Endpoint Protection

 View Only
Expand all | Collapse all

Stay Abreast

Migration User

Migration UserApr 22, 2009 03:02 AM

Migration User

Migration UserMay 04, 2009 10:42 PM

Migration User

Migration UserMay 04, 2009 11:44 PM

  • 1.  Stay Abreast

    Posted Apr 21, 2009 04:15 PM
    Just to keep everyone upto date, Today’s topics on full-disclosure include a conficker scanner for the network.



    Reference: http://security.bkis.vn/?p=560


    It's developed by BKIS, The same group who had found out the vulnerability against chrome some time back amongst others






  • 2.  RE: Stay Abreast

    Posted Apr 21, 2009 04:34 PM

    Thanks Sandeep after spreading downadup to whole world this could be a very helpfull for all.



  • 3.  RE: Stay Abreast

    Posted Apr 21, 2009 05:45 PM
    We get scared on downloading any software from internet, especially on the corporate network. Thogh Sandeep's name tag suggest he is a Trusted Advisor. However my point is not refering to his suggestion. I need a best practice in general.

    Can someone suggest, how?



  • 4.  RE: Stay Abreast

    Posted Apr 21, 2009 11:54 PM
    Hi,

    Good one sandeep, but "eeye retina" also publish such tools wherein you can detect which machines are infected and which machines are having MS08-067 Vulnerability.

    Rgrds,
    SAM


  • 5.  RE: Stay Abreast

    Posted Apr 22, 2009 01:45 AM
    Yeah, There are ways with Nmap as well to remotely detect the conficker worm
    http://insecure.org/#conficker



  • 6.  RE: Stay Abreast

    Posted Apr 22, 2009 01:48 AM
    hi sandeep this is really a good one, very helpful...


  • 7.  RE: Stay Abreast

    Posted Apr 22, 2009 02:51 AM
    I guess this should be the best one.

    This is a MS-KB on the removal process/best practice of w32.downadup.B

    http://support.microsoft.com/kb/962007



    Enabling debug logging for the Net Logon service

    http://support.microsoft.com/kb/109626



    MS Account Lockout Tools

    http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en



    MS08-67 patch download [KB 958644]

    http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx



    Disable Auto play with GPO

    http://support.microsoft.com/kb/953252



    Disable Scheduled Tasks with GPO

    http://support.microsoft.com/kb/310208



    Enable Security Auditing with GPO

    http://support.microsoft.com/kb/300549


    Once you have Enable Debugging for Netlogon Service you will be able to see which clients are attacking.
    Once the source is found it can be remidiated and cleaned.

    By disabling Scheduled Task Service
    We can stop Downadup from spreading .As it created Schduled Jobs and spread across the network.

    Disable autoplay
    That is the most important for every worm


  • 8.  RE: Stay Abreast

    Posted Apr 22, 2009 03:02 AM
    Good one Sandeep


  • 9.  RE: Stay Abreast

    Posted May 04, 2009 10:42 PM
    How to disable Auto Play?


  • 10.  RE: Stay Abreast

    Posted May 04, 2009 11:44 PM
    Hi Tejas, pls check SAV to SEP's post.


  • 11.  RE: Stay Abreast

    Posted May 05, 2009 04:11 AM
    Nice one Sandeep.

    @SAV to SEP: Great references.
    Disabling autoplay really did it.
    thanks.


  • 12.  RE: Stay Abreast

    Posted May 05, 2009 08:34 AM
    I used GPO to disable autoplay and used SEP to block access to any autoplay.inf file. Nothing at all can possibly start automatically around here. of course most important is the MS patches!
    Doesn't help much to have a guard dog if you leave all the windows and doors on a 3 story house wide open at night.


  • 13.  RE: Stay Abreast

    Posted May 07, 2009 12:13 AM
    @ShadowsPapa: Definitely agree with you on that.
    By the way is there a method to disable USB devices and not disabling USB KB and mouse?
    Made a test environment and USB was successfully blocked on the specific client.
    the problem is the mouse was also disabled.
    thanks.  


  • 14.  RE: Stay Abreast



  • 15.  RE: Stay Abreast

    Posted May 07, 2009 09:38 PM
    @Sandeep Cheema: Nice... Now I have something to play in the test area... you are a life saver friend... thanks!