ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Who writes viruses?

Scorp

Published: 25 Sep 2003 13:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Who takes the time and effort to pull off malicious stunts, like viruses, malware, worms, Trojans, or any other deliberately damaging actions? And why? After all, there are risks involved. Who are these people and what do they gain?

The common stereotype is a bored but brilliant teenager from a dysfunctional family. The very name "script kiddies" implies that. And the latest (as of this writing) virus writer caught seems to reflect that stereotype. Go to any news search engine and enter "Jeffrey Lee Parson" and there he is, the alleged author of a variant of the LovSan/Blaster worm. Yes, he's 18, probably smart, possibly maladjusted, and instead of writing an original chunk of code, he (allegedly) chose to modify an existing worm. Part of his (alleged) modification was to insert a backdoor Trojan to enable (in theory) the remote control of any infected box. His motive is at this time unclear -- the best current guess is that he merely wanted to prove that he could do it and gain some status or notoriety. He also left a clear trail back to himself as the author, which strikes the investigators who caught him as being careless.

One would think that anyone technically competent enough to modify code would have to have at least a basic understanding of how the Internet works.

The case of the "LovSan" worm
This cute little piece of prankishness in its original form contained the message: "Billy Gates, why do you make this possible? Stop making money and fix your software!"

This is ironic. The LovSan worm was so poorly written and executed as to be laughable. Not only did it announce its presence by causing spontaneous shutdowns (not an event that could be classified as "subtle"), but its payload -- supposed to be a Trojan that would launch a simultaneous DDoS attack on the Microsoft update site -- was a miserable failure. Not only was the embedded URL inaccurate (it "almost" led to a page that merely forwarded the visitor to the real page) but once alerted, Microsoft was able to disable the page long before any damage was done.

It's difficult to see just where this kind of stunt results in any accolades for the author. What presumably began as a grand scheme to "send a message" to Microsoft merely caused minor aggravation nearly everywhere else -- by any standard, that can't be rated as a "successful" exploit.

Next

Previous

1 2 3 4


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
230 out of 437 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I’m a PC. I’m a Handheld.

Hello, I’m a PC. I’m a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I’ll say it again, mobile devices are simply replacing computers.... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec