News:

Holy shit, it's 2018 2019 2020 2021 2022 2023 2024, and the US isn't a fascist country! What a time to be alive.

Main Menu

How Wonderful...

Started by Lead, July 06, 2009, 07:02:50 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Lead

Company got hit with the Conficker worm while I was on vacation. Although it is not directly my job to address it, one could only assume with all the machines we have how long it is going to take to remedy the problem.

It is causing some major havoc on our AD servers for some reason... disabling accounts randomly... weird.


QuoteSon, if you really want something in this life, you have to work for it. Now quiet! They're about to announce the lottery numbers. - Homer Simpson

iago

Conficker tries to bruteforce passwords for fileshares -- that won't disable accounts, but it'll lock them out. Is that what you're seeing?

Lead

Quote from: iago on July 06, 2009, 08:38:23 AM
Conficker tries to bruteforce passwords for fileshares -- that won't disable accounts, but it'll lock them out. Is that what you're seeing?


Yes. I ran your SMB checks on some of my dev machines and what do you know, infected. Lots of production machines affected too. My Company = yearsbehind.com


QuoteSon, if you really want something in this life, you have to work for it. Now quiet! They're about to announce the lottery numbers. - Homer Simpson

iago

Fun stuff!

Make sure you patch machines and create strong passwords when you fix them, otherwise they'll get infected again. Also, you might consider temporarily banning USB devices from the network, Conficker will travel on those, too. That's the most likely way it'll initially get into a network.

Lead

Quote from: iago on July 06, 2009, 10:37:44 AM
Fun stuff!

Make sure you patch machines and create strong passwords when you fix them, otherwise they'll get infected again. Also, you might consider temporarily banning USB devices from the network, Conficker will travel on those, too. That's the most likely way it'll initially get into a network.


Not my department. I suggested to the security team that we patch the machines months ago in fear of the worm. But listen to me? No.


QuoteSon, if you really want something in this life, you have to work for it. Now quiet! They're about to announce the lottery numbers. - Homer Simpson

iago

Even if you're unpatched, having a firewall or filtering router should still prevent the attack. Few organizations let port 445 in at the border (though you never know!)

But, if you're unpatched, all it takes is one infected machine brought onto the network (or an infected USB stick) to introduce it. :)