Conficker Collateral Damage for March 2009
If you have a flight booked with Southwest Airlines on Friday March 13th, you may have difficulty checking in online — that’s when the Conficker worm will be calling it home.
To clarify, before outright blocking the 7750 Conficker call-home domains for the month of March, I dug into the giant list to see if the deterministic domain generation algorithm hit any existing non-malicious domains.
And good thing I did — on March 13th, the millions of machines infected with Conficker will be contacting wnsux.com for further instructions — they won’t get any, but that may certainly disrupt the operation of southwest.com — a reputable travel and tourism site that wnsux.com (also owned by Southwest Airlines) redirects to.
A legitimate domain that happens to make it into the Conficker call-home list is a problem for two reasons. First, without proper investigation, they may end up on a blocklist and prevent users from accessing their services. Second, those millions of Conficker infected machines contacting the domain on its given day may overload the site and essentially result in a denial-of-service attack.
Continue reading here....
Similar entries
- Why Web Site Security Matters to Us All
- A Few Quiet Days… and a New Exploit of MS08-067 Has Been Identified
- Conficker C / B++ Autoupdate Capabilities, Detection Tactics and Geometric Detection
- Conficker: a good excuse for an early spring cleaning
- Cleaning Conficker: Keeping Your Network Safe from Windows Worm
















Recent comments
30 weeks 5 days ago
33 weeks 2 days ago
1 year 2 weeks ago
1 year 2 weeks ago
1 year 2 weeks ago
1 year 18 weeks ago
1 year 34 weeks ago
2 years 25 weeks ago
2 years 26 weeks ago
2 years 28 weeks ago