SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Conficker is coming: Are our domain names in danger?

Conficker is coming: Are our domain names in danger?

By:  Briony Smith  On: 24 Mar 2009 For: ComputerWorld Canada Creator

Although Conficker C is allegedly almost upon us, CIRA says that we shouldn't have anything to worry about

For those who have been fretting over the imminent appearance of the wily worm Conficker C next week, the Canadian Internet Registration Authority (CIRA) has been at work on a solution to keep .ca domains safe once the worm is unleashed upon the world, and thinks Canadian IT staffers and Internet pros should have nothing to worry about.

This two-stage worm was detected last fall. Its first stage involves infecting as many computers as possible, according to Byron Holland, president and CEO of CIRA. “From there, it will reach out to its host to receive its direction,” he said. “It’s one of the biggest bot-nets out there.”

After its discovery in autumn, experts had been working on puzzling through the code, and discovered that the second phase would most likely deploy on April 1.

And right in the line of fire? The .ca domain, which is one of the 110 country-code domains targeted by the worm for corruption.

More from IDG News Service

The search for Conficker's first victim

So far, experts don’t know what the exact intent of the worm is, said Holland, although it could range anywhere from spam to various forms of fraud or identity theft.

“Part of what Conficker does is register new domains that can become a host for driving the spread of infection,” said James Quin, senior research analyst with the Info-Tech Research Group. “This doesn't present a threat to existing Web sites since those domains are already registered. The threat is that the worm could register new, currently unused domains."

More from IDG News Service

Conficker worm spawns evil twin

The thousands of endangered domain names will be taken out of circulation, said Holland.

The only real fallout is someone perhaps missing out on their preferred domain name, said Quin. “Should one of those domains turn out to be something an individual or business desires, that individual may feel impacted, but no more so than if the domain had previously been registered for legitimate purposes," he said.

“Of the small number of registered domains, we are investigating them and validating them to make sure they are kosher,” Holland said. He could not confirm the number of possibly affected domains, citing security concerns.


Sign up for our Newsletters












Print |  Views: 1307   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Briony Smith Briony Smith is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Conficker's first scam
Conficker's first scamUsing one of the oldest tricks in the book, Conficker C downloads a fake antivirus program called Spyware Protect 2009 and hits victims for $49.95 a pop
Conficker passes quietly, but threat isn't over
Conficker passes quietly, but threat isn't overThe activation of the Conficker.c worm at midnight on April 1 passed without incident, but security researchers said users aren't out of the woods yet. The people behind Conficker may simply be biding their time
Fake security software scammers jump on Conficker
Fake security software scammers jump on ConfickerGoogle's search rankings are being manipulated in order to trick people into downloading bad software
Dan Swanson's Security Resources: #12
business is about change, and peter’s change management repository is one of the very best, and certainly well worth regular visits by busy professionals.
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
Questions about Conficker
over the weekend i was interviewed by cbc’s sunday evening news show about conficker and the possibly grim outlook for pc users everywhere on april 1. maybe not my best interview, but what bugs me now is that i was just a little too late to provide more detail on how you can tell who’s been infected.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.