<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Detecting Conficker with NMAP or scs</title>
	<atom:link href="http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=detecting-conficker-with-nmap-or-scs</link>
	<description>The Thinks I Think</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:50:17 -0500</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Computer Repair Los Angeles&#124;Marina Del Rey&#124;Santa Monica</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3944</link>
		<dc:creator>Computer Repair Los Angeles&#124;Marina Del Rey&#124;Santa Monica</dc:creator>
		<pubDate>Mon, 30 May 2011 01:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3944</guid>
		<description>Back in March 2009 here was the word: &quot;Millions of PCs have been infected with the Conficker worm, and word has it the program may cause mischief tomorrow—April Fool’s Day. But routing it out needn’t be difficult, the AP reports. 

Conficker Worm wants to remain undetected, as Conficker Worm downloads more malware onto your computer, contacts ISPs to get directions from a hacker, and places your computer in the Conficker Worm botnet.&quot;

I was looking for it on the machines I support.

However, my existing anti-malware tools did their job. We came out clean.

However, Shawn the work you did back then was helpful to those who were in trouble.

Therefore, keep up the good work.

Johnnie James
The Malware Killer
Computer Repair Santa Monica</description>
		<content:encoded><![CDATA[<p>Back in March 2009 here was the word: &#8220;Millions of PCs have been infected with the Conficker worm, and word has it the program may cause mischief tomorrow—April Fool’s Day. But routing it out needn’t be difficult, the AP reports. </p>
<p>Conficker Worm wants to remain undetected, as Conficker Worm downloads more malware onto your computer, contacts ISPs to get directions from a hacker, and places your computer in the Conficker Worm botnet.&#8221;</p>
<p>I was looking for it on the machines I support.</p>
<p>However, my existing anti-malware tools did their job. We came out clean.</p>
<p>However, Shawn the work you did back then was helpful to those who were in trouble.</p>
<p>Therefore, keep up the good work.</p>
<p>Johnnie James<br />
The Malware Killer<br />
Computer Repair Santa Monica</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: computer repair santa monica</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3943</link>
		<dc:creator>computer repair santa monica</dc:creator>
		<pubDate>Sat, 28 May 2011 05:07:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3943</guid>
		<description>Nmap is a great tool all-around. I use it myself for network security and auditing systems. Also Shawn I think it&#039;s great how you share your faith so openly. We&#039;ve have a lot in common!</description>
		<content:encoded><![CDATA[<p>Nmap is a great tool all-around. I use it myself for network security and auditing systems. Also Shawn I think it&#8217;s great how you share your faith so openly. We&#8217;ve have a lot in common!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LA Dude</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3942</link>
		<dc:creator>LA Dude</dc:creator>
		<pubDate>Wed, 10 Mar 2010 09:46:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3942</guid>
		<description>Any idea what this year&#039;s version may be?  I&#039;m a computer repair intern and would love to surprise my boss by being head&#039;s up on something like this!  I doubt they would be considerate enough to newbie pc techs like me and just call it conficker 2.0!</description>
		<content:encoded><![CDATA[<p>Any idea what this year&#8217;s version may be?  I&#8217;m a computer repair intern and would love to surprise my boss by being head&#8217;s up on something like this!  I doubt they would be considerate enough to newbie pc techs like me and just call it conficker 2.0!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MikeP</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3941</link>
		<dc:creator>MikeP</dc:creator>
		<pubDate>Tue, 07 Apr 2009 20:29:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3941</guid>
		<description>Hey, Port 25 smtp is a no go...

Thanks.</description>
		<content:encoded><![CDATA[<p>Hey, Port 25 smtp is a no go&#8230;</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3940</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Fri, 03 Apr 2009 02:19:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3940</guid>
		<description>Thanks a ton, Jose.  That&#039;s very useful.  :)</description>
		<content:encoded><![CDATA[<p>Thanks a ton, Jose.  That&#8217;s very useful.  <img src='http://www.brainofshawn.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3939</link>
		<dc:creator>Jose</dc:creator>
		<pubDate>Thu, 02 Apr 2009 17:36:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3939</guid>
		<description>I wrote a small script that parses the nmap output and uses nbtscan to retrieve the netbios name and outputs vulnerable / infected machine in comma delimited format.  It works well for us, hope it helps!

