Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Re: Big up to torpig authors
From: John Lamb <full-disclosure () lawnjam com>
Date: Tue, 5 May 2009 09:53:10 +0100

On Mon, May 04, 2009 at 02:23:38PM -0400, T Biehn wrote:
"A recent update to this algorithm is particularly interesting.
Similarly to the previous version, the new algorithm uses the current
date to generate the drive-by-download domain. However, the new
algorithm also relies on search trends from Twitter to generate one
additional seed byte."

http://www.cs.ucsb.edu/~seclab/projects/torpig/index.html

Unfortunately for them a competing virus has seriously reduced the
entropy of their source - "Swine Flu" has been sitting at the top of the
list for days now...

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]