Dallas-Mavs.com Forums

Go Back   Dallas-Mavs.com Forums > Everything Else > The Lounge

Reply
 
Thread Tools Display Modes
Old 08-29-2003, 03:22 PM   #1
u2sarajevo
moderately impressed
 
u2sarajevo's Avatar
 
Join Date: May 2003
Location: Home of the thirteenth colony
Posts: 17,705
u2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond repute
Default Blaster worm suspect arrested...

]

Minn. Teen Faces Internet Attack Charges
Fri Aug 29,12:06 PM ET Add Technology - AP to My Yahoo!


By TED BRIDIS, AP Technology Writer

WASHINGTON - U.S. cyber investigators arrested a Minnesota teenager Friday who the FBI (news - web sites) said has admitted unleashing one version of a damaging virus-like infection weeks ago on the Internet. A court official identified the teenager as Jeffrey Lee Parson, 18, of Hopkins, Minn., known online as "teekid." A U.S. official in Washington also confirmed an arrest was made early Friday.

Court papers said FBI and Secret Service agents searched Parson's home on Aug. 19 and seized seven computers, which are still being analyzed. In an interview with FBI Special Agent Eric Smithmier, Parson admitted modifying the original "Blaster" infection and creating a version known by a variety of different names, including "Blaster.B.," court papers said.

FBI Director Robert Mueller hinted earlier this week that an arrest was imminent, when he cited the damage from the recent Blaster and "SoBig" infections. "We employ the latest technology and code analysis to direct us to potential sources, and I am confident that we will find the culprits," Mueller said Tuesday.

Parson — a physically imposing presence at 6-foot-4 and 320 pounds — told the FBI he built into his version a method for reconnecting to victim computers later, according to court papers. Infected computers automatically registered themselves with Parson's Web site so he could keep track of them. Parson operated the t33kid.com Web site, according to Internet registration records. The Web site, which was operated from computers physically in San Diego, appeared Friday not to have any content on it but previously contained software code for at least one virus and a listing of the most-damaging viruses circulating on the Internet. The FBI said in court documents that at least 7,000 computers were infected by Parson's software.

Further details were expected to be disclosed Friday by the FBI and U.S. attorney's office in Seattle, which has been leading the investigation. The case was being handled from Seattle because the infection affected software sold by Microsoft Corp., based in nearby Redmond. Prosecutors said Microsoft suffered financial losses that "significantly" exceeded $5,000, the statutory threshold in most hacker cases.

Collectively, different versions of the virus-like worm, alternately called "LovSan" or "Blaster," snarled corporate networks worldwide, forcing Maryland's motor vehicle agency to close for one day. The infection inundated networks and frustrated home users. Symantec Corp., a leading antivirus vendor, said the worm and its variants infected more than 500,000 computers worldwide. Experts consider it one of the worst outbreaks this year. The "Blaster.B" version of the infection, which began spreading Aug. 13, was remarkably similar to the original Blaster worm that first struck two days earlier; experts said the author made few changes, renaming the infecting file from "msblast" to an anatomical reference.

All the Blaster virus variants took advantage of a flaw in Microsoft Corp.'s flagship Windows software. Government and industry experts had anticipated such an outbreak since July 16, when Microsoft acknowledged the software problem, which affects Windows technology used to share data files across computer networks.

The infection was quickly dubbed "LovSan" because of a love note left behind on vulnerable computers: "I just want to say LOVE YOU SAN!" Researchers also discovered another message hidden inside the infection that appeared to taunt Microsoft Chairman Bill Gates (news - web sites): "billy gates why do you make this possible? Stop making money and fix your software!"

Infected computers were programmed to automatically launch an attack on a Web site operated by Microsoft, which the software maker easily blunted. The site, windowsupdate.com, is used to deliver repairing software patches to Microsoft customers to prevent these types of infections.
__________________
u2sarajevo is offline   Reply With Quote
Sponsored Links
Old 08-29-2003, 04:21 PM   #2
Chiwas
Guru
 
Join Date: Sep 2002
Posts: 13,363
Chiwas is infamous around these partsChiwas is infamous around these parts
Default Blaster worm suspect arrested...




I knew LRB was behind all this stuff! He was so quiet lately....[img]i/expressions/face-icon-small-happy.gif[/img]












j/k with my buddy.

