[113030] in North American Network Operators' Group
RE: The Confiker Virus.
daemon@ATHENA.MIT.EDU (Richard Golodner)
Sun Mar 29 20:20:03 2009
From: "Richard Golodner" <rgolodner@infratection.com>
To: "'Joe Blanchard'" <jbfixurpc@gmail.com>,
"'Barry Raveendran Greene'" <bgreene@senki.org>, <nanog@nanog.org>
In-Reply-To: <002f01c9b0cb$0b0f6de0$0101a8c0@E520>
Date: Sun, 29 Mar 2009 19:16:29 -0500
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Joe said earlier today:
> Thanks, the only thing is that these, like most, websites are very vague
about the mechanics behind the infiltration
Joe, the SRI report would be right up your alley as it is the most
technical in its analysis of the variants A and B as well as an explanation
of the algorithm it uses to determine domain names for future use of some
kind.
http://mtc.sri.com/Conficker/
Sincerely, Richard Golodner