22 ms·
No, you reverse engineer the "domain generation algorithm" and figure out what the secret seeds are as input, then every time you need to know the name of the r
by munin 9y ago
No, you reverse engineer the "domain generation algorithm" and figure out what the secret seeds are as input, then every time you need to know the name of the rendezvous point you figure out what the current seed is (easy if it's static, a little harder if it's dynamic) and run the algorithm.
Anyone that does this can register the reddit/twitter handles or domain names as soon as they figure this out, if they aren't pre-registered. And if you're the provider, you are then given a list of accounts to kill. Now you're in a game of cat and mouse with the botnet operator, and each move you take kills off some of the operators bots, perhaps all of them if you get ahead of them by enough.
- jstanley 9y agoThe commands could be cryptographically signed to prevent "malicious" control of the botnet.
- munin 9y agoTrue, but you can prevent the introduction of new commands. In this setting, if there's a central point, it can be cut. It's different if there is no central point (i.e. conficker P2P).