__________________
Chiwas is offline   Reply With Quote
Old 08-29-2003, 05:28 PM   #3
Ummmmm Ok
Platinum Member
 
Join Date: Oct 2002
Posts: 2,021
Ummmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to allUmmmmm Ok is a name known to all
Default RE: Blaster worm suspect arrested...

Quote:
Infected computers were programmed to automatically launch an attack on a Web site operated by Microsoft, which the software maker easily blunted. The site, windowsupdate.com, is used to deliver repairing software patches to Microsoft customers to prevent these types of infections.
Sad as this sounds, this was actually kind of brilliant. I just can't believe he got caught. Curious as to how he got the virus out, and how they tracked it back to him.
__________________
"If you want to be successful, find someone who has achieved the results you want and copy what they do and you'll achieve the same results." Tony Robbins

Too many leaders act as if the sheep.. their people.. are there for the benefit of the shepherd, not that the shepherd has responsibility for the sheep. Ken Blanchard

What we think determines what happens to us, so if we want to change our lives, we need to stretch our minds. Wayne Dyer

These are things that I read and live by!
Ummmmm Ok is offline   Reply With Quote
Old 08-29-2003, 06:05 PM   #4
u2sarajevo
moderately impressed
 
u2sarajevo's Avatar
 
Join Date: May 2003
Location: Home of the thirteenth colony
Posts: 17,705
u2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond repute
Default Blaster worm suspect arrested...

Quote:
Originally posted by: Ummmmm Ok
Quote:
Infected computers were programmed to automatically launch an attack on a Web site operated by Microsoft, which the software maker easily blunted. The site, windowsupdate.com, is used to deliver repairing software patches to Microsoft customers to prevent these types of infections.
Sad as this sounds, this was actually kind of brilliant. I just can't believe he got caught. Curious as to how he got the virus out, and how they tracked it back to him.
Well no, actually it was not brilliant. If he wanted it to be effective he could have made it virtually impossible in the time given for Microsoft to thwart this attack. Microsoft shutdown windowsupdate.com, because within versions of IE that host name is not what is accessed. Did he do this on purpose? I don't know, but if you are gonna go down for something you would think you would do as much damage as possible.

They tracked it back to him through tips, then his ISP's logs, then it was rather easy.

You would be shocked to know how easy it is to find someone using the originating Network address (IP address which every one of you have).

The Internet is a wonderful thing, but ALL you guys need to realize that you should protect yourself as much as you possibly can.
__________________
u2sarajevo is offline   Reply With Quote
Old 08-29-2003, 06:50 PM   #5
mavsfanforever
Diamond Member
 
mavsfanforever's Avatar
 
Join Date: Apr 2003
Posts: 8,141
mavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of lightmavsfanforever is a glorious beacon of light
Default RE: Oh how I wish I could get 5 minutes with this punk......

U2 maybe you can use that pic for your avatar.
__________________
BELIEVE IT.
mavsfanforever is offline   Reply With Quote
Old 08-29-2003, 06:51 PM   #6
u2sarajevo
moderately impressed
 
u2sarajevo's Avatar
 
Join Date: May 2003
Location: Home of the thirteenth colony
Posts: 17,705
u2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond reputeu2sarajevo has a reputation beyond repute
Default Oh how I wish I could get 5 minutes with this punk......

Quote:
Originally posted by: mavsfanforever
U2 maybe you can use that pic for your avatar.
Nah... I have already printed it out and replaced Gephardts picture with this guy on my office's dart board.
__________________
u2sarajevo is offline   Reply With Quote
Old 08-29-2003, 06:52 PM   #7
EricaLubarsky
Inactive.
 
EricaLubarsky's Avatar
 
Join Date: Feb 2004
Location: Scottsdale, AZ
Posts: 42,476
EricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond reputeEricaLubarsky has a reputation beyond repute
Default Oh how I wish I could get 5 minutes with this punk......

Quote:
Originally posted by: Chiwas
I think he asked me out to the prom in high school.

[img]i/expressions/rolleye.gif[/img]
EricaLubarsky is online now   Reply With Quote
Old 08-29-2003, 07:39 PM   #8
senorfrog
Member
 
senorfrog's Avatar
 
Join Date: Jul 2002
Posts: 787
senorfrog is on a distinguished road
Default Oh how I wish I could get 5 minutes with this punk......


AP"Jeffrey's classmates found it quite odd that he liked to carry a fried egg around on the top of his head."
__________________
I'm not drunk you shilly sit
senorfrog is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump




All times are GMT -5. The time now is 11:28 AM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.