Feeds

$250K reward for Sasser virus informants

That's what friends are for

  • alert
  • submit to reddit

Using blade systems to cut costs and sharpen efficiencies

The two people who helped identify the creator of the infamous Sasser worm in 2004 will share a reward of $250,000, Microsoft confirmed Friday. News of the payment under the software giant's Anti Virus Reward Program comes after a German court sentenced Sven Jaschan, 19, self-confessed author of Sasser to 21 months probation and a community service order following his conviction on computer sabotage offences.

Sasser is a network aware worm that exploited a well-known Microsoft vulnerability (in Windows Local Security Authority Subsystem Service - MS04-011) to infect thousands of systems in May 2004. The worm has caused widespread disruption affecting the operations of companies ranging from Finnish bank Sampo and Germany's Deutsche Post to the UK Coastguard.

Jaschan was arrested in the village of Waffensen near Rotenburg, in northern Germany, on suspicion of writing and distributing the Sasser worm within days of the beginning of the Sasser pandemic. The teenager later confessed to police that he was both the author of Sasser and the original creator of the NetSky worm.

Jaschan was arrested after a tip-off to Microsoft from individuals (believed to be Jaschan's erstwhile friends but Microsoft is keeping their names secret) who took advantage of Microsoft's Anti-Virus Reward Program. Investigators questioned Jaschan's mates on suspicion of assisting his virus writing activities but none were charged. In a statement, Microsoft said it was a condition of its anti-virus tip-off reward that recipients had no criminal involvement in a case.

Microsoft earmarked $5m in establishing its the Anti-Virus Reward Program back in November 2003. The scheme is designed to "help law enforcement agencies identify and bring to justice those who illegally release damaging worms, viruses and other types of malicious code on the Internet". Microsoft is putting up the money but it is up to investigators to decide if anyone qualifies for the bounties, payable on arrest and conviction of a virus writer. The Saser reward represents the first payment under the scheme, a Microsoft spokeswoman confirmed. ®

Related stories

Sasser worm creates havoc
Sasser creates European pandemonium
German police arrest Sasser worm suspect
Police probe Sasser informant
German police raid five homes in Sasser case
Sasser kid blamed for viral plague
Sasser author gets IT security job
Sasser author admits guilt
Sasser suspect walks free
MS puts $250k bounty on virus authors' heads
AV vendors shun MS bounty hunters

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.