You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft puts $250,000 bounty on worm-creator's head

Trying to catch Conficker criminal

Tags: microsoft, reward, worm, conficker

By Elinor Mills

Published: 16 February 2009 11:05 GMT

Microsoft last week said it is offering a $250,000 reward for information that leads to the arrest and conviction of whoever is responsible for creating the Conficker internet worm that has infected millions of PCs.

Microsoft said it is offering the reward because the worm constitutes a "criminal attack". Residents of any country are eligible for the reward and should contact their international law enforcement authorities, the company said in a statement.

Microsoft also announced it has partnered with security companies, domain name providers, and others on a co-ordinated global response to the worm, also known as Downadup. Participants include: AOL, Arbor Networks, the Internet Corporation for Assigned Names and Numbers (Icann), F-Secure, Global Domains International, Public Internet Registry, Symantec and VeriSign.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

The worm, which has been around since last year, spreads through a hole in Windows systems, exploiting a vulnerability that Microsoft patched in October.

It also spreads via removable storage devices like USB drives, and network shares by guessing passwords and usernames, which is "causing it to spread like wild fire in the enterprise", Jose Nazario, manager of security research for Arbor Networks, wrote on a company blog.

Coalition members have been trying to thwart the efforts of Conficker by pre-registering and locking up the domain names being used by the worm to distribute updates.

Nazario wrote: "The worm seeks to update itself by using a long list of pseudo-randomly generated domain names to contact over HTTP and then grab new code.

"The algorithm for this domain name generation scheme has been cracked (by F-Secure and others) and has been used to pre-compute the names for pre-registration to prevent hostile parties from using this update feature.

"This has been facilitated - greatly facilitated - by Icann, TLD operators, and various registrars working together with Microsoft and others to identify the names and grab the ones they need to. These records can then be pointed at sinkholes to discover Conficker-infected hosts checking in."

Last week, Symantec had observed an average of 453,436 IP addresses infected per day with W32.Downadup.A and 1.7 million IP addresses infected per day with W32.Downadup.B, the company said in a blog posting.

Symantec said: "W32.Downadup is the first successful worm to target a vulnerability in a remote service since W32.Sasser in 2004, and in doing so it has shown that the internet is still a successful breeding ground for worms."

Infected machines, of which there could be as many as 12 million according to Arbor Networks, could be used to launch distributed denial-of-service attacks on websites or seed a new worm, according to Symantec.

Original article: Microsoft offers $250,000 reward for Conficker arrest from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
New Business Sales Executive - IT Managed Services - London

This role will report to the UK Sales Director and will be backed up by a second to none pre-sales, internal sales and lead generation team selling ...

Pre Sales Solution Architect-Data Centres or VMWare or MOSS

Main Duties: The primary domain expertise of the Solution Architect will fall into one of three main areas. MOSS, Exchange, Groove etc) * Storage ...

Infrastructure Analyst

Support, administration and maintenance of all web servers, associated domain names and certificates Including implementation of group policies and ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: