Feeds

$250K reward for Sasser virus informants

That's what friends are for

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

The two people who helped identify the creator of the infamous Sasser worm in 2004 will share a reward of $250,000, Microsoft confirmed Friday. News of the payment under the software giant's Anti Virus Reward Program comes after a German court sentenced Sven Jaschan, 19, self-confessed author of Sasser to 21 months probation and a community service order following his conviction on computer sabotage offences.

Sasser is a network aware worm that exploited a well-known Microsoft vulnerability (in Windows Local Security Authority Subsystem Service - MS04-011) to infect thousands of systems in May 2004. The worm has caused widespread disruption affecting the operations of companies ranging from Finnish bank Sampo and Germany's Deutsche Post to the UK Coastguard.

Jaschan was arrested in the village of Waffensen near Rotenburg, in northern Germany, on suspicion of writing and distributing the Sasser worm within days of the beginning of the Sasser pandemic. The teenager later confessed to police that he was both the author of Sasser and the original creator of the NetSky worm.

Jaschan was arrested after a tip-off to Microsoft from individuals (believed to be Jaschan's erstwhile friends but Microsoft is keeping their names secret) who took advantage of Microsoft's Anti-Virus Reward Program. Investigators questioned Jaschan's mates on suspicion of assisting his virus writing activities but none were charged. In a statement, Microsoft said it was a condition of its anti-virus tip-off reward that recipients had no criminal involvement in a case.

Microsoft earmarked $5m in establishing its the Anti-Virus Reward Program back in November 2003. The scheme is designed to "help law enforcement agencies identify and bring to justice those who illegally release damaging worms, viruses and other types of malicious code on the Internet". Microsoft is putting up the money but it is up to investigators to decide if anyone qualifies for the bounties, payable on arrest and conviction of a virus writer. The Saser reward represents the first payment under the scheme, a Microsoft spokeswoman confirmed. ®

Related stories

Sasser worm creates havoc
Sasser creates European pandemonium
German police arrest Sasser worm suspect
Police probe Sasser informant
German police raid five homes in Sasser case
Sasser kid blamed for viral plague
Sasser author gets IT security job
Sasser author admits guilt
Sasser suspect walks free
MS puts $250k bounty on virus authors' heads
AV vendors shun MS bounty hunters

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.