<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IBM ISS cracks open Conficker&#8217;s secret communications code</title>
	<atom:link href="http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/feed/" rel="self" type="application/rss+xml" />
	<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Sun, 05 Sep 2010 13:14:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Chester Wisniewski</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-420</link>
		<dc:creator>Chester Wisniewski</dc:creator>
		<pubDate>Sun, 26 Apr 2009 23:49:46 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-420</guid>
		<description>As a security analyst at Sophos, I can understand IBM&#039;s position on this issue. Conficker&#039;s authors have reacted faster and more aggressively to defend their command and control than any other recent malware writers. The anti-virus, anti-spam, and other security related industries have established methods for communicating sensitive information and samples in place, and although I have no specific insight to this particular topic, I hope and expect IBM to &quot;do the right thing&quot;.

Chet</description>
		<content:encoded><![CDATA[<p>As a security analyst at Sophos, I can understand IBM&#8217;s position on this issue. Conficker&#8217;s authors have reacted faster and more aggressively to defend their command and control than any other recent malware writers. The anti-virus, anti-spam, and other security related industries have established methods for communicating sensitive information and samples in place, and although I have no specific insight to this particular topic, I hope and expect IBM to &#8220;do the right thing&#8221;.</p>
<p>Chet</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RSA attendee</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-416</link>
		<dc:creator>RSA attendee</dc:creator>
		<pubDate>Sat, 25 Apr 2009 02:07:54 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-416</guid>
		<description>Today&#039;s presentation &quot;A Look at Conficker and Other Recent Internet Malware&quot; was a nice complimentary review to Yason&#039;s research.  Most fascinating was Conficker&#039;s design to use bleeding edge encryption to ensure accurate replication in other machines.  Colleague Phil Porras from SRI&#039;s Computer Science Laboratory was commended for providing a comprehensive brief to audience.</description>
		<content:encoded><![CDATA[<p>Today&#8217;s presentation &#8220;A Look at Conficker and Other Recent Internet Malware&#8221; was a nice complimentary review to Yason&#8217;s research.  Most fascinating was Conficker&#8217;s design to use bleeding edge encryption to ensure accurate replication in other machines.  Colleague Phil Porras from SRI&#8217;s Computer Science Laboratory was commended for providing a comprehensive brief to audience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HillDozer</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-401</link>
		<dc:creator>HillDozer</dc:creator>
		<pubDate>Tue, 14 Apr 2009 15:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-401</guid>
		<description>The problem is &quot;cracking the p2p network&quot; could mean a lot of things.  

Yason might have complete mastery of the protocol, or might have just identified enough to build a basic IDS signature for one of the packets.

Without peer review, nobody knows.</description>
		<content:encoded><![CDATA[<p>The problem is &#8220;cracking the p2p network&#8221; could mean a lot of things.  </p>
<p>Yason might have complete mastery of the protocol, or might have just identified enough to build a basic IDS signature for one of the packets.</p>
<p>Without peer review, nobody knows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jimny Cricket</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-393</link>
		<dc:creator>Jimny Cricket</dc:creator>
		<pubDate>Mon, 13 Apr 2009 02:02:50 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-393</guid>
		<description>If IBM knows the secret chat channel for Conficker, why don&#039;t they just send a command along that channel to have all of the bots uninstall and erase Conficker from themselves?

:)</description>
		<content:encoded><![CDATA[<p>If IBM knows the secret chat channel for Conficker, why don&#8217;t they just send a command along that channel to have all of the bots uninstall and erase Conficker from themselves?</p>
<p> <img src='http://lastwatchdog.com/wp/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mumbo</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-360</link>
		<dc:creator>Mumbo</dc:creator>
		<pubDate>Tue, 07 Apr 2009 04:51:26 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-360</guid>
		<description>If you&#039;ve every seen the exploits on the heels of a patch announcement, I think you&#039;ll understand why *all* security researchers are cautious about full disclosure. I don&#039;t expect that any other security company would react differently. I think Stewart&#039;s statement made perfect sense:

&quot;Big Blue decided, as one might expect, against full public disclosure.  “We don’t want the wrong people to use it against our customers,” says Stewart. “If the Conficker writers know exactly what we’ve done to detect their communications, they’ll change it. Our customers are first and foremost in our mind.”&quot;</description>
		<content:encoded><![CDATA[<p>If you&#8217;ve every seen the exploits on the heels of a patch announcement, I think you&#8217;ll understand why *all* security researchers are cautious about full disclosure. I don&#8217;t expect that any other security company would react differently. I think Stewart&#8217;s statement made perfect sense:</p>
<p>&#8220;Big Blue decided, as one might expect, against full public disclosure.  “We don’t want the wrong people to use it against our customers,” says Stewart. “If the Conficker writers know exactly what we’ve done to detect their communications, they’ll change it. Our customers are first and foremost in our mind.”&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Nagel</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-356</link>
		<dc:creator>David Nagel</dc:creator>
		<pubDate>Mon, 06 Apr 2009 14:28:47 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-356</guid>
		<description>Nice work XFORCE! Giddyup!</description>
		<content:encoded><![CDATA[<p>Nice work XFORCE! Giddyup!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C. Manson</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-332</link>
		<dc:creator>C. Manson</dc:creator>
		<pubDate>Thu, 02 Apr 2009 19:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-332</guid>
		<description>Kudos to IBM!  Unlike Marley, I think that most people understand propietary ownership of the research is essential to security as well as capiltalism.  Why would IBM share what their researchers discovered?  If they share that with us then they share that with everyone including the bad guys.  Congrats to IBM on the break through.  I look forward to &quot;not&quot; knowing how Yason did it.</description>
		<content:encoded><![CDATA[<p>Kudos to IBM!  Unlike Marley, I think that most people understand propietary ownership of the research is essential to security as well as capiltalism.  Why would IBM share what their researchers discovered?  If they share that with us then they share that with everyone including the bad guys.  Congrats to IBM on the break through.  I look forward to &#8220;not&#8221; knowing how Yason did it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marley Wylie</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-330</link>
		<dc:creator>Marley Wylie</dc:creator>
		<pubDate>Thu, 02 Apr 2009 15:57:51 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-330</guid>
		<description>Kudos to Yason and a rasberry to IBM. Witholding information in order to gain advantage over competitors may be sensible business but it leaves innocent users in the lurch. When there is a threat to all users it should be fought for the sake of all not for the profit of just one organization. The name &quot;Quisling&quot; comes to mind here.</description>
		<content:encoded><![CDATA[<p>Kudos to Yason and a rasberry to IBM. Witholding information in order to gain advantage over competitors may be sensible business but it leaves innocent users in the lurch. When there is a threat to all users it should be fought for the sake of all not for the profit of just one organization. The name &#8220;Quisling&#8221; comes to mind here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Melih Abdulhayoglu</title>
		<link>http://lastwatchdog.com/ibm-iss-cracks-open-confickers-secret-communications/#comment-327</link>
		<dc:creator>Melih Abdulhayoglu</dc:creator>
		<pubDate>Wed, 01 Apr 2009 20:04:13 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=1260#comment-327</guid>
		<description>Hats off to Mark Yason for cracking Conficker&#039;s protocol--but what a shame that he needed to do so.  We already have the tools to prevent worms like Conficker from infecting us.  

Instead of detecting it after it installs, let&#039;s starve the beast.  Hackers and crackers can&#039;t profit from malware if we don&#039;t let them install.  
 
Default-deny prevention keeps malware out.  Default-allow prevention ensures that even as we kill the Conficker, another malware will rise up to take its place.</description>
		<content:encoded><![CDATA[<p>Hats off to Mark Yason for cracking Conficker&#8217;s protocol&#8211;but what a shame that he needed to do so.  We already have the tools to prevent worms like Conficker from infecting us.  </p>
<p>Instead of detecting it after it installs, let&#8217;s starve the beast.  Hackers and crackers can&#8217;t profit from malware if we don&#8217;t let them install.  </p>
<p>Default-deny prevention keeps malware out.  Default-allow prevention ensures that even as we kill the Conficker, another malware will rise up to take its place.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