Download:
http://jdltech.com/conficker/</description>
		<content:encoded><![CDATA[<p>I wrote a small script that parses the nmap output and uses nbtscan to retrieve the netbios name and outputs vulnerable / infected machine in comma delimited format.  It works well for us, hope it helps!</p>
<p>Download:<br />
<a href="http://jdltech.com/conficker/" rel="nofollow">http://jdltech.com/conficker/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3938</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 01 Apr 2009 06:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3938</guid>
		<description>[...] Detecting Conficker with NMAP or scs [...] </description>
		<content:encoded><![CDATA[<p>[...] Detecting Conficker with NMAP or scs [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3937</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Wed, 01 Apr 2009 03:28:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3937</guid>
		<description>Glad to help, Paul.  :)</description>
		<content:encoded><![CDATA[<p>Glad to help, Paul.  <img src='http://www.brainofshawn.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Cafuk</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3936</link>
		<dc:creator>Paul Cafuk</dc:creator>
		<pubDate>Wed, 01 Apr 2009 03:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3936</guid>
		<description>Thanks Shawn!!  Good thing I decided to check my email!  and I thought I was done working until tomoorow morning!!!</description>
		<content:encoded><![CDATA[<p>Thanks Shawn!!  Good thing I decided to check my email!  and I thought I was done working until tomoorow morning!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MOM</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3935</link>
		<dc:creator>MOM</dc:creator>
		<pubDate>Tue, 31 Mar 2009 23:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3935</guid>
		<description>A BIG confused WHAT!</description>
		<content:encoded><![CDATA[<p>A BIG confused WHAT!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MWT</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3934</link>
		<dc:creator>MWT</dc:creator>
		<pubDate>Tue, 31 Mar 2009 21:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3934</guid>
		<description>Stinger is running on my computer now. Thanks! :)</description>
		<content:encoded><![CDATA[<p>Stinger is running on my computer now. Thanks! <img src='http://www.brainofshawn.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3933</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:55:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3933</guid>
		<description>Alex:

I haven&#039;t seen the problem -- but like Matt mentions, NMAP has caused a few issues, especially if used with the unsafe=1 flag.

I&#039;d probably follow that link I gave to MWT from the local machine in question, run Stinger, and see what it finds.</description>
		<content:encoded><![CDATA[<p>Alex:</p>
<p>I haven&#8217;t seen the problem &#8212; but like Matt mentions, NMAP has caused a few issues, especially if used with the unsafe=1 flag.</p>
<p>I&#8217;d probably follow that link I gave to MWT from the local machine in question, run Stinger, and see what it finds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3932</link>
		<dc:creator>alex</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:53:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3932</guid>
		<description>I&#039;ve come across a strange issue, not sure if it means computers are infected, but whenever I try to scan using scs or nmap the machine being scanned will go offline, and needs a reboot to get connectivity again.  I&#039;m running windows updates and antivirus right now just in case. Have you seen this problem?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve come across a strange issue, not sure if it means computers are infected, but whenever I try to scan using scs or nmap the machine being scanned will go offline, and needs a reboot to get connectivity again.  I&#8217;m running windows updates and antivirus right now just in case. Have you seen this problem?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3931</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:50:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3931</guid>
		<description>MWT: For a single machine, try this: http://vil.nai.com/vil/averttools.aspx

The first link is Stinger, with support for Conficker.</description>
		<content:encoded><![CDATA[<p>MWT: For a single machine, try this: <a href="http://vil.nai.com/vil/averttools.aspx" rel="nofollow">http://vil.nai.com/vil/averttools.aspx</a></p>
<p>The first link is Stinger, with support for Conficker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MWT</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3930</link>
		<dc:creator>MWT</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:33:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3930</guid>
		<description>Yeah, XP. 

Well, it&#039;s running on top of solaris, but it still needs to be scanned.</description>
		<content:encoded><![CDATA[<p>Yeah, XP. </p>
<p>Well, it&#8217;s running on top of solaris, but it still needs to be scanned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3929</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:28:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3929</guid>
		<description>MWT: Are you running Windows?</description>
		<content:encoded><![CDATA[<p>MWT: Are you running Windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MWT</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3928</link>
		<dc:creator>MWT</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:26:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3928</guid>
		<description>&quot;The system cannot execute the specified program.&quot; T.T</description>
		<content:encoded><![CDATA[<p>&#8220;The system cannot execute the specified program.&#8221; T.T</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3927</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3927</guid>
		<description>Thanks Matt!</description>
		<content:encoded><![CDATA[<p>Thanks Matt!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt McMahon</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3926</link>
		<dc:creator>Matt McMahon</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3926</guid>
		<description>Great summary, Shawn.  Couple of add&#039;l notes.  First, the author of the smb-check-vulns script (Ron Bowes) has some very recent updates on his blog  and yes, that site is being hit pretty hard right now, don&#039;t expect ninja-like-speed.  To even save a visit, I&#039;ll summarize...  

