PDA

View Full Version : OT: Microsoft offering $$$...are you up to date?


William
02-13-2009, 02:31 PM
Microsoft bounty for worm creator
By Maggie Shiels
Technology reporter, BBC News, Silicon Valley

http://news.bbc.co.uk/2/hi/technology/7887577.stm

A reward of $250,000 (£172,000) has been offered by Microsoft to find who is behind the Downadup/Conficker virus.

Since it started circulating in October 2008 the Conficker worm has managed to infect millions of computers worldwide.

The software giant is offering the cash reward because it views the Conficker worm as a criminal attack.

"People who write this malware have to be held accountable," said George Stathakopulos, of Microsoft's Trustworthy Computing Group.

He told BBC News the company was "not prepared to sit back and let this kind of activity go unchecked".

"Our message is very clear - whoever wrote this caused significant pain to our customers and we are sending a message that we will do everything we can to help with your arrest," said Mr Stathakopulos.

Arbor Networks said as many as 12 million computers could be affected globally by Conficker/Downadup since it began prowling the web looking for vulnerable machines to infect in October.

Malicious payload

The Conficker worm is a self-replicating program that takes advantage of networks or computers that have not kept up to date with Windows security patches.

It can infect machines via a net connection or by hiding on USB memory drives used to ferry data from one computer to another. Once in a computer it digs deep, setting up defences that make it hard to extract.

The worm slithers through networks by guessing usernames and passwords. Security specialists recommend hardening passwords by mixing in numbers, punctuation marks and capital letters.

The virus reports in to its creators for updates by visiting a web domain. It generates the name of the domain itself using a complicated code which security firms have cracked to track the growth of the worm and block its progress.

Malware such as Downadup can be triggered to steal data or turn control of infected computers over to malicious hackers which pool them into larger armies of so-called botnets.

These networks of compromised machines can be used to send spam, as dead drops for stolen or pirated data and to launch attacks on other machines.

Although Downadup is widespread its creators have yet to activate its payload to steal data or launch other attacks.

It has caused costly headaches for network administrators dealing with users locked out of their accounts when the worm correctly guesses a password.

While Microsoft says it does not know the intention of the worm's creator, it wants to ensure it does not wreak any more havoc.

Experts say users should have up-to-date anti-virus software and install Microsoft's MS08-067 patch - also known as KB958644.

Global response

Microsoft has also partnered with security companies, domain name providers, academia, internet companies such as AOL and others on a co-ordinated global response to the worm.

Also included is the US Department of Justice and the Department of Homeland Security.

"The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together," said Greg Rattray, chief internet security adviser at the Internet Corporation for Assigned Names and Numbers (Icann).

"Icann represents a community that's all about co-ordinating those kinds of efforts to keep the internet globally secure and stable."

Sasser worm

In 2003 Microsoft created its reward programme with $5m (£3.4m) in funding to help law enforcement agencies bring computer virus and worm authors to justice.

This reward for help in tracking the creators of Downadup is the first time in four years that the company has put up some cash in response to a worm outbreak.

"We have not seen this type of worm or one of its class since 2004," said Mr Stathakopulos.

In 2005 Microsoft paid out $250,000 (£171,000) to two individuals who helped identify the creator of the notorious Sasser worm. The author was arrested and sentenced by the German authorities.

Rewards of $250,000 were offered over three other major computer worm threats known as Blaster, MyDoom and Sobig worms.

Those perpetrators have never been caught.

Nil Else
04-01-2009, 12:03 AM
It's 12:02AM 04/01/2009 and well..my PC is still scanning....

http://www.npr.org/templates/story/story.php?storyId=102574501

http://tech.yahoo.com/blogs/null/132464;_ylt=AgqCDof.8jc332o6iJM9HNDxMJA5?comment_s tart=6&comment_count=20#see_comments

GuyGadois
04-01-2009, 01:53 AM
This is the primary reason I run a Mac. i got so fed up with the worm viruses and consistent scans. I have run a Mac three years without even having a virus software installed.

:beer:

-GG-

Ray
04-01-2009, 02:07 AM
This is the primary reason I run a Mac. i got so fed up with the worm viruses and consistent scans. I have run a Mac three years without even having a virus software installed.

:beer:

-GG-
Is that because Mac has such relatively smaller market share that most virus writers just don't aim at them? Or is there something about the Mac OS that makes it harder to do? If its the former, Macs increasing success might become a real problem if hackers start taking aim at it. I was 100% Mac in the early days but switched to Windows about 12-13 years ago. I have fewer compelling reasons to stay with Windows these days and may switch back in the next couple of years. I've been pretty vigilant about virus protection, but it definitely requires attention and occasional effort.

-Ray

Nil Else
04-01-2009, 02:34 AM
Is that because Mac has such relatively smaller market share that most virus writers just don't aim at them? Or is there something about the Mac OS that makes it harder to do? If its the former, Macs increasing success might become a real problem if hackers start taking aim at it. I was 100% Mac in the early days but switched to Windows about 12-13 years ago. I have fewer compelling reasons to stay with Windows these days and may switch back in the next couple of years. I've been pretty vigilant about virus protection, but it definitely requires attention and occasional effort.

-Ray

It is both. Because of the small market virus writers don't bother but also Macs are built up from ground up different with security in mind for example all of Macs ports come locked and closed whereas PCs come with some open ports. I'm no expert (I just use Mac) but that's what I remember reading from a book.