A few months ago I shared some information about checking for Conficker with nmap. Unfortunately, it turns out that post was out of date pretty quickly. Whoops. How about some updates?
From the nmap changelog page:
New Conficker versions eliminate the loophole we were using to detect them with smb-check-vulns,nse, so we’ve added new methods which work
Continue reading Conficker Detection: Updated
Now here’s a clever idea. Since the Conficker virus likes to block access to certain sites, a fellow named Joe Stewart from the Conficker Working Group created this slick little eye chart.
Each image is hot-linked from the represented site. Thus, if you have any images blocked, you might have Conficker – and from the diagnosis
Continue reading Conficker Eye Chart
I wasn’t going to write a Conficker post, but I had so much fun playing with nmap today that I caved in…
This afternoon I decided that it would be prudent to make a quick scan of the corporate networks for signs of Conficker-ness. I knew from Dan Kaminsky’s recent “Taming Conficker” that I should be
Continue reading Conficker, Nmap and What I sent to the Office