<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Do you have Conficker? Find out in your OpenDNS account.</title>
	<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/</link>
	<description>Making the Internet safer and faster</description>
	<pubDate>Sat, 21 Nov 2009 09:49:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: Cadê o Conficker? &#124; Segurança</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-321976</link>
		<author>Cadê o Conficker? &#124; Segurança</author>
		<pubDate>Tue, 04 Aug 2009 06:02:21 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-321976</guid>
		<description>[...] provedora de serviços de resolução de DNS OpenDNS chegou a dizer que 12% dos computadores do Brasil estava infectados com o tal vírus, mas que estava trabalhando arduamente para que seus usuários não conseguissem [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] provedora de serviços de resolução de DNS OpenDNS chegou a dizer que 12% dos computadores do Brasil estava infectados com o tal vírus, mas que estava trabalhando arduamente para que seus usuários não conseguissem [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Do you have Conficker? Find out in your OpenDNS account. - CornDog Computers</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-319235</link>
		<author>Do you have Conficker? Find out in your OpenDNS account. - CornDog Computers</author>
		<pubDate>Sat, 27 Jun 2009 19:08:51 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-319235</guid>
		<description>[...] http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/ [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] <a href="http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/" rel="nofollow">http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/</a> [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ::Pim pom PAPAS!:: &#187; Prevención contra el conficker, sin antivirus</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-311073</link>
		<author>::Pim pom PAPAS!:: &#187; Prevención contra el conficker, sin antivirus</author>
		<pubDate>Sun, 10 May 2009 00:57:49 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-311073</guid>
		<description>[...] nuevo servicio lo encontré vía el blog de OpenDNS, donde además llevan una interesante estadística geográfica del porcentaje de [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] nuevo servicio lo encontré vía el blog de OpenDNS, donde además llevan una interesante estadística geográfica del porcentaje de [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-310537</link>
		<author>Adam</author>
		<pubDate>Wed, 06 May 2009 22:20:44 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-310537</guid>
		<description>So far I'm clean ;0  But yea, I got 4 systems here, 2 desktops, and 2-4 laptops connected thru wireless at various times, so finding a "problem" machine could be a pain in the abutt...lol.

Any chance that OpenDNS can gather the "computer name" or "local IP address" (192.168.1.x...) that initiated the connection to the blocklisted Conficker domain?



Lastly, any chance of upgrading this to "all" or "any" up/coming malware related domains...?  Ala, Storm Worm, etc...

I'm not sure how this all works on the backend, but if you got that domain tool running in the background, to "predict" bad domains that I was reading about, dump the domains constantly to the "malware" label (automatically voted as malware obviously...) - I'm sure the process could be adjusted to any later outbreak of bad domains too?</description>
		<content:encoded><![CDATA[<p>So far I&#8217;m clean ;0  But yea, I got 4 systems here, 2 desktops, and 2-4 laptops connected thru wireless at various times, so finding a &#8220;problem&#8221; machine could be a pain in the abutt&#8230;lol.</p>
<p>Any chance that OpenDNS can gather the &#8220;computer name&#8221; or &#8220;local IP address&#8221; (192.168.1.x&#8230;) that initiated the connection to the blocklisted Conficker domain?</p>
<p>Lastly, any chance of upgrading this to &#8220;all&#8221; or &#8220;any&#8221; up/coming malware related domains&#8230;?  Ala, Storm Worm, etc&#8230;</p>
<p>I&#8217;m not sure how this all works on the backend, but if you got that domain tool running in the background, to &#8220;predict&#8221; bad domains that I was reading about, dump the domains constantly to the &#8220;malware&#8221; label (automatically voted as malware obviously&#8230;) - I&#8217;m sure the process could be adjusted to any later outbreak of bad domains too?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: richard koswandi</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307923</link>
		<author>richard koswandi</author>
		<pubDate>Sun, 19 Apr 2009 01:29:30 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307923</guid>
		<description>is Conficker posible infect a macintosh operating system?
I use belkin wireless router to share the internet connection</description>
		<content:encoded><![CDATA[<p>is Conficker posible infect a macintosh operating system?<br />
I use belkin wireless router to share the internet connection</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frabj</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307852</link>
		<author>Frabj</author>
		<pubDate>Sat, 18 Apr 2009 14:27:50 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307852</guid>
		<description>"Tim Haigh - I have a Mac so I dont worry about such exploits of microsofts inferior operating systems."

