Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Domain summit 2024

cctld Worm affecting .ca domains

Status
Not open for further replies.

Namefox

Namefox
Legacy Exclusive Member
Joined
Feb 14, 2005
Messages
5,746
Reaction score
28
Feedback: 179 / 0 / 0
I saw a segment on the BC news with a rep from CIRA stating that the conficker worm is affecting .ca domains. Here is the article from MacLeans magazine.



OTTAWA - A malicious cyber worm could wreak havoc on millions of potentially infected computers April 1 - or it could all be one big April Fool's joke.

But the Canadian Internet Registration Authority isn't taking any chances when it comes to the latest variant of the Conficker worm.

CIRA, which manages Canada's dot-ca (.ca) domain name registry, warned Tuesday that millions of computers running Microsoft's operating system may have been infected since the worm began spreading last fall.

Beginning April 1, the worm is expected to force infected computers to randomly generate and connect to 50,000 web URLs a day from 110 domains around the world, including dot-ca domains.

A secret "command-and-control" file instructing the worm to perform malicious actions could be hidden on any one of those URLs.

"This command-and-control computer that all of the infected computers are going to try to reach out to is hosted under a particular domain name," said Byron Holland, CIRA's president and CEO.

"This worm is quite smart, so what it does (is) it creates a smokescreen by generating a random list of many tens of thousands of domain names, among which the single domain name is associated with the command-and-control computer."

It's not known what - if anything - the worm's creators have in mind. They might overwhelm the Internet with spam, monitor keyboard strokes to collect passwords and banking information or delete files on a person's computer.

"Once a virus has control of an individual computer, it can effectively see what's happening in, or happening to, that computer," Holland said.

"At this point, we really don't know what the actual intent of this one is."

CIRA worked with security experts around the globe to "reverse engineer" the worm so they could find out which sites it will generate, Holland said.

As a preventative measure, the authority has now blocked 157,000 unregistered dot-ca domains expected to be generated by the worm, he added.

Microsoft released a patch in October to stop the worm from spreading. But newer variants are more sophisticated than the original worm and have continued to infect computers.

This latest variant of the worm, Conficker C, was identified in early March. An earlier variant, Conficker B, worked like this latest variant except that it generated a list of only 250 to connect to every day.

A cabal of Internet groups and companies, led by Microsoft, is offering $250,000 for information leading to the arrest and conviction of those responsible for the worm.

Roughly 1.2 million dot-ca domains are registered with CIRA.
 

whitebark

Level 9
Legacy Platinum Member
Joined
Jul 9, 2006
Messages
3,026
Reaction score
26
Feedback: 78 / 0 / 0
How in the heck are they going to register those domain names? Do they already have a registrant # ready to go? Where is the money coming from? Wouldn't a registrar notice a sudden surge of thousands of registrations through its system from outside the country?
 

TheLegendaryJP

Level 9
Legacy Exclusive Member
Joined
Jul 12, 2005
Messages
4,335
Reaction score
171
Feedback: 51 / 0 / 0
They just cant come up with enough ways to spend the surplus of cash they sit on.

Next they plan on building a bunker to defend against the end times... for dot ca registrants only.
 

Ilze

Level 5
Legacy Exclusive Member
Joined
Apr 29, 2008
Messages
445
Reaction score
18
Feedback: 6 / 0 / 0
This sounds so idiotic. You need to create a Rant at the Registrar, ....go to Cira and read ad-nauseum documents lots of red tape to register a dot ca

.It just does not make sense...And, to put something like this on the CIRA website...that does not make sense either. I am not sure what the point is. If anyone can tell me, I would appreciate it. What CIRA needs to do is reduce the registration fees..they have too much money to spend. I totally agree with JP...
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Be a Squirrel
MariaBuy

Our Mods' Businesses

UrlPick.com
URL Shortener

*the exceptional businesses of our esteemed moderators

Top Bottom