ext_137338 ([identity profile] docstrange.livejournal.com) wrote in [personal profile] doc_strange 2003-08-16 10:01 am (UTC)

Re: Incidentally

My sources are as the grains of sand in my shoe.

Which is to say, the MS pulling DNS, I figured out with dnsq and dnstrace.

The action the worm will take upon receiving no DNS for windowsupdate.com information was provided by Symantec.

That and some friends set it up in their lab, and ran it through its paces. It's almost too straightforward to spend time with a debugger.

Post a comment in response:

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting