Impending (mydoom) DOS attack

Stephen J. Wilcox steve at telecomplete.co.uk
Sat Jan 31 18:24:42 UTC 2004


> For the record, I fully believe that this worm (both variants) is designed to 
> attack high profile targets in order to take the focus off of it's spamming 
> capability and create uncertainty as to what group actually authored the 
> worm. It is my firm belief that this worm was written by spammers for the 
> purpose creating spam relays.

I'm not sure what the point of the DoS is if its intended to be a spam engine, 
that would have the effect of helping to identify and hence clean up the 
infections.

Of course we're guessing about the spam connection, it doesnt have a spam engine 
in it, the mail capabilities are purely to redistribute itself... to do spam you 
need to add the engine via the backdoor.

I'm tempted to think its nothing more than a bot and the backdoor is to allow 
the controller to go in and change its target. The DoS engine isnt that well 
written tho, this is odd too...

Oh well, I guess we'll see tomoro!

Steve




More information about the NANOG mailing list