Showing posts with label Corporate Networks. Show all posts
Showing posts with label Corporate Networks. Show all posts

Monday, 11 December 2017

Conficker Worm Still Active On 150,000 Computers After 9 Years


The Conficker worm that infected nine million computers at its peak has been operating on 150,000 computers since its first appearance on 21 November 2008, anti-virus company Trend Micro said. Conficker is distributed in a variety of ways, including a vulnerability in the Windows Server service, shared network folders, and the Autorun feature of Windows.

The vulnerability in the Windows Server service was patched by Microsoft on October 23, 2008. In January 2009, Conficker also started distributing itself through the Autorun feature of Windows, something for which Microsoft released an update in February 2011. According to Trend Micro, Conficker is mainly active in China, Brazil and India. These three countries together account for more than half of all infections. Most infections were found in government systems, followed by production companies and health care.

After an infection, Conficker tries to connect every day with all kinds of domains to see if there are new instructions from the makers. ICANN, the organization that is responsible for the distribution of ip numbers and domains, has, however, taken measures so that these domains can not be registered. Thus, the infected computers can not be used for criminal purposes.

According to Trend Micro, Conficker can also be labeled as "background malware" that is mainly active on legacy systems. "Although it is not as interesting to the general public as more modern malware such as WannaCry and Petya, it remains a persistent threat and will remain so as long as unsupported, unpatched legacy systems are still part of corporate networks," says researcher the virus fighter .

Sunday, 16 August 2015

The Seven Deadly Sins Of System


System administrators play an important role in the prevention of attacks on their organization. However, there are arranged attacks in the news in which there is, for example, vulnerabilities have been used to infiltrate the corporate network for which for many years were available updates.

However, the security updates were not installed so employees by opening a document or visit a Web site became infected.This relates to old vulnerabilities in, for example Microsoft Office and Java regularly targeted. Among other targeted espionage attacks. Something recently the FBI warned . There are also other things that should have a system in place, or else run the risk organization. Reason for security GFI Software to a list of seven deadly sins to create system in which not installing security updates is called first.

The other mortal sins are using default configurations and passwords, working with admin rights, not documenting changes, IP addresses and license keys, no viewing log files, password sharing and finally the question of passwords. Often alerting system administrators and end users to phishing attacks say that they should never share their passwords, then himself to the user asking his password if there is a problem. End users should also never be asked for their password, according to the explanation of the last mortal sin.