* Posts by Dan Kaminsky

2 publicly visible posts • joined 30 Mar 2009

Busted! Conficker's tell-tale heart uncovered

Dan Kaminsky

nmap

www.doxpara.com has instructions for nmap as well.

Dan Kaminsky
Flame

Just a quick note

Heh, this is Dan Kaminsky, from the story. Just to make something very clear:

Tillmann Werner and Felix Leder are the Honeynet Project researchers who actually noticed the behavioral shift introduced by Conficker. I've been doing work in fingerprinting lately, so I saw the opportunity to make it quite a bit easier to track down infected nodes in large organizations, but again, it was Tillmann and Felix who actually designed the fingerprinting logic that ultimately all these other organizations are integrating into their vulnerability scanning systems.

This is one small part of what's actually some very fine research about Conficker. This is their baby, I've just been helping it fly.