I should have been clearer: Domain generation algorithms render solutions like Google SafeBrowsing vulnerable. Sure, these are only used by botnets today, but before we know it, it'd be put to use by adware and spyware too.
DGAs aren't a solution to the "my phishing page is blocked by safebrowsing/some other blacklist" problem. You can't send someone an email with a "link" that generates URLs until one of them isn't blocked: hyperlinks aren't programmable in that sense. You can send them a link to a page that does that, sure, but that doesn't stop them from blacklisting the redirector page. How would someone running a phishing campaign actually use a DGA?
Comments
I should have been clearer: Domain generation algorithms render solutions like Google SafeBrowsing vulnerable. Sure, these are only used by botnets today, but before we know it, it'd be put to use by adware and spyware too.
DGAs aren't a solution to the "my phishing page is blocked by safebrowsing/some other blacklist" problem. You can't send someone an email with a "link" that generates URLs until one of them isn't blocked: hyperlinks aren't programmable in that sense. You can send them a link to a page that does that, sure, but that doesn't stop them from blacklisting the redirector page. How would someone running a phishing campaign actually use a DGA?