Feeds

Melissa virus author jailed for 20 months

Long time coming

  • alert
  • submit to reddit

High performance access to file storage

The author of the infamous Melissa virus was sentenced today to 20 months in Federal prison for causing millions of dollars of damage through its release into the wild in March 1999.

David L Smith, 33, pleaded guilty to creating the virus in December 1999 - the delay in his sentencing has created consternation in the security community.

Free on bail since then, Smith learned his fate today when Judge Joseph A. Greenaway sent him to prison and imposed a $5,000 fine.

Both sides in the case agreed that damage from Melissa, one of the first email borne viruses that exploited flaws in Microsoft's Outlook client exceeded $80 million, largely by jamming up corporate email systems.

Jack Clark, product marketing manager of the McAfee division of Network Associates, described the sentence as "about right" and expressed hopes that it would act as a deterrent to other would-be virus creators.

"This sends a clear message to other virus creators, who over the last few years, thought they might get way with it," said Clark, who hoped other authorities would look at the US ruling.

Smith released the Melissa virus by deliberately posting an infected document to an alt.sex.usenet newsgroup from a stolen AOL account. The virus, believed to be named after a stripper Smith knew in Florida, forwards itself to the first 50 addresses in all of your accessible Outlook address books.

Companies such as Microsoft, Intel, Lockheed Martin, and Lucent Technologies were forced to shut down their email gateways because of the large amount of email generated by the virus. It also caused the closure of e-mail systems of government agencies in both the US and UK. ®

Related Stories

Justice mysteriously delayed for 'Melissa' author
Melissa programmer freed on bail
Melissa virus threatens to bring email to a halt
AV vendors sell 'blunt razor blades'
Malware by numbers: online virus creation tool spotted
MS security memo a mere gesture
Anna Kournikova virus author stands trial
24 year-old Brit charged with virus writing

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.