<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3142797122483599580</id><updated>2012-02-16T13:07:14.519-08:00</updated><title type='text'>Confiker Share this Chart</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://confikerchart.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3142797122483599580/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://confikerchart.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Computer Depot Technician</name><uri>http://www.blogger.com/profile/01547626998868436749</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3142797122483599580.post-2332035974342624808</id><published>2009-04-09T12:09:00.001-07:00</published><updated>2009-04-09T12:55:50.205-07:00</updated><title type='text'></title><content type='html'>&lt;p class="callout"&gt;On account of the original eye chart at Joe Stewart's site being down, I've taken the liberty of creating this eye chart in replacement.&lt;/p&gt;&lt;br /&gt;&lt;table align="center"&gt; &lt;tbody&gt;&lt;/tbody&gt;&lt;tbody&gt; &lt;tr&gt; &lt;td align="center"&gt;&lt;a href="http://www.f-secure.com/"&gt;&lt;img src="http://www.f-secure.com/export/system/fsgalleries/thumbnails/thumbnails_112xN/FSC_logo_pos_112x128.jpg" alt="" height="128" width="112" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;td align="center"&gt;&lt;a href="http://www.secureworks.com/"&gt;&lt;img src="http://www.secureworks.com/images/headerlogo.gif" alt="" height="37" width="233" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;td align="center"&gt;&lt;a href="http://www.trendmicro.com/"&gt;&lt;img src="http://us.trendmicro.com/images/common/LogoTrendMicro_3d.gif" alt="" height="45" width="120" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;&lt;a href="http://www.openbsd.org/"&gt;&lt;img src="http://eyechart.sie.isc.org/openbsd.jpg" alt="" height="129" width="150" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;td align="center"&gt;&lt;a href="http://www.linux.org/"&gt;&lt;img src="http://149.20.54.68/linux.png" alt="" height="129" width="109" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;td align="center"&gt;&lt;a href="http://www.freebsd.org/"&gt;&lt;img src="http://eyechart.sie.isc.org/freebsd.png" alt="" height="129" width="118" /&gt;&lt;/a&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;h2&gt;How to interpret&lt;/h2&gt;&lt;br /&gt;&lt;table&gt; &lt;tbody&gt;&lt;/tbody&gt;&lt;tbody&gt; &lt;tr align="center"&gt; &lt;td&gt;If you see this above:&lt;/td&gt; &lt;td&gt;It probably means this:&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;All six images displayed&lt;/td&gt; &lt;th align="left"&gt;= Normal/Not Infected by Conficker (or using proxy)&lt;/th&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;Security/AV logos not displayed&lt;/td&gt; &lt;th align="left"&gt;= Possibly Infected by Conficker (C variant or greater)&lt;/th&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;Some security/AV logos not displayed&lt;/td&gt; &lt;th align="left"&gt;= Possibly Infected by Conficker B variant&lt;/th&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;Lower images don't appear&lt;br /&gt;(Tux, blowfish, devil)&lt;br /&gt;&lt;/td&gt; &lt;th align="left"&gt;=&lt;br /&gt;&lt;ol&gt;&lt;li&gt; Image loading turned off in browser?&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Verification images most likely being DDoSed (attacked by thousands of machines around the globe)&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;It's okay, the important part is the top images -- &lt;em&gt;do you see them&lt;/em&gt;?&lt;/th&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt;Any other combination&lt;/td&gt; &lt;th align="left"&gt;= Poor Internet connection?&lt;/th&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;h2&gt;Explanation&lt;/h2&gt;&lt;br /&gt;&lt;p&gt;Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;If you are blocked from loading the remote images in the first row of&lt;br /&gt;the top table above (AV/security sites) but not blocked from loading&lt;br /&gt;the remote images in the second row (websites of alternative operating&lt;br /&gt;systems) then your Windows PC may be infected by Conficker (or some&lt;br /&gt;other malicious software).&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;If you can see all six images in both rows of the top table -- or at&lt;br /&gt;least the top ones, as the bottom ones seem to be DDoSed at the time -- you are either not infected by Conficker, or you&lt;br /&gt;may be using a proxy server, in which case you will not be able to use&lt;br /&gt;this test to make an accurate determination, since Conficker will be&lt;br /&gt;unable to block you from viewing the AV/security sites.&lt;/p&gt;&lt;br /&gt;&lt;h2&gt;Detecting Conficker on your network through a port scanner&lt;/h2&gt;&lt;br /&gt;&lt;p&gt;&lt;a class="external-link" href="http://www.net-security.org/secworld.php?id=7252"&gt;Net-Security suggests that&lt;/a&gt;, to scan for Conficker, you can a command such as:&lt;/p&gt;&lt;br /&gt;&lt;pre&gt; nmap -PN -T4 -p139,445 -n -v --script=smb-check-vulns --script-args safe=1 [targetnetworks]&lt;/pre&gt;&lt;br /&gt;&lt;h2&gt;Credits&lt;br /&gt;&lt;/h2&gt;&lt;br /&gt;&lt;p class="discreet"&gt;F-Secure and the F-Secure Logo are trademarks of F-Secure Corporation.&lt;br /&gt;SecureWorks and the SecureWorks Logo are registered trademarks of SecureWorks Inc.&lt;br /&gt;Trend Micro and the T-Ball logo are trademarks or registered trademarks of Trend Micro Inc.&lt;br /&gt;&lt;br /&gt;The Conficker Eye Chart is a concept by &lt;a href="http://www.joestewart.org/"&gt;Joe Stewart&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This derivative work was set up to help Joe Stewart's efforts.&lt;br /&gt;&lt;a href="http://www.gnu.org/copyleft/"&gt;Copyleft&lt;/a&gt; 2009.&lt;/p&gt;&lt;br /&gt;&lt;p class="callout"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3142797122483599580-2332035974342624808?l=confikerchart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://confikerchart.blogspot.com/feeds/2332035974342624808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://confikerchart.blogspot.com/2009/04/on-account-of-original-eye-chart-at-joe.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3142797122483599580/posts/default/2332035974342624808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3142797122483599580/posts/default/2332035974342624808'/><link rel='alternate' type='text/html' href='http://confikerchart.blogspot.com/2009/04/on-account-of-original-eye-chart-at-joe.html' title=''/><author><name>Computer Depot Technician</name><uri>http://www.blogger.com/profile/01547626998868436749</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
