ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Sasser worm author arrested in Germany

Reuters CNET

Published: 09 May 2004 11:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Spokesman Frank Federau for the Lower Saxony police said the man was arrested Friday. Federau said the suspect admitted to programming the worm, but authorities did not know if he had created all the versions of it.

Security experts said this could be the single biggest arrest yet in the campaign against the computing underground responsible for hatching worms and viruses, which has proved difficult for law enforcement to crack.

"He made a confession, and the experts at Microsoft have now confirmed that he was the cause of this worm," Federau said. He said he did not have any details of how the suspect was found.

Surprised at the rapid developments, security experts said this could be the single biggest arrest yet in bringing down a virus-writing gang.

Federau said that the man, who lived with his parents near the central German town of Rotenburg, did not have any links with organized crime. But the spokesman could not confirm if the suspect had ties to other worm programmers.

All the teenager's computers were confiscated by police but the suspect himself was not in custody, Federau said.

Since appearing a week ago, Sasser has wreaked havoc on personal computers running on the ubiquitous Microsoft Windows 2000, NT and XP operating systems, but is expected to slow down as computer users download antivirus patches.

The computing underground responsible for hatching worms and viruses has proved a difficult ring to crack for law enforcement.

"Hopefully this arrest will limit their activities," said Mikko Hypponen, antivirus research director at Finnish data security firm F-Secure. "If we can start catching these guys, it will certainly put more pressure on existing virus writers."

Separately, police in the southern state of Baden-Wuerttemberg said they had arrested a 21-year-old man who confessed to programing the Internet worm Agobot, which was later renamed as Phatbot.

A spokesman for the State Police Office in Stuttgart said the arrests were not connected.

From the outset, Sasser baffled security experts. Unlike the most recent digital outbreaks, Sasser was programed simply to spread and knock out computer networks, not take over machines and possibly steal information stored on them.

The prevailing theory was Sasser was written by the same gang behind the prevalent 2-month-old Netsky virus. German news magazine Der Spiegel said the German man was also suspected of creating a variant of the Netsky virus.The police spokesman would not confirm that and said police were still investigating the suspect's links to Netsky variants.

Pieces of code found in a recent version of Netsky made references to Sasser. Typically, such clues generate the biggest leads for authorities in hunting down culprits.

Previous versions of Netsky, for example, were programed to attack the Web site for an education server in the German state of Lower Saxony where the German suspect lived, security officials point out.

If the Sasser author is part of the Netsky group, which calls itself the "Skynet antivirus group," this could be the most important arrest yet in cracking virus-writing crime.

"The police may just have cracked the Netsky gang with this arrest. The whole ring may be broken wide open," said Graham Cluley, senior technology consultant at Sophos, a British-based security outfit.

Home users, corporations, and government agencies throughout Europe, North America and Asia have been hit. Once infected, the vulnerable PC reboots without warning as the compact program hunts for more machines to infiltrate.

The economic toll of Sasser may never be known, but it has claimed some big victims, including Germany's Deutsche Post, Britain's coast guard stations and investment bank Goldman Sachs.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 137 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Internet Operations Analysts

In this growing area, youll have every opportunity to use your technical skills at the sharp end of our operations supporting intelligence and ...

Business Product Support Analyst - Spanish/German/French Speaking

Spanish, German or French. My client is a leading Software house who is seeking a talented Business product support analyst. Some of the activities ...

Helpdesk Support Analyst (1st/2nd Line Support)

We have an expanding 1,300 strong Force working with the community and other partners to promote a safe, peaceful and crime-free environment in the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments