Advertisement
Promo

Security threats Toolkit

Microsoft offers $250k bounty for Downadup arrest

Elinor Mills CNET News

Published: 13 Feb 2009 13:06 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Thursday said it is offering a $250,000 reward for information that leads to the arrest and conviction of whoever is responsible for creating the Conficker internet worm that has infected millions of PCs.

Microsoft said it is offering the reward because the worm constitutes a "criminal attack" and offering compensation should hasten prosecution. Residents of any country are eligible for the reward and should contact their international law-enforcement authorities, the company said in a statement.

Microsoft also announced that it has partnered with security companies, domain-name providers and others on a co-ordinated global response to the worm, also known as Downadup. Participating are: the Internet Corporation for Assigned Names and Numbers (Icann), VeriSign, NeuStar, CNNIC, Afilias, Public Internet Registry, Global Domains International, M1D Global, AOL, Symantec, F-Secure, ISC, Georgia Tech, the Shadowserver Foundation, Arbor Networks and Support Intelligence.

The worm, which has been around since last year, spreads through a hole in Windows systems, exploiting a vulnerability that Microsoft patched in October.

It also spreads via removable storage devices such as USB drives, and network shares by guessing passwords and usernames, which is "causing it to spread like wild fire in the enterprise", Jose Nazario, manager of security research for Arbor Networks, wrote on a company blog.

Coalition members have been trying to thwart the efforts of Conficker by pre-registering and locking up the domain names being used by the worm to distribute updates.

"The worm seeks to update itself by using a long list of pseudo-randomly generated domain names to contact over HTTP and then grab new code," Nazario wrote. "The algorithm for this domain-name generation scheme has been cracked (by F-Secure and others) and has been used to pre-compute the names for pre-registration to prevent hostile parties from using this update feature. This has been facilitated — greatly facilitated — by ICANN, TLD operators and various registrars working together with Microsoft and others to identify the names and grab the ones they need to. These records can then be pointed at sinkholes to discover Conficker-infected hosts checking in."

Over the past five days, Symantec has observed an average of 453,436 IP addresses infected per day with W32.Downadup.A and 1.7 million IP addresses infected per day with W32.Downadup.B, the company said in a blog posting.

"W32.Downadup is the first successful worm to target a vulnerability in a remote service since W32.Sasser in 2004, and in doing so it has shown that the internet is still a successful breeding ground for worms," Symantec said. Infected machines, of which there could be as many as 12 million according to an estimate by Arbor Networks, could be used to launch distributed denial-of-service attacks on websites or seed a new worm, according to Symantec.

 

Credit: Microsoft offers $250,000 reward for Conficker arrest from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
4 out of 4 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters