• On TechRepublic: FREE download: Social networking policy
March 2, 2009 1:06 PM PST

Conficker worm targets Southwest Airlines site

by Elinor Mills
  • Font size
  • Print
  • 4 comments

The Conficker worm, also known as Downadup, is targeting the Web site of Southwest Airlines and could disrupt online flight check-in and other services on March 13 as a result, security firm Sophos warned on Monday.

Mike Wood of SophosLabs Canada did some digging and found that the millions of computers infected with Conficker are programmed to contact wnsux.com, which redirects visitors to the main Southwest.com site, on March 13 to get instructions. That would cause a denial of service, shutting the site down temporarily, he wrote in a blog entry.

The worm is targeting about 7,750 domains, of which Wood said he found that nearly 3,900 are active. But they only resolve to 42 unique IP addresses, he said. Only a handful of those IP addresses are involved in a covert operation of ISPs and others trying to thwart Conficker by pre-registering domains, Wood wrote.

Other sites and potential dates that could be affected by Conficker are music site jogli.com on March 8, Chinese women's network qhflh.com on March 18, and computer phonetics site praat.org on March 31, he said.

"Other, less frequented sites of interest that appeared in the list include 'The Tennesse Dogue De Bordeaux' dog breeders site (tnddb.com, March 14) and the coy 'Double Super Secret Message Board' site (dssmb.com, March 11)," Wood wrote.

Sophos has more information in a statement on its Web site.

The worm, which has been around since last year, spreads through a hole in Windows systems, exploiting a vulnerability that Microsoft patched in October. Conficker also spreads via removable storage devices like USB drives, and network shares by guessing passwords and usernames.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
by gerrrg March 2, 2009 1:57 PM PST
Looks like they've already shut down wnsux.com.
Reply to this comment
by ballmerisanape March 2, 2009 2:07 PM PST
Windows is awesome.
Reply to this comment
by hassan_bin_sober March 3, 2009 9:03 AM PST
How could it be more disrupted than the norm.
Reply to this comment
by jcomputm March 6, 2009 8:49 PM PST
Why? This is going to make me cry! First the worldwide infection, and nowthis: social interference
Reply to this comment
(4 Comments)
  • prev
  • 1
  • next
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right