<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Possible defense? in </title>
<link>http://www.dslreports.com/forum/r21496386</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 10:26:37 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 10:26:37 EDT</lastBuildDate>

<item>
<title>Re: Possible defense?</title>
<link>http://www.dslreports.com/forum/remark,21496836</link>
<description><![CDATA[<A HREF="/useremail/u/121095"><b>RARPSL</b></A> : <div class="bquote"><small>said by  fireflier <A HREF="/useremail/u/397739"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>"For weeks, the researchers were able to thwart the emergency backup measure by generating the domain names such as qpqduqud.com themselves and then snapping up the addresses ahead of the bad guys. The cat-and-mouse standoff ended this week after FireEye researchers decided they could no longer afford to spend the money buying the domains."<br> </div>There is a simple solution to that issue of cost. Have the names (for the next year) put on a banned list so they can not be registered). There is no need to PAY for them (the registrar can eat the minimal cost as a contribution to the SPAM/BOT fight).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21496836</guid>
<pubDate>Fri, 28 Nov 2008 12:28:42 EDT</pubDate>
</item>

<item>
<title>Re: Possible defense?</title>
<link>http://www.dslreports.com/forum/remark,21496660</link>
<description><![CDATA[<A HREF="/useremail/u/397739"><b>fireflier</b></A> : <div class="bquote"><small>said by  kpatz <A HREF="/useremail/u/825971"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>If the algorithm for the domains has been cracked, an enterprising security firm could register up the next few batches of domains, use them to take control of the botnet, and distribute an "update" that removes (or at least shuts down) the malware from the victim's systems.<br> </div>Some kinda thought of that, but not so much to disable the bots, more to prevent registration of the next domains they'd be looking for:<br><br>&raquo;<A HREF="http://www.theregister.co.uk/2008/11/26/srizbi_returns_from_dead/" >www.theregister.co.uk/2008/11/26&middot;&middot;&middot;om_dead/</A><br><br>"For weeks, the researchers were able to thwart the emergency backup measure by generating the domain names such as qpqduqud.com themselves and then snapping up the addresses ahead of the bad guys. The cat-and-mouse standoff ended this week after FireEye researchers decided they could no longer afford to spend the money buying the domains."<br><br>But, as you pointed out, it would be nice if they could use that vulerability to disable the bots. . .<br><small>--<br>Tradition: Just because you've always done it that way doesn't mean it's not incredibly stupid. --despair.com</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21496660</guid>
<pubDate>Fri, 28 Nov 2008 11:43:04 EDT</pubDate>
</item>

<item>
<title>Possible defense?</title>
<link>http://www.dslreports.com/forum/remark,21496386</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : If the algorithm for the domains has been cracked, an enterprising security firm could register up the next few batches of domains, use them to take control of the botnet, and distribute an "update" that removes (or at least shuts down) the malware from the victim's systems.<br><small>--<br>To ISPs:  Leave our ports alone!  If I want ports blocked, I'll do it myself, thank you.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21496386</guid>
<pubDate>Fri, 28 Nov 2008 10:32:55 EDT</pubDate>
</item>

</channel>
</rss>