Tim -
Mac users should still practice safe computing. Check the IWork Trojan DDOS botnet: trojan was downloaded in pirated copies of iWork.  See the article here: 
http://preview.tinyurl.com/df6agh AND:
http://www.securemac.com/ 

OpenDNS should add the qwfojzlk.freehostia.com address to its global blocking lists.</description>
		<content:encoded><![CDATA[<p>&#8220;Tim Haigh - I have a Mac so I dont worry about such exploits of microsofts inferior operating systems.&#8221;</p>
<p>Tim -<br />
Mac users should still practice safe computing. Check the IWork Trojan DDOS botnet: trojan was downloaded in pirated copies of iWork.  See the article here:<br />
<a href="http://preview.tinyurl.com/df6agh" rel="nofollow">http://preview.tinyurl.com/df6agh</a> AND:<br />
<a href="http://www.securemac.com/" rel="nofollow">http://www.securemac.com/</a> </p>
<p>OpenDNS should add the qwfojzlk.freehostia.com address to its global blocking lists.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rex Moncrief</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307389</link>
		<author>Rex Moncrief</author>
		<pubDate>Wed, 15 Apr 2009 13:47:04 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-307389</guid>
		<description>Once your machine has been compromised, the only real way to deal with the threat is to backup your critical data files (you should have a backup system anyway), wipe the machine, reinstall Windows, make sure you are behind a NAT router, and patch it up. Reinstall your software, tweak your settings, and don't let it get infected again. Simple.

After your software is reinstalled and pc is tweaked, then use imaging software to make a snapshot of it.</description>
		<content:encoded><![CDATA[<p>Once your machine has been compromised, the only real way to deal with the threat is to backup your critical data files (you should have a backup system anyway), wipe the machine, reinstall Windows, make sure you are behind a NAT router, and patch it up. Reinstall your software, tweak your settings, and don&#8217;t let it get infected again. Simple.</p>
<p>After your software is reinstalled and pc is tweaked, then use imaging software to make a snapshot of it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: crybaby</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306726</link>
		<author>crybaby</author>
		<pubDate>Sat, 11 Apr 2009 03:48:36 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306726</guid>
		<description>crazy</description>
		<content:encoded><![CDATA[<p>crazy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Haigh</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306665</link>
		<author>Tim Haigh</author>
		<pubDate>Fri, 10 Apr 2009 22:26:38 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306665</guid>
		<description>I have a Mac so I dont worry about such exploits of microsofts inferior operating systems.</description>
		<content:encoded><![CDATA[<p>I have a Mac so I dont worry about such exploits of microsofts inferior operating systems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harvey</title>
		<link>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306200</link>
		<author>Harvey</author>
		<pubDate>Thu, 09 Apr 2009 09:14:03 +0000</pubDate>
		<guid>http://blog.opendns.com/2009/04/02/do-you-have-conficker-find-out-in-your-opendns-account/#comment-306200</guid>
		<description>I received an email informing me that my network is infected by Conficker. I logged on to my OpenDNS account and saw big banner on the dashboard, but when I checked the stats for April 8 with the filter "View only requests that were blocked as malware" it returned "You haven’t requested any known malware sites." So I changed the date to April 7. It did return some stats with the filter "View everything". I tried changing it back to "View only requests that were blocked as malware" and then I clicked the Apply button. Nothing happened.

If specify a range of dates, the bot returned an error saying "We’re experiencing some network issues with our website.  (Don’t worry, our website is separate from our DNS infrastructure.)  Stats will be back soon."

How to know if indeed my network is infected and what domains my network was accessing to (malware/sites of Conficker)?</description>
		<content:encoded><![CDATA[<p>I received an email informing me that my network is infected by Conficker. I logged on to my OpenDNS account and saw big banner on the dashboard, but when I checked the stats for April 8 with the filter &#8220;View only requests that were blocked as malware&#8221; it returned &#8220;You haven’t requested any known malware sites.&#8221; So I changed the date to April 7. It did return some stats with the filter &#8220;View everything&#8221;. I tried changing it back to &#8220;View only requests that were blocked as malware&#8221; and then I clicked the Apply button. Nothing happened.</p>
<p>If specify a range of dates, the bot returned an error saying &#8220;We’re experiencing some network issues with our website.  (Don’t worry, our website is separate from our DNS infrastructure.)  Stats will be back soon.&#8221;</p>
<p>How to know if indeed my network is infected and what domains my network was accessing to (malware/sites of Conficker)?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
