Conficker Detection Breakthrough From Germany
Submitted
by
nandemoari
nandemoari writes "Tillmann Werner and Felix Leder, two German researchers from the Honeynet Project, figured out that the malware tries to patch the same security flaw (MS08-067) that it previously exploited. The binary patch NetpwPathCanonicalize — used by the Conficker/Downadup worm — works quite a bit differently, meaning that network scanners are able to pinpoint the existence of the malware.
The Honeynet Project released a proof of concept scanner that contains tools and information on containing the Conficker/Downadup worm.
Enterprise-class scanners from Tenable, McAfee, Nmap, Ncircle and Qualys are also available."