fact. This is just based on my observation. And my aim to give everyone a headsup.