Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Who writes viruses?

Scorp

Published: 25 Sep 2003 13:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Who takes the time and effort to pull off malicious stunts, like viruses, malware, worms, Trojans, or any other deliberately damaging actions? And why? After all, there are risks involved. Who are these people and what do they gain?

The common stereotype is a bored but brilliant teenager from a dysfunctional family. The very name "script kiddies" implies that. And the latest (as of this writing) virus writer caught seems to reflect that stereotype. Go to any news search engine and enter "Jeffrey Lee Parson" and there he is, the alleged author of a variant of the LovSan/Blaster worm. Yes, he's 18, probably smart, possibly maladjusted, and instead of writing an original chunk of code, he (allegedly) chose to modify an existing worm. Part of his (alleged) modification was to insert a backdoor Trojan to enable (in theory) the remote control of any infected box. His motive is at this time unclear -- the best current guess is that he merely wanted to prove that he could do it and gain some status or notoriety. He also left a clear trail back to himself as the author, which strikes the investigators who caught him as being careless.

One would think that anyone technically competent enough to modify code would have to have at least a basic understanding of how the Internet works.

The case of the "LovSan" worm
This cute little piece of prankishness in its original form contained the message: "Billy Gates, why do you make this possible? Stop making money and fix your software!"

This is ironic. The LovSan worm was so poorly written and executed as to be laughable. Not only did it announce its presence by causing spontaneous shutdowns (not an event that could be classified as "subtle"), but its payload -- supposed to be a Trojan that would launch a simultaneous DDoS attack on the Microsoft update site -- was a miserable failure. Not only was the embedded URL inaccurate (it "almost" led to a page that merely forwarded the visitor to the real page) but once alerted, Microsoft was able to disable the page long before any damage was done.

It's difficult to see just where this kind of stunt results in any accolades for the author. What presumably began as a grand scheme to "send a message" to Microsoft merely caused minor aggravation nearly everywhere else -- by any standard, that can't be rated as a "successful" exploit.

Next

Previous

1 2 3 4


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
238 out of 448 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters