Slashdot Mirror


Maker of Kournikova Gets Wrist Slapped Too

shelflife writes: "This story says 'It is the first time in history that the maker of a computer virus has been tried in the Netherlands -- indeed one of the few times it has been done in the world. Hypponen knows only of one conviction. A man was sentenced to 18 months in jail in the U.K. in the early 1990s. The man served 11 months, said Hypponen.' but that can't be true. What about Robert Morris? Anyway, the requested sentence is amazingly light -- 240 hours of civil service." The really interesting part is that this kid wasn't even a programmer. He just downloaded a kit. Shows how far this Virus Craze has gone in the last few years.

167 comments

  1. Oh? by Anonymous Coward · · Score: 0
    The really interesting part is that this kid wasn't even a programmer. He just downloaded a kit.

    Ohhhhh, so it was a Java virus!

  2. May be he is guilty for spreading it? by SergioB · · Score: 1

    May be he is guilty for spreading it?

  3. How do you determine the cost? Makes sense ... by pgrote · · Score: 1

    If you read the article it says, "The fact that no damage claims have been filed with the prosecutor's office is one of the reasons the prosecutor isn't asking for heavier sentencing. However, the U.S. Federal Bureau of Investigation said in a fax to the prosecutor it identified 55 victims of the Kournikova worm with a total damage of $166,827. That claim wasn't specific enough, the prosecutor said."

    That is exactly right. No one stepped up to claim damages.

    In light of that the defense attorney attacked the prosecution.

    In terms of right or wrong it is obvious that the right thing wasn't done. In terms of judicial process and law, it was a success.

    Maybe there needs to a better way to determine losses during a virus/worm incident. Are there any standard formulas not based on Anti Virus company PR?

    The only thing I could find was this:

    http://www.vibert.ca/prevbus.htm

    It breaks time down on support efforts and totals it.

    1. Re:How do you determine the cost? Makes sense ... by motherhead · · Score: 0

      The point if levying a substantial fine is not just to restitute damages. (how is this kid suppose to come up with huge amounts of theoretical restitution) But to discourage irresponsible acts.

      If one were shut down a brick and mortar business, for even a half a day with some malicious act of vandalism, one would expect to face stern punishment. Malicious code spread through the net has the ability to affect far more businesses and people then routine angry vandalism. (albeit, this was a particularly innocuous varient)

      I think a message should be sent to bored assholes that they will probably be found and they will atone in a manner that should warrant pause.

    2. Re:How do you determine the cost? Makes sense ... by Anonymous Coward · · Score: 0

      55 victims of the Kournikova worm with a total damage of $166,827

      Umm, WHAT?!?!?!?!

      They want people to believe that it cost over $3000 per person?

      Jesus, how the hell did they come up with that figure?!?!? If you figure that you lose 1 day of productivity, and throw the old computer away (which is a little like giving your car to a wrecker because you ran out of gas), you're still under that amount.

      What the hell has the FBI been smoking?

  4. script kiddies by Mysa · · Score: 1

    Joy. Now we have script kiddie wannabes.

  5. a kit! by Captain+Pooh · · Score: 1

    That's messed up he used a kit. What a hobo.

  6. Interesting that he turned himself in. by strags · · Score: 2, Interesting

    Interesting that he turned himself in - perhaps this does lend credence to the idea that he really didn't know what he was doing. Although, to be fair, if you download a worm creation kit, use it to create a worm, and then post it to Usenet, it seems unlikely that you wouldn't be aware of the potential consequences.

    1. Re:Interesting that he turned himself in. by Anonymous Coward · · Score: 0

      1. Don't brag. (Smile inwardly instead).
      2. Don't repeat. (Find something better to do).
      3. Don't come back to watch. (Watch it on TV).

  7. Anna Kournikova... by netsharc · · Score: 0

    When I first saw the title, I read it as "Mother of Kournikova... Too", then I wondered what she had done, and because of the "Too", I presumed it was Anna that had done something before her mother.

    Mmmm.. Anna Kournikova naked and petrified...

    --
    What time is it/will be over there? Check with my iPhone app!
  8. It's about time by moebius_4d · · Score: 1

    I think it's high time that this kind of thing happened. All these script kiddies with their DDOS and rootkit tools, virus kiddies and their kits, are able to do what they are doing because they don't have to suffer for it. Everyone else has to suffer instead. Situations like that are why we make laws in the first place.

    I'm certainly against penalizing the authors of the kits, if they don't release viruses. We shouldn't do anything to people who alert us to security vulnerabilities, even to the extent of releasing an exploit, since this is often the only way to get companies to make a patch. But for those people who decide to use this information to steal the time and money of others to gratify their egos, the law is the proper recourse.

    If you don't agree, that's fine. See how you feel after having to spend a weekend of your own time wiping and reinstalling the OS and applications on a machine or machines that have been hacked. Then, testing them and having to deploy new security procedures so that you can be live on Monday. It's not fun.

  9. Good.. by evel+aka+matt · · Score: 2, Insightful

    Finally someone in a computer-related trial gets a semi-fair sentencing. I'm suprised he didn't get $4,000,000,000 worth of jail time for all the "damages" he caused. I must admit, I'm a little suprised at the people who are not happy with the outcome of this trial..

    ---
    evelakamatt

    1. Re:Good.. by Spruitje · · Score: 2, Interesting


      Finally someone in a computer-related trial gets a semi-fair sentencing. I'm suprised he didn't get $4,000,000,000 worth of jail time for all the "damages" he caused.


      Contrary to the US it is not common that people are compensated above Fl 50.000 (that's around $ 22.000) in the Netherlands.
      If a waitress spill some coffee on in a restaurant the normal compensation is that the restaurant pays the bill of the dry cleaner.
      Contrary to the US we at least have some common sense and it isn't done to sue somebody for a mistake (and it is almost impossible).
      You will find that this is the case in most parts of Europe.

  10. How to calculate the damage? by timothy · · Score: 1

    Anna K. never infested my email box the way Sircam has, but for some people it probably did.

    I hope the court took into consideration:

    - cumulative time (at sysadmin rates) spent cleaning off the virus
    - long-distance and other comms. telling infectees, infected systems' admins that their systems are infected
    - lost time due to disk-full errors etc.

    What else?

    The real loss / damage is that people are pissed off at each other for passing on a virus which someone else specifically designed for them to be able to pass on unknowingly.

    Like switching the brake and clutch in city buses. Ha ha, what a riot. OK, so no one got killed, but Ha ha! Look at me! How'd you like the hospital treating your loved ones to be putting their resources toward cleaning off this scum rather than toward keeping records straight, making sure your parent / sibling / spouse / child doesn't get a medicine they're allergic to, etc?

    timothy

    --
    jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
    1. Re:How to calculate the damage? by Anonymous Coward · · Score: 0

      Switching the brake and clutch in a bus? Where did you hear about this?

      Slashdot requires you to wait 20 seconds between hitting 'reply' and submitting a comment.

      It's been 18 seconds since you hit 'reply'!

      If you this error seems to be incorrect, please provide the following in your report to Source Forge:

      Browser type
      User ID/Nickname or AC
      What steps caused this error
      Whether or not you know your ISP to be using a proxy or some sort of service that gives you an IP that others are using simultaneously.
      How many posts to this form you successfully submitted during the day* Please choose 'formkeys' for the category!
      Thank you.

    2. Re:How to calculate the damage? by Anonymous Coward · · Score: 0
      - cumulative time (at sysadmin rates) spent cleaning off the virus

      In other words, the virus author should be punished because he forced sysadmins to actually work for those phat paychecks.

    3. Re:How to calculate the damage? by Dr.+Prakash+Kothari · · Score: 2, Offtopic

      Sir, I find your sig to be more than a small bit offensive.

      As an Arab living in the United States, I too have been affected by the tragedy inflicted on your country by these terrorists. I had several friends in the WTC at the time of the attacks, and I feel that the USia needs to extract vengance upon those who committed these acts. However, you must understand that the men who perpetrated this violence represent a distinct minority among Arabs.

      Your suggestion that all arabs have their arms amputated strikes me as offensive and highly insensitive. Racially motivated violence will not bring the dead back to life.

      Now is the time for level-headedness and tolerance, not ignorance and persecution.

      --

      "Technically, a cat locked in a box may be alive or dead." -Kurt Cobain

    4. Re: How to calculate the damage? by Inthewire · · Score: 1

      Your suggestion that all arabs have their arms amputated strikes me as offensive and highly insensitive. Racially motivated violence will not bring the dead back to life.
      Sure he didn't mean weapons?

      --


      Writers imply. Readers infer.
    5. Re:How to calculate the damage? by Anonymous Coward · · Score: 0
      Your suggestion that all arabs have their arms amputated

      And then the TROLL ALARM goes off - his suggestion was not to give them WEAPONS, in other words, ARMS.

      (Not that his suggestion would have helped ANYTHING, so I guess removing physical arms would be a better solution to preventing the tragedy - although still wrong.)

    6. Re:How to calculate the damage? by LoudMusic · · Score: 2, Informative
      Dude, he's talking about guns, weapons. Not human limbs.

      "Arms" as defined by dictionary.com.

      ~LoudMusic

      --
      No sig for you. YOU GET NO SIG!
    7. Re:How to calculate the damage? by Anonymous Coward · · Score: 0

      Actually being an Arab you can't blame him for naturally assuming human limbs since that's the norm as relates to punishment for them.

  11. Couldn't do it alone... by Ed+Avis · · Score: 3, Troll

    Will the makers of Outlook go to court for actively helping the spread of the worm by deliberately insecure handling of attachments?

    --
    -- Ed Avis ed@membled.com
    1. Re:Couldn't do it alone... by pgrote · · Score: 2, Insightful

      I guess I am really tired of hearing people say this.

      Yes, Outlook is prone to leaving gaping holes to run these things through, but let's not blame the responsibility.

      Someone, an IT Manager, a Network Administrator, a tech, has made the decision that their company, group or department will use Outlook. That is where the blame rests.

      No one puts a gun to their head and forces them to use Outlook. No one. Someone makes the final decision.

      In that decision there may be mitigating factors such as software investments, training costs, etc. so if they find themselves in a situation where they feel Outlook is their best decision they then need to protect themselves.

      After the first Outlook specific virus everyone should have realized this simple fact: anit-virus products exist for a reason.

      A good anti-virus product will override your email and not allow it to happen. Automated updates to DAT files can be handled locally or over the internet.

      There is no use in blaming Microsoft. You blame the people who handle IT for the organization.

    2. Re:Couldn't do it alone... by Ed+Avis · · Score: 2

      I agree. Microsoft should not be held responsible for writing the Outlook program; the fault is with those stupid enough to run it. The same principle should be applied to the person who wrote the Kournikova worm.

      --
      -- Ed Avis ed@membled.com
    3. Re:Couldn't do it alone... by Dog+and+Pony · · Score: 1

      I agree... and even if you are forced to use outlook, it behaves unless you are outright stupid.
      And moreover, I'm tired of seeing those posts everywhere, where they are Not needed. If you really feel so hard about this crusade, why don't you tell the people that are Unaware of such?

      Ah yes. Scoring cheap points by cheering for the home team... :)

      Want me to tell you what the Real culprit is? All those management morons sending small little "funny" or "cute" AVIs or flash games... those are the ones that will dbl-click on Any attachement, and those are the ones likely to send an attachement that you should dbl-click. (Mail-rule: email from X with attachement goes straight to trash).

    4. Re:Couldn't do it alone... by thrig · · Score: 2

      How many people factor the expense of mandatory anti-virus software into their calculations when choosing Outlook?

      What if IT says "hell no" but management forces the Microsoft solution on them. Do you still blame IT?

      What about schools and ISP's where clients just start using the bundled Outlook Express because it came with the computer, forcing the overworked sysadmins to divert time and money to installing centralized anti-virus software on the mail hosts, because there's no way in hell that anti-virus software is going to be installed properly configured on all the client machines?

      I say boycott Microsoft until they fix the negligent product design that brought us the anti-virus market.

    5. Re:Couldn't do it alone... by DrSkwid · · Score: 1

      except of course when it had a buffer overun in the Date: field

      Execute code with your account before you even see the message isn't what I'd call 'behaving'

      --
      There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
    6. Re:Couldn't do it alone... by tswinzig · · Score: 2

      Will the makers of Outlook go to court for actively helping the spread of the worm by deliberately insecure handling of attachments?

      Yes, but only if we also take God to court, for making people so stupid.

      --

      "And like that ... he's gone."
    7. Re:Couldn't do it alone... by Anonymous Coward · · Score: 0

      Saying "we can't blame Microsoft, we should blame IT" isn't fair, nor is it true. At my office, I pleaded with the owner of the company not to use Outlook, as it is not only prone to viruses, but has inherent flaws in its calendar andtask features. He used Outlook somewhere else, so he wants to use it here. He is not an informed computer-user, so he relies on my judgement. However, since he is not an informed user, he thinks a company that has made billions wouldn't have become rich by writing shoddy software, so he listens when they tell him the product is secure.

      New viruses emerge every day, anti-viruses are never 100% effective. A company that has an opt-out "feature" of automatically running scripts from within a program that communicates with every/any one on the outside world is just plain stupid. This was bound to happen, and has been happening for years without them ever fixing it...I wouldn't have blamed them in 1997, but this is 2001. When exactly will they learn?

    8. Re:Couldn't do it alone... by pgrote · · Score: 1

      Again, a decision was made to use the product. Period.

      Microsoft didn't force the person to use it. You informed the person of the ramifications of using it and he decided to.

      People make decisions that seem stupid, perilous and ill informed everyday.

      That does not mean the tools they use as a result of those decisions should be held responsible.

      I mean if someone uses gasoline to clean their water heater and then relights the pilot light should the gasoline company be held accountable?

    9. Re:Couldn't do it alone... by Anonymous Coward · · Score: 0

      I mean if someone uses gasoline to clean their
      water heater and then relights the pilot light
      should the gasoline company be held accountable?


      Uh, yeah... If the company had been selling an "integrated water heater system" and bundled gasoline as the recommended integrated heating solution.

      Ken

    10. Re:Couldn't do it alone... by Anonymous Coward · · Score: 0

      Do you have any evidence that Outlook Express is insecure, or are just spraying FUD?

    11. Re:Couldn't do it alone... by Anonymous Coward · · Score: 0

      I'm curious if you have a specific understanding of the security issues with Outlook, or if you are just piling on.

    12. Re:Couldn't do it alone... by Ed+Avis · · Score: 2, Insightful

      The biggest security problem is failing to distinguish between opening a file and _executing_ a program. Remember when the standard line was, you cannot get a virus just from reading a message? That is still true, but Outlook (and Windows as a whole) deliberately blurs the line between reading information and executing code, so it's possible for users to become infected just by choosing to 'open' a document. Really Windows should have two different actions, 'open' and 'execute', but given that it doesn't, Outlook should at least make some effort to figure out those file types that are likely to execute code when run (.exe .com .bat .pif .cmd, maybe others) and warn about them. It's been a while since I used it ('Outlook 98 copyright 1997 Microsoft Corp.') but judging by the spread of worms it doesn't seem to have improved.

      Another factor contributing to the confusion between files and executables is the 'user-friendly' hiding of extensions, as used by Loveletter (loveletter.TXT.vbs, or something like that). And of course there is no excuse for basic errors like buffer overruns - a few such bugs are forgivable in ordinary applications, but an Internet mail client really needs more care in design.

      Finally, these weaknesses have often been pointed out and exploited for several years now. Yet Micrsoft never seems to do anything about them (apart from some kludge to drop all .exe attachments at the mail server). So it's hard not to class that as in some way 'deliberate'.

      --
      -- Ed Avis ed@membled.com
    13. Re:Couldn't do it alone... by Anonymous Coward · · Score: 0

      OK - but all Windows (and Mac) mailers pretty much have this fault, which as you point out extends to the shell too. NTFS has an executable perm (almost always set), but you can't assume NTFS.

      Not to mention that the file type metadata (extensions) is totally fubar in Windows.

      The real problems with Outlook are:
      1) Handful of buffer overflows which automatically execute code. It's likely that other mailers have this problem too, but have received less attention from the white hats.

      2) Easy to use scripting API. This really means nothing except that it allows non-programmers to write worms.

      Outlook now blocks executable attachments - doesn't drop them, just makes them inaccessible from the client. Very unpopular feature, but given the underlying design issues with Windows and the uneducatable userbase, not a bad decision.

    14. Re:Couldn't do it alone... by Ed+Avis · · Score: 1

      I'd like to know who thought it would be a good idea to expose a scripting API to untrusted email messages. I mean, it's not something you can add to the program by accident...

      --
      -- Ed Avis ed@membled.com
    15. Re:Couldn't do it alone... by itarget · · Score: 1

      Remember when the standard line was, you cannot get a virus just from reading a message? That is still true, but...

      Actually, with the buffer overflow in Outlook's Date: field a while back, it ceased to be true. Virii could execute and proliferate the moment it hit your inbox wether you read the message or not, let alone execute an attachment.

      --

      "Where shall the word be found, where will the word resound? Not here, there is not enough silence." -T.S. Eliot
  12. Announcement by Anonymous Coward · · Score: 1, Funny

    We at Micro$oft strive to give as much help and support to the budding young developers as possible. To this end we announce the Micro$oft Virus Developers Network (M$VDN). Join now, download our VDK 1.0 and recieve a FREE one month subscription to our developers resource center, where you can learn about new security holes and exploits as soon as we make them!

  13. He used a kit? What a fag by Anonymous Coward · · Score: 0

    REAL programmers write everything in pure machine language!

    B8 00 4C CD 21

    1. Re:He used a kit? What a fag by Anonymous Coward · · Score: 0

      lda #$00
      jmp $dc21

      What a interesting piece of code indeed! If you got a 6502 processor you can actually run this program! Let's look at what this does... Why, first you clear every single bit in the accumulator there is to clear and then you unconditionally branch to $dc21. I wonder what wonders await all those cleared bits in the accumulator when code in the $dc21 wonderland gets executed? Maybe they will get pushed to the stack, (wheeee!) or there is a store accumulator and all these cleared bits get to go on the ride of their lives....

    2. Re:He used a kit? What a fag by Anonymous Coward · · Score: 0

      real 'hackers' program in asm and shave with chainsaws

  14. Reasoning... by Telek · · Score: 3, Insightful

    The really interesting part is that this kid wasn't even a programmer. He just downloaded a kit.

    and

    The defendant, Jan de Wit, turned himself in to the police in his hometown Sneek, Netherlands, on Feb. 14.

    I would venture a guess to say that those are the reasons why he was given such a light sentance, and the fact that he was 20 years old. A little remorse goes a long way in the courts, and turning yourself in too usually helps to give a lighter sentance.

    --

    If God gave us curiosity
    1. Re:Reasoning... by thue · · Score: 0

      You put people in prison to make it clear to them that their actions are unacceptable. The prison term then hopefully teaches them not to repeat their actions.
      Some also want revenge over criminals for their actions, but I usually don't consider that a valid reason.
      Lastly, long punishment could serve as a discouragement to other people, but it would in a sense be unfair for someone to be punished for no other reason than this, and should be avoided if possible.

      If he had already learned his leason it served little purpose to put him in prison, and the punishment is fair, IMO.

    2. Re:Reasoning... by Telek · · Score: 2

      But prison is NOT a deterrant. There are people who would rather be in prison than on the streets. I can agree that there is merit in allowing them to exercise, watch TV, study, and do many other things that some people outside don't have the opportunity to do, but it is those who take advantage of the situation that ruin it for everybody. How can you justify sending someone to prison for hacking a computer beside someone who is a serial rapist? The justice system is royally screwed up. If prison were a box in the artic where you airdropped food in once a day, I think that we would have far far far less people becoming criminals than you do today.

      --

      If God gave us curiosity
  15. Anna..mmmmm by Anonymous Coward · · Score: 0
    Click here to see pictures of God.

    She is so beautiful there are no words to describe her.

  16. Re:i am your fs1rt ps0ting god... by u-238 · · Score: 0

    you are a total fag. and nothing more. i am sorry i had to break it to you this way, but somebody has to tell you...and its about time.

  17. GOOD! by Kamel+Jockey · · Score: 1

    I was wondering how long it would take for the police to finally go after these low-lifes who seem to have nothing better to do with their time than cause other people aggravation. After having to deal with these script kiddies for quite some time, I think jail is the safest place for them. I know quite a few IT people who would love to hunt down these jerks and kill them (Jay and Silent Bob style hehe). I think that in addtion to putting these people in prison where they belong, they should also be fined for all the costs incurred by victims of these viruses.

    Anyone who makes a "virus kit" or anything similar should also be imprisoned and fined. Figuring out how to breach security in software and letting the authors know so they can fix it is one thing, and its a good thing to do. But actually writing a program to exploit shortcomings in programs has nothing other than malice written all over it.

    On the other hand... one could also make a case that people should be allowed to sue software manufacturers for costs incurred dealing with virii, etc. if the software company was indeed informed about the problem but took no corrective action to fix it. Of course, if they released a patch and you didn't bother to install it, or you didn't bother to install/set up the software correctly, that is and still should be your own fault.

    --
    In case of fire, do not use elevator. Use water!
    1. Re:GOOD! by sheetsda · · Score: 1
      Anyone who makes a "virus kit" or anything similar should also be imprisoned and fined. Figuring out how to breach security in software and letting the authors know so they can fix it is one thing, and its a good thing to do. But actually writing a program to exploit shortcomings in programs has nothing other than malice written all over it.

      Some authors will refuse to patch the software until something is actually exploiting it vulnerablities. *cough*Microsoft*cough* See also this comment.

    2. Re:GOOD! by Kamel+Jockey · · Score: 1

      Surely though, anyone who writes a program which exploits security holes for malicious purposes and then willingly distributes it to anyone who wants it is no better than a willing accomplice in a DDOS attack.

      This is not the same as punishing someone who sells you a gun because you use it to protect yourself. These kinds of malicious programs serve no legitimate, useful purpose of any kind. While I don't think coding should be a crime, the programs DO cause real damage which costs real money to fix. Something needs to be done about it.

      One example, not too long ago, someone posted instructions which would allow Hotmail users to read emails belonging to other Hotmail users. What purpose was served by posting this stuff in a public forum? We had already known hotmail security was breached. Did the poster think that someone might just use it to illegally break into another person's hotmail account?

      --
      In case of fire, do not use elevator. Use water!
    3. Re:GOOD! by Graymalkin · · Score: 2

      For fuck sake dude, a good sized rock can be used to kill someone. Does that mean rocks of particular sizes ought to be outlawed? Should the writers of compilers be held accountable for people who used their compiler to make a virus? Run of the mill network utilities can easily be used to DOS some poor sap with a slower connection than yours. You post vulnerabilities in order to expose the fact that company X doesn't test their shit properly and ought to learn how before they lose all their customers. I'd rather use a product that has had bugs exploited and fixed than one where I didn't know if it had been exploited or not. If you're the target of an exploit especially a dumbfuck exploit like macro virii then you live and learn.

      --
      I'm a loner Dottie, a Rebel.
    4. Re:GOOD! by sheetsda · · Score: 2
      One example, not too long ago, someone posted instructions which would allow Hotmail users to read emails belonging to other Hotmail users. What purpose was served by posting this stuff in a public forum?

      The purpose was to force Hotmail to fix the vulnerablity. It worked. The reason it worked was because the Joe Blow User found out about the vulnerablity due to the coverage, and took appropriate action. Different people take different actions, but the end result gave Hotmail a clear message: fix it, or you won't have enough business to sustain your operation. Often these security holes are considered too obscure and therefore not a threat. All you have to do it get the message out to a couple blackhats and average users, and walla, it becomes a serious threat even to those who would rather not deal with it.

      We had already known hotmail security was breached. Did the poster think that someone might just use it to illegally break into another person's hotmail account?

      Yes, the poster knew all too well that the blackhats would find and exploit the vulnerablity if it were made public, and they would run amuck if it were not fixed, as such he/she made it so public that Hotmail is left with no choice but to fix it. The same principle is the reason we invest in the stock market: We give up a little bit of something now, to get more back later. That something is money or security depending on your favorite paradigm.

  18. Re:Fuck you dick by u-238 · · Score: 0

    ha...dont worry. all of your family and ancestory will be annialated. soon, your sorry muslim ass will die too...and in a few generations, the world will be completly rid of your scum.

  19. I remember when... by Bistronaut · · Score: 1

    ... my buddy and I were reading about different poly-morphic and boot-sector viruses in the program F-Prot. We came across one that was written in Visual Basic - and laughed. Boy, have things changed!

  20. Right decision by lukel · · Score: 2

    Sure kids who program or release viruses should get their wrirsts slapped and do some community service. What gets me is these stupid figures for damages that get banded about. If companies really are losing much as they claim, why don't they just hire someone to install security patches when they become available, it's not exactly rocket science. In my view if you have some critical systems but don't bother to add security patches when they become available, you are equally to blame and should not be allowed to claim damages.

    1. Re:Right decision by WolfWithoutAClause · · Score: 2

      Huh? If you leave your keys in the ignition of your car, and someone jumps in takes it for a ride and torches it, you're not allowed to sue him for the loss of your car because you left your keys there?

      And that's a lot more lacsidasical than we are talking here- it's closer to a manufacturing a car that's easy to hotwire.

      In my view you're an ass. There are very real costs with setting a system up right. How long does it take you to reinstall your operating system? My personal system takes a couple of evenings for the basics and won't be right for weeks.

      >If companies really are losing much as they claim, why don't they just hire someone to install
      >security patches when they become available, it's not exactly rocket science.

      They do. These networks can be vast though, and getting to all of the machines in time can be difficult. Also, many patches or fixes involve switching off services or features. Companies cannot blindly install patches, they need to test them first. It ain't easy.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    2. Re:Right decision by lukel · · Score: 1

      IMO your car analogy misses important features of the case. I think a better analogy would be a fire officer deciding what fire precautions to take. He knows that for every fire, someone must take the blame. He also knows that most fires are started by arsonists. Taking fire precautions is a time consuming and tedious job. Whatever punishment is given to arsonists, arson attacks won't stop: most arsonists get away, and most of them are kids so can't be punished severely anyway. The fire officer knows this, the problem is that what's important to him and his immediate manager is that they don't get blamed for fires and sacked, and that they are not overworked taking fire precautions. If there is a fire and they're not blamed, it's not the end of the world for them since other people do most of the clearing up. They have an incentive take less than the optimum level of fire precautions and to make sure arsonists get all the blame for fires.

    3. Re:Right decision by archen · · Score: 2, Insightful

      "How long does it take you to reinstall your operating system? My personal system takes a couple of evenings for the basics and won't be right for weeks. "

      Two words dude: Norton Ghost

      Besides which as most any computer oriented person will tell you, backing everything up is most important.

    4. Re:Right decision by WolfWithoutAClause · · Score: 2

      >If there is a fire and they?re not blamed, it?s not the end
      >of the world for them since other people do most of the clearing up.

      Oh right, so the architects of the WTC were to blaim for the building falling down? [In that case I think they should be admired that the building stood for an hour after such a brutal attack; and the failure mode was the best you could really have- almost straight down.]

      Some or even many attacks cannot be realistically avoided; but can only be dealt as best anyone can when they occur. We don't know the holes until somebody finds them, and the bad guys sometimes find them first.

      >They have an incentive take less than the optimum level of fire
      >precautions and to make sure arsonists get all the blame for fires.

      Not so much; if they are being significantly reckless they will carry some small part of the blame in all likelyhood, same as if you leave the door open; and that can be career affecting. But still, 90+% of the blame rests on the attacker.

      In the company I work for Red Code attacked a handful of servers out of hundreds or even thousands- the rest had been patched; in that case perhaps there was some recklessness involved, they should have patched them. But 95% of the blaim lies at the doors of the authors.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    5. Re:Right decision by WolfWithoutAClause · · Score: 2

      >backing everything up is most important.

      Yeah, if you have the hardware to do that; and even then only if your data is necessary.

      People that go around trashing, writing worms, trojans or viruses, or cracking are dirt. It's like stealing peoples lives- often hundreds of dollars worth of time per system. Even with backups.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    6. Re:Right decision by lukel · · Score: 1
      Oh right, so the architects of the WTC were to blaim for the building falling down?

      No. Noone in their right mind would have expected those attacks. However, when you connect a machine to the internet, you can be almost certain it will be port scanned for weaknesses.


      In the company I work for Red Code attacked a handful of servers out of hundreds or even thousands- the rest had been patched


      Security can never be 100%. I'm suggesting that if reasonable precautions haven't been taken, then blame should be shared.

    7. Re:Right decision by WolfWithoutAClause · · Score: 2

      >I'm suggesting that if reasonable precautions haven't been taken,
      >then blame should be shared.

      How many hours of community service should the system admins have been given then? Get a clue dude, you've lost it.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    8. Re:Right decision by lukel · · Score: 1
      How many hours of community service should the system admins have been given then? Get a clue dude, you've lost it.

      LOL.. Off the top of my head.. 24 hours per month.

      (If you read carefully, I said if people aren't taking precautions, they shouldn't get damages - not that they should do community service.)

    9. Re:Right decision by aozilla · · Score: 2

      What if circuit city accidently marks the price of its TVs at $5.00? The value of the TV is $100. They were selling for $500. You hear about this "bug", and go to circuit city and buy 1000 TVs. The cashier accepts the purchase and you go home with 1000 TVs for $5000. The TVs are destroyed in an explosion when you get home. Should you owe Circuit City $95000, $495000, or nothing? Should you have to do community service, or spend time in jail?

      --
      ok then your [sic] infringing on my copyright! Could you as [sic] me next time before STEALING my comments for your own?
    10. Re:Right decision by WolfWithoutAClause · · Score: 2

      Are you admitting to something? ;-)

      IANAL; sounds like you would need one...

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
  21. D'oh by zpengo · · Score: 4, Offtopic

    And here I was seeing "Kournikova" and "slapped" and thinking this article was going to be much more interesting (and perhaps have some pics!)

    --


    Got Rhinos?
    1. Re:D'oh by Anonymous Coward · · Score: 0

      Almost as funny as the "Kournikova spreads aggressively" headline that was on Yahoo a few months ago...that story was a disappointment, too.

  22. That seems like a reasonable sentence by iabervon · · Score: 3, Insightful

    It's a light sentence, as sentences go, but it makes the whole process, from putting it together to serving the sentence, more trouble than it's worth in entertainment.

    The reason lame modern viruses get written is that it's really easy; you put in very little time, and then get to hear reports about how it spreads: very little effort, a little entertainment. If he'd known that it would take 250 hours of work, he probably wouldn't have bothered.

    The same goes for hacking websites: people do it because it doesn't take any real effort. If it took 250 hours of boring work that you can't automate, people wouldn't bother.

  23. all you can get ur hands on are witetrash by u-238 · · Score: 0

    Sorry....even white trash has enough taste not to fuck an arab. With your primitive intelect, grotesq smell, inferior beliefe and culture system, and down-rught uglyness. Question:you are in america. No one hurts you our persecuts you (i know this because you said you live in arazona...and you are happily siting on your computer posting in a slashdot forum.) Why the fuck do you think you shuld hurt us? does your feeble mind succomb to bin laden's pathetic propagand? are you that simple of a man?

  24. Re:Keep this crap off of Slashdot! by Anonymous Coward · · Score: 0

    "I'm ready for my close-up, Mr Katz"

  25. Ra-Slurm-Gurm-Roort, pharao, alive at 4732 by Anonymous Coward · · Score: 0

    I just heard some joyful news on talk radio - pharao and son of Ra Ra-Slurm-Gurm-Roort was found alive in his egyptian tomb this morning. There weren't any more details. I'm sure everyone in the Slashdot community will welcome him - even if you won't enjoy his work, there's no denying his upcoming contributions to popular culture. Truly an ancient icon.

  26. Re:Well, that's interesting enough by u-238 · · Score: 0

    she would never fuck your sorry sand nigger ass. you might wanna try a camel...they usuly dont mind.

  27. Damn. by Anonymous Coward · · Score: 0

    Damn. I thought it said, "Kournikova Gets Slapped."

    I got all excited for nothing.

  28. You aren't the real Allah troll! by Anonymous Coward · · Score: 0

    He said he lived in Arizona. Area code 905 is in Canada.

    1. Re:You aren't the real Allah troll! by jrockway · · Score: 1

      What a fool ;)

      --
      My other car is first.
  29. crime and punishment by shelflife · · Score: 1

    I think that all viruses show how much the Internet relies on trust, and how easy it is to violate that trust. To me this is like removing stop signs at intersections, or disabling stop lights -- on the one hand, a thoughtless prank,
    ; on the other hand, a criminal act that costs countless money and time. I hope this kid has to do sysadmin work, install patches, and fight off other viruses as part of his community service.

  30. Why did they to that... by Karpe · · Score: 2

    ...to the father of the beutiful tennis player?

  31. Kevin Mitnick by Zero__Kelvin · · Score: 2, Interesting


    "A man was sentenced to 18 months in jail in the U.K. in the early 1990s. The man served 11 months, said Hypponen.' but that can't be true. What about Robert Morris?"

    Not to take away from RTM, but what about Kevin Mitnick?

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    1. Re: Kevin Mitnick by Inthewire · · Score: 2, Informative

      KM didn't release a virus

      --


      Writers imply. Readers infer.
    2. Re:Kevin Mitnick by ArchieBunker · · Score: 0

      Mitnick fucked with the wrong people and lied to the feds. Also his 4 year jail term was because of HIS lawyers. They kept requesting the trial date be pushed back so they could gather evidence. I don't see any problems.

      --
      Only the State obtains its revenue by coercion. - Murray Rothbard
    3. Re: Kevin Mitnick by Anonymous Coward · · Score: 0


      And you would know this how?

    4. Re:Kevin Mitnick by Anonymous Coward · · Score: 0


      Does this actually have anything at all to do with the post you are 'replying' to? Clearly not, which explains the rating.

    5. Re: Kevin Mitnick by Inthewire · · Score: 1

      Good point. KM was not sent to prison for releasing a virus.

      --


      Writers imply. Readers infer.
  32. Wrist slapped? by sedawkgrep · · Score: 2, Insightful

    240 hours of community service is quite a bit, at least in my book.

