Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cool, but how long until it auto-registers new domain names according to some algo? (see Srizbi)


Well, it's not sentient, so it isn't registering anything it wasn't already programmed to, and it isn't getting any new commands with all existing C&C routes gone.


Making the C&C domain time-dependent is trivial. Making the domain name based on time-dependent keys, steganography and queries across multiple domains as the basis for computing the current or next C&C domain would make the life of the good guys very uncomfortable.


Of course it can be done (and has been done). But in this case it apparently wasn't.


The arms race will undoubtedly continue.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: