io9

  • io9
  • science
  • overmind
  • kotaku
  • gizmodo
Profile logout login
12 Successful SF Authors Who've Written Racy Fanfic

12 Successful SF Authors Who've Written Racy Fanfic #romance3000 #slashfiction

Neither Snow Nor Sleet Can Stop This Week's Comics - Or Can They?

Neither Snow Nor Sleet Can Stop This Week's Comics - Or Can They? #comicswecrave #xmen

The Complete History Of Pandora, According To Avatar's Designers

The Complete History Of Pandora, According To Avatar's Designers #exclusive #avatar

This Week, io9 Plunges Into The Throbbing Future Of Love

This Week, io9 Plunges Into The Throbbing Future Of Love #specialfeature #romance3000

Dark Knight's Nolan To Reboot Superman?

Dark Knight's Nolan To Reboot Superman? #superman #thedarkknight

Goodbye, Heroes, Goodbye

Goodbye, Heroes, Goodbye #heroesrecap #heroes

Couch is Benjamin Parzybok's Slacker Odyssey

Couch is Benjamin Parzybok's Slacker Odyssey #bookreview #couch

io9

FAQ. Include # before tag:
#observationdeck, #tips, #calendar, etc.

San Francisco, 1:36 AM
Wed Feb 10
25 posts in the last 24 hours

IO9 TEAM

Tip your editors:

Editor-in-Chief:
Annalee Newitz |

News Editor:
Charlie Jane Anders |

Associate Editor:
Meredith Woerner |

Assistant Editor:
Lauren Davis |


Weekend Editor:
Graeme McMillan |

Contributors:
Joshua Glenn
Stephen Goldmeier |
Ed Grabianowski |
Austin Grossman
Paul Hogan |
Lauren Davis |
Chris Hsiang |
Lynn Peril |
Ann VanderMeer
Alasdair Wilkins |

Graphic Designer:
Stephanie Fox |

Interns:
Tim Barribeau |
Julia Carusillo |
Alex Eichler |
Cyriaque Lamar |
Caitlin Petrakovitz |
Mary Ratliff |
Josh Snyder |

More:
io9 on Facebook
follow io9 on Twitter

SUBSCRIBE TO IO9 RSS

New: Breaking news and daily top stories via email
1428 Subscribers


Please confirm your birth date:

Please enter a valid date
Please enter your full birth year
This content is restricted.

The Secret Origin Of The Conficker Worm

It snuck onto millions of computers in just a few months, and has been called "one of the most sophisticated pieces of malignant software ever seen" - but what, exactly, was the Conficker Worm all about? A new story explains.

New Scientist has a wonderful indepth article about how the Conficker Worm worked its way around the internet, and the steps taken by various internet security professionals to try and stop it:

Every day, the worm came up with 250 meaningless strings of letters and attached a top-level domain name - a .com, .net, .org, .info or .biz - to the end of each to create a series of internet addresses, or URLs. Then the worm contacted these URLs. The worm's creators knew what each day's URLs would be, so they could register any one of them as a website at any time and leave new instructions for the worm there.

It was a smart trick. The worm hunters would only ever spot the illicit address when the infected computers were making contact and the update was being downloaded - too late to do anything. For the next day's set of instructions, the creators would have a different list of 250 to work with. The security community had no way of keeping up.

No way, that is, until Phil Porras got involved. He and his computer security team at SRI International in Menlo Park, California, began to tease apart the Conficker code. It was slow going: the worm was hidden within two shells of encryption that defeated the tools that Porras usually applied. By about a week before Christmas, however, his team and others - including the Russian security firm Kaspersky Labs, based in Moscow - had exposed the worm's inner workings, and had found a list of all the URLs it would contact.

The back and forth between the Worm's creators, constantly reworking their code to get around the latest security upgrades, and the people working to break the Worm once and for all, is the kind of thing that nerdy blockbusters are made of - even if it ends on an unsatisfying moment that allows both sides to claim victory. What may be most eye-opening, however, is the suggestion that the Worm itself was just misdirection to make security experts look in the wrong place at the right time... and that the entire thing was just laying the groundwork for other people to make money. Go, read and feel very insecure about your Microsoft Updates.

The inside story of the Conficker worm [New Scientist]


Send an email to Graeme McMillan, the author of this post, at graeme@io9.com.


Upload an image | Add an image URL ×
×
×
Choose a file to upload:
×
Dsmvwl  Admin  Promote to frontpage Approve user Ban user ×
Loading comments ... -/|\
Earlier discussions Paging in progress... | Other discussions | Show all discussions | Show featured discussions only | Expand all threads Collapse all threads
Start a new discussion
By Graeme McMillan
Jun 13, 2009 10:00 AM 8,988 27
Edit » Set to Draft » Invite » Syndicate »

Syndicate this post


Site:
Mode:

sending request
cancel
more about #confickerworm
read more: #confickerworm, #internetsecurity
 
  • Archives
  • About
  • Advertising
  • Legal
  • Help
  • Report a Bug
  • FAQ
Original material is licensed under a Creative Commons License permitting non-commercial sharing with attribution.

Login

Enter your username and password.

Please enter a username.
Please enter your password.
logging in
Login via Facebook | Sign Up | Forgot Password?

Reset Password

Please enter your email address to have your password reset.

Please enter your email address.
Please enter a valid email address.
requesting password reset

Register

Registering will give you a user profile and the ability to add other users as friends. To become a commenter, however, you need to audition.

Want to know more? Consult the Comment FAQ and legal terms.

Please enter a username.
Please enter a password.
Please confirm your password.
Passwords are not identical.
Please enter a valid email address.
registration sent, waiting for reply

Submit Your Comment

You don't need to login to comment. Just enter your email address below.

See how your address will be displayed in the Comment FAQ.

Please enter a valid email address.
Please enter a valid email address.
logging in

Login with your Facebook or io9 account.

Sign up here.



Send An Invitation

To invite commenters to this page, paste in a list of comma-separated email addresses, and then select send invites.

Please enter at least one email address.
Please use valid email addresses.
Please use unique email addresses.
Please enter fewer addresses.
requesting invites

Send a link

Send a link to this post 'The Secret Origin Of The Conficker Worm' via email:

Please enter your name.
Please enter your email address.
Please enter a valid email address.
Please enter your recipient's email address.
Please enter a valid email address.
Please enter your message.
Sending message