    Say you work a 40-hour week (days)...that pretty much only gives you weekends to devote to service. If you work 8 hours on saturday, it will take 30 weeks to complete the sentence.

    Anybody want to give up 30 saturdays? I didn't think so.

    The punishment is certainly less than what one might have expected, but I think this is a good trend, not a bad one. I'd much rather see these marginally troublesome white-collar criminals get easier sentences than ANY drunk driver or other violent criminal acts. So the virus is bad. Sure. Was there any loss of life? Was anyone maimed or psychologically traumatized (heh) over the incident? Hell - he didn't even try to steal information or money.

    Punishments should fit the crime. What he did was not excusable, but a little perspective check is in order - especially after tuesday's events.

    sedawkgrep

    --
    Is that a salami in my pants or am I just happy to be me?
    1. Re:Wrist slapped? by Anonymous Coward · · Score: 0

      Actually, in the Netherlands killing someone by drunk driving will usually lead to the same 240 hours of civil service©©©

    2. Re:Wrist slapped? by Kamel+Jockey · · Score: 1

      Say you work a 40-hour week (days)...that pretty much only gives you weekends to devote to service. If you work 8 hours on saturday, it will take 30 weeks to complete the sentence.

      Anybody want to give up 30 saturdays? I didn't think so

      Why should the criminal get to determine the conditions under which his sentence will be imposed? He should have to run the risk of losing his job to complete his sentence. Had the law not been broken, he would not be in such trouble.

      --
      In case of fire, do not use elevator. Use water!
    3. Re:Wrist slapped? by Tyndareos · · Score: 2, Funny

      Actually, in the Netherlands killing someone by drunk driving will usually lead to the same 240 hours of civil service
      Only if you're a famous soccer player or opera singer ...

    4. Re:Wrist slapped? by FKnight · · Score: 1
      Say you work a 40-hour week (days)...that pretty much only gives you weekends to devote to service. If you work 8 hours on saturday, it will take 30 weeks to complete the sentence.

      Say you work a 40-hour week and at 4:45 pm on a Friday a new virus gets emailed to someone in your company and starts renaming random files on your file server? That pretty much only gives you the weekend to devote to restoring from backup, instituting new procedures, etc.

      So the virus is bad. Sure. Was there any loss of life? Was anyone maimed or psychologically traumatized (heh) over the incident?

      There was no loss of life, but a system administrator had to spend the next day and a half, while his wife and 2 year old kid were at home, restoring from backup, updating virus definitions, and cleaning infected machines. If he gets paid hourly, the company lost money. If he's salary, he lost money -- and a weekend day, maybe the entire weekend, with his wife and kid at Disney World. I think 240 hours is more than fair.

    5. Re:Wrist slapped? by jawtheshark · · Score: 1
      but a system administrator had to spend the next day and a half, [...] updating virus definitions

      Sorry, but that was the admins responsibility is the first place: a good admin will prevent virus infections at all cost. Hey, I'm just admin of our family network and I update virus definitions each month twice.... In a company he should even filter out all executables at mailserver level. Sorry, I don't condone writing viruses but companies should be protecting themselves.
      Normal people, I mean, granny using her computer, are of course not protected that way....Companies and admins administering the networks have no excuse. They are in fault when a virus gets through.

      --
      Ahhh...the great dumpster continuum. Many a free computer will be found there. -- sowth (748135)
    6. Re:Wrist slapped? by haruharaharu · · Score: 1

      He should have to run the risk of losing his job to complete his sentence

      There you go, trying to call down hellfire and brimstone. One of the intents of a sentence is rehabilitation - the convict should be more capable of normal functioning at the end of this, not less. What do you think will happen if he loses his job?

      --
      Reboot macht Frei.
  33. Re:Your false beliefs of superiority... by Anonymous Coward · · Score: 0

    and you wipe your asses with your hands. i mean whats that all about?

  34. Virus Kits aren't that new by Innominandum · · Score: 1

    Last few years? Hmm. Virus kits have been around for awhile now. Right now I am looking over the docs for IVP (Instant Virus Production Kit) 1.7 which has a time-stamp from 1992. It supported .COM/.EXE(MZ) infections, encryption, etc. If you look through a virus bestiary, all of these viruses begin with IVP.*. I remember seeing a "review" of the kit by a virus software company, calling it shoddy. So I guess Virus Kits are nothing new. Just thought I would mention it.

    1. Re:Virus Kits aren't that new by jandrese · · Score: 2

      I remember those kits. Especially the one that came with wordstar built in that was set up like Turbo-C. They were pretty shoddy IIRC, it was the quickest way to write a virus that all antivirus packages would immediatly detect (because the kits themselves tended to leave their signature on the virus). I do remember some of the more sophisticated kits claiming to make your virus automatically polymorphic, but I don't know if they actually worked. Most of those kits were riddled with bugs to boot (heck, most _viruses_ have bugs in them, have you ever read through those virus bestiaries?).
      Besides, I never heard of any kits that helped you to write boot sector viruses, which were the only ones that ever seemed to spread anywhere, at least before Word Macro viruses and Outlook worms came