Friday, December 27, 2013

CPE: McAfee AudioParasitic: Episode 60: Conficker special edition


length: 00:06:38
Very special AudioParasitic
Quick list of countermeasure against Conficker:
AV DAT, HIPS< IPS

2009/03/30 DAT 3569 covers all variations of Conficker worm.
Generic b0f protection will cover as well
HIPS has specific signature: 3961
IPS: protection using last October NetBIOS vulnerability signature
Foundstone: did not have complete coverage, however based honeynet – recently it has been added to provide capability to accurately detect infected PC
Vflash: remedy – stinger tool cover only conficker
Document: finding suspicious files
MS08-067
Not all variant use this MS08-067 exploit.

Labels: ,

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home