Perp: Sven Jaschan
Status: Free on parole, currently employed by a security vendor
Dossier: Mild-mannered Sven Jaschan never struck anyone as the master-criminal type, but by the age of 17, the German worm-writing wunderkind had already established himself with Netsky, a piece of malware that spreads from computer to computer and removes two types of spam-sending botnet malware, Bagle and Mydoom. Not content with the pace of his anti-spam vigilantism, Jaschan fashioned an even faster way to destroy his targets in 2004 in the form of Sasser.
The first versions of the Sasser worm were discovered in the wild just days after a Russian hacker released source code to exploit a newly discovered vulnerability in the Windows LSASS (Local Security Authority Subsystem Service) library, which manages local security on Windows 2000 and XP systems. Within days, Sasser unleashed all kinds of unintended chaos, initiating unstoppable 60-second countdowns to reboot on infected PCs. Thousands of computers, regardless of whether they were infected with Bagle or Mydoom, began rebooting repeatedly, the by-design behavior of Windows when the LSASS process is terminated. Whole networks of governments, banks, and hospitals were taken offline for hours, or in some cases, days.
Jaschan, who embedded messages to anti-virus researchers in Sasser, tied the worm to Netsky. Anti-virus companies confirmed that the two worms were related but still had no idea who the author was. That all changed a week later when one of Jaschan's high school friends contacted Microsoft's German office and offered to identify the creator of Sasser in return for the $250,000 publicized bounty. Jaschan was arrested, brought to trial, and convicted on a computer crime charge in Germany. The judge was lenient, however, handing down a suspended sentence. Free to saddle up to his computer again, Jaschan was even offered a job by German computer security vendor Securepoint.
(In a slightly ironic twist, the LSASS vulnerability Jaschan tapped to help distribute Sasser is the same exploit used by the version of the RBot Trojan Ancheta used to send spam and load adware onto PCs. Oh, the double-edged sword.)
Upshot: Noble intentions aside, Jaschan's ill-conceived execution of Sasser wreaked havoc for months, as the worm periodically resurfaced to infect and reinfect machines. Lucky for him he wrote his worms before he turned 18 and could only be tried as a juvenile. Speaking of juvenile, how about bragging about your criminal exploits to would-be friends at school? Lesson learned: Be careful whom you count among your clique of confidants, and don't use your high school network as the platform to launch your attacks on the Net.
[ Stupid hacker index | Christopher William Smith: The upper limit of enhancement ]
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »