<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IT Security Attaché &#187; Fixes</title>
	<atom:link href="http://theitsecurityattache.com/blogs/tag/fixes/feed/" rel="self" type="application/rss+xml" />
	<link>http://theitsecurityattache.com/blogs</link>
	<description>His life, profiles, work, aspirations, agenda and schedule.</description>
	<lastBuildDate>Mon, 26 Jul 2010 22:05:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Conficker&#8217;s cure? So what happens now? Is this the end, NO.</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:04:36 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[My Writings]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Blended Threats]]></category>
		<category><![CDATA[Conficker Worm]]></category>
		<category><![CDATA[Fixes]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[Media Players]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[QuickTime]]></category>
		<category><![CDATA[Signatures]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerable Apps]]></category>
		<category><![CDATA[Web Browsers]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=265</guid>
		<description><![CDATA[FYI&#8230; 
Original URL: http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/

Busted! Conficker&#8217;s tell-tale heart uncovered

Researchers find super worm cure, just in time
By Dan Goodin in San Francisco
Posted in Software &#38; Security, 30th March 2009 11:02 GMT
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
My thoughts, feedback and input.
You have a few hours to work on this and I know you’re going to be vigilant about it. Let’s save what and who [...]]]></description>
			<content:encoded><![CDATA[<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">FYI&#8230; </span></span></p>
<p class="orig-url" style="margin: auto 0in; line-height: 14.25pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="color: black; mso-ansi-language: EN;" lang="EN">Original URL: </span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a href="http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/"><span style="font-size: 12pt; color: purple; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/</span></a></span></span></span></p>
<p><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 15.5pt; color: #303030; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN;" lang="EN"></p>
<p class="MsoNormal" style="margin: 12pt 0in 3pt; mso-line-height-alt: 14.25pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18pt; color: #303030; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN">Busted! Conficker&#8217;s tell-tale heart uncovered</span></strong></p>
<p></span></strong></span></p>
<p class="standfirst1" style="margin: 0in 0in 3pt; line-height: 14.25pt;"><span style="font-family: Times New Roman;"><strong><span style="font-size: 13.5pt; color: #303030; mso-ansi-language: EN;" lang="EN">Researchers find super worm cure, just in time</span></strong><strong><span style="font-size: 13.5pt;"></span></strong></span></p>
<p class="byline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="color: black; mso-ansi-language: EN;" lang="EN">By </span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a title="Send email to the author" href="http://forms.channelregister.co.uk/mail_author/?story_url=/2009/03/30/conficker_signature_discovery/"><strong><span style="font-size: 12pt; color: #0000dd; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Dan Goodin in San Francisco</span></strong></a></span></span></span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;;"></span></p>
<p class="dateline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="font-family: Times New Roman;"><span style="font-size: small;"><span style="color: black; mso-ansi-language: EN;" lang="EN">Posted in </span><span style="color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a href="http://www.channelregister.co.uk/software_security/"><span style="font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Software &amp; Security</span></a></span></span><span style="color: black; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">, 30th March 2009 11:02 GMT</span></span></span></p>
<p class="dateline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="color: black; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</span></span></span></p>
<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">My thoughts, feedback and input.</span></span></p>
<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">You have a few hours to work on this and I know you’re going to be vigilant about it. Let’s save what and who we can with our best efforts. Time is of the essence so get to it. I will be a bit busy for the next few hours checking on new vendor signature releases and info about this, dealing with my internal network and doing some last minute checking and changes so please pardon any delays in my responses for a while.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">So now that signatures are being released for it is it over?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">No it’s not. This is a staged effort. The signatures will be created, disseminated throughout the various security scanners, anti-virus and anti-malware vendor products but then comes the updating and patching of the systems. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are running an older version of a vendor product I strongly suggest you upgrade it now.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are running any definitions other than March 31<sup>st</sup> 2009 for your anti-virus and anti-malware solution then you’re not fully protected yet.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are still missing Microsoft Windows patches (any and all of them) then there’s still some level of risk for you.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you’re running vulnerable applications like Adobe Reader, Acrobat, Firefox, iTunes, QuickTime, web browsers, media players and other applications check to make sure you’re not missing any vendor patches. The developers have released secure versions recently.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I still stick to my original take on this which is, if you are already infected just wipe and start over. There’s no real guarantee that you will fully get rid of the infection and the various pieces it comes with. If not, you have a good set of protective layers to work with.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Keep in mind that a signature based solution works off detecting via signature and not anomaly based threats. As Conficker is a blended threat, I expect to see some aspects of it still evading some security solutions if not configured properly for effective use. Some people have their solutions configured with out of the box settings which may not be optimally configured for a critical threat like this with such a rapid change effect rate.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I know this is short timing but it is good timing to get the word out and get people to act quickly. Be kind and help to spread the word to your family, friends, partners, associates, peers and anyone you converse with. This is critical info that needs to be shared.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Let’s get to it people. I’ve been up since Saturday helping people with their systems and talking about this and I plan to get some sleep over the next day or two.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Good luck and please keep me posted on any new developments and happenings around this once April 1<sup>st</sup> kicks in.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">~<strong style="mso-bidi-font-weight: normal;">Brett A. Scudder</strong>~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
