ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Compliance Toolkit

Microsoft puts price on virus writers' heads

Published: 05 Nov 2003 08:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft will announce on Wednesday that it will offer two $250,000 (£148,960) bounties for information that leads to the arrest of the people who released the MSBlast worm and the SoBig virus, CNET News.com has learned.

The two programs attacked computers that run Microsoft's Windows operating system, causing havoc among companies and home users in August and September. The reward, confirmed by sources in both the security industry and in law enforcement, will be announced in a joint press conference with the FBI, the US Secret Service and Interpol that's scheduled for 10 a.m. (EST) on Wednesday.

The rewards are the first time a company has offered money for information about the identity of the cybercriminals.

"It's a new approach," said Chris Wysopal, a security researcher from digital security company @stake, who hadn't known about the bounties and was sceptical that they would work. "I don't think anyone has done this before."

Microsoft declined to comment until Wednesday.

The rewards mark the latest move by Microsoft and law enforcement to track down the people responsible for infecting hundreds of thousands of computers in August and September. The US Department of Justice, the FBI and Microsoft had earlier announced the arrests of two men who are suspected of modifying and releasing minor variations of the MSBlast worm.

The attacks were serious enough to hurt Microsoft's bottom line and help security companies post more profits.

MSBlast, also known as Blaster and Lovsan, spread to as many as 1.2 million computers, according to data from security company Symantec. The worm compromised computers by using a serious vulnerability in Windows systems for which Microsoft had released a patch a month earlier. The Sobig.F virus spread through email on 19 August, compromising users' computers with software designed to turn the systems into tools for junk emailers. A variant of the MSBlast worm, MSBlast.D, was intended to protect machines against the original program, but it ended up being so aggressive that the avalanche of data it produced shut down networks.

Sources who asked to remain anonymous said Microsoft would foot the entire bill for the bounties. Law enforcement typically neither condones nor disapproves of such rewards.

Security researchers gave the planned bounties mixed reviews.

"I think it is not a bad approach to counter the growing activity out there," said Peter Lindstrom, director of research for network protection company Spire Security. "People might criticise Microsoft for it, but it is a legitimate way to mobilise more folks to start analyzing their logs."

Despite nearly three months of intensive investigation, the FBI and Microsoft have only been able to track down two suspected bit players. The rewards seem designed to produce a mutiny in the close-knit circles of the hacker underground.

However, some researchers believed that such rewards might divert attention away from other efforts to add security that might defeat worms and viruses in the future.

"It doesn't solve the underlying problem of people being able to write worms like MSBlast," said one security researcher, who spoke with the condition of anonymity. "It doesn't quite equate accountability with being at the keyboard."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 112 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Desktop Support Analyst - Asset management - London City

Desktop Support Analyst - Asset management - London City The role is to provide 1st line support and manage the technology needs for the IT ...

EXCELLENT SAN ROLE!

My Client based in Glasgow requests a candidate with In-depth knowledge of the following: Fibre architecture and Protocol Design, implementation, ...

Backup Engineer

Manual intervention to recover failed housekeeping jobs - Scheduling and policy definition (driven from design documents) - Problem resolution (in ...

Loading Video Player ....

Featured Talkback

There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment