ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Fifth Sasser 'released before arrest'

Robert Lemos and Dawn Kawamoto CNET News.com

Published: 11 May 2004 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus companies discovered a fifth version of the Sasser variant this weekend, within hours of German police arresting an 18-year-old man who confessed to being the Sasser worm's author.

The latest variant, Sasser.E, was released a week ago, according to Microsoft. It attempts to warn people whose computers are vulnerable that their systems have not been patched for a widespread Microsoft Windows vulnerability exploited by the program.

"It appears that whoever released it is trying to notify people that their systems are vulnerable," said Oliver Friedrichs, a senior manager in Symantec's security response centre. The security company first captured a copy of the worm at 1 a.m. (PST) on Sunday, but Friedrichs said the spread of the infection is moving slow enough to indicate that the worm could have been released earlier in the week.

German authorities arrested an 18-year-old resident of Waffensen, a small town in the Lower Saxony region of Germany, late on Friday, according to Microsoft, which tipped off authorities after informants came forward with details about the suspected Sasser author. German law enforcement forces believe that the suspect also coded all 28 versions of the mass-mailing computer virus NetSky.

While antivirus experts are not certain whether Sasser.E started spreading before or after the arrest, Microsoft believes that the fifth version of the worm was released four days before the teenager was arrested, according to a representative of the software giant.

"Microsoft's technical analysis of this variant indicates that the E variant was released on Monday, four days prior to the suspect being taken into custody," the representative said.

Antivirus experts do not expect this latest version of Sasser to spread as fast as previous variants. Sasser.E is currently rated a low security threat by antivirus firm Network Associates and rates a "2" on rival Symantec's five-point scale. It is believed to have infected fewer than 100,000 computer systems since its discovery on Saturday night, said Jimmy Kuo, a research fellow with antivirus software maker NAI.

Earlier versions of Sasser received a medium threat rating, with some estimates putting the level of attacks at 500,000 computer systems in the first several days.

Kuo said that additional laws may be necessary to dissuade virus writers from releasing their programs onto the Internet.

"We would hope that there could be laws that would prohibit the posting of malicious code," Kuo said. "Sasser was partially written by some malicious code that was downloaded by the Internet."

This latest version of Sasser attempts to disable Bagle variants by removing the registry keys created by the competing worm. Previous versions of Sasser did not contain this feature.

The Sasser.E code includes this warning to victims of the worm:

    1. Your computer is affected by the MS04-011 vulnerability
    2. It can be that dangerous computer viruses similar the Blaster worm infect your computer
    3. Please update your computer with the MS04-011 LSASS patch from the www.microsoft.com website
    4. This is an message from the SkyNet Team for malicious activity prevention

Sasser.E also creates a remote shell on TCP -- Transmission Control Protocol -- port 1022, rather than 9995. And it also uses file transfer protocol on TCP port 1023, rather than 5554.

One antivirus company, Panda Software, suggested the timing of the attack may indicate an "organised group of delinquents" is creating Sasser, since the company's detection of the latest infection came after the arrest of the 18-year-old in Germany.

"This new variant has not gone as far afield in spreading," said Fernando de la Cuadra, an international technical editor for Panda Software. He suggested that the slow rate of infection is largely a result of the patches that users have installed since Sasser was first detected in late April.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
48 out of 125 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Quality Lead - Unilever - Level C-00055185

Quality Lead - Unilever - Level C-00055185 Description Quality Lead Port Sunlight, Wirral, Cheshire Up to 42,000 plus comprehensive benefits This is ...

Cognos 8 Contract Consultant

Cognos - BI - Contract - Germany. My key client a leading consultancy are currently seeking a Cognos 8 Contract consultant to be based in Germany on ...

Emebdded Engineer - Linux Kernel Specialist - England/Germany l

My Exclusive world-renowned client is currently seeking a Linux Kernel Specialist. This is to design and develop complete Linux solutions requiring ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment