Welcome to Spyware Removal News

SRI releases Conficker scanner source code


The experts at SRI International, who have been tracking the Conficker worm as closely as anyone, have released the source code to the scanner they wrote to detect the active P2P scanning that Conficker-infected machines perform.

The Conficker worm exhibits a number of interesting characteristics that have helped researchers identify infected machines and help stop the worm's spread. For example, Conficker-infected machines always open teo TCP ports and two UDP ports in order to listen for traffic from other infected machines. SRI's scanner works by identifying hosts that have opened up those ports by scanning all of the IP addresses on a given network. SRI releases Conficker scanner source code | threatpost




Please Visit our Home Page

Home

More Spyware Removal News