*ahem*  

The 4.85BETA5 version of nmap does return some false positives and will, under some circumstances, fail to even run the script on machines when it should (that one bit me).  The author is keeping the code updated by the minute and has fixed these bugs, but hasn&#039;t (yet) released a BETA6.  The easiest way for you to keep up is with his SVN repository.  Instructions are on the website above, but in an effort to save mouse-clicks, I&#039;ll copy &#039;n&#039; paste:

svn co --username=guest --password=&#039;&#039;  
svn://svn.insecure.org/nmap
cd nmap
./configure
make
make install

This is source code and built fine in my Slackware install, YMMV...</description>
		<content:encoded><![CDATA[<p>Great summary, Shawn.  Couple of add&#8217;l notes.  First, the author of the smb-check-vulns script (Ron Bowes) has some very recent updates on his blog  and yes, that site is being hit pretty hard right now, don&#8217;t expect ninja-like-speed.  To even save a visit, I&#8217;ll summarize&#8230;  </p>
<p>*ahem*  </p>
<p>The 4.85BETA5 version of nmap does return some false positives and will, under some circumstances, fail to even run the script on machines when it should (that one bit me).  The author is keeping the code updated by the minute and has fixed these bugs, but hasn&#8217;t (yet) released a BETA6.  The easiest way for you to keep up is with his SVN repository.  Instructions are on the website above, but in an effort to save mouse-clicks, I&#8217;ll copy &#8216;n&#8217; paste:</p>
<p>svn co &#8211;username=guest &#8211;password=&#8221;<br />
<a href="svn://svn.insecure.org/nmap" rel="nofollow">svn://svn.insecure.org/nmap</a><br />
cd nmap<br />
./configure<br />
make<br />
make install</p>
<p>This is source code and built fine in my Slackware install, YMMV&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Powers</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3925</link>
		<dc:creator>Shawn Powers</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:09:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3925</guid>
		<description>In Windows you need to open a command window.  (Start &#124; Run &#124; type &quot;cmd&quot; &#124; enter)

Change to the directory you extracted the .zip file into.

To scan a single IP address, type scanner.exe [ip_address]

To scan a range of IP addresses, type scs.exe [first_ip_in_range] [last_ip_in_range]

Or just type the file.exe program with no arguments for instructions to be displayed on the screen.

Cheers!  :)</description>
		<content:encoded><![CDATA[<p>In Windows you need to open a command window.  (Start | Run | type &#8220;cmd&#8221; | enter)</p>
<p>Change to the directory you extracted the .zip file into.</p>
<p>To scan a single IP address, type scanner.exe [ip_address]</p>
<p>To scan a range of IP addresses, type scs.exe [first_ip_in_range] [last_ip_in_range]</p>
<p>Or just type the file.exe program with no arguments for instructions to be displayed on the screen.</p>
<p>Cheers!  <img src='http://www.brainofshawn.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MWT</title>
		<link>http://www.brainofshawn.com/2009/03/31/detecting-conficker-with-nmap-or-scs/#comment-3924</link>
		<dc:creator>MWT</dc:creator>
		<pubDate>Tue, 31 Mar 2009 20:05:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.brainofshawn.com/?p=1223#comment-3924</guid>
		<description>Hmmm. Okay, so I downloaded the &lt;a href=&quot;http://www.doxpara.com/scs.zip&quot; rel=&quot;nofollow&quot;&gt;&quot;easy but slow&quot; thing&lt;/a&gt;, and upon opening it, there are three exe files. Which one should I click?</description>
		<content:encoded><![CDATA[<p>Hmmm. Okay, so I downloaded the <a href="http://www.doxpara.com/scs.zip" rel="nofollow">&#8220;easy but slow&#8221; thing</a>, and upon opening it, there are three exe files. Which one should I click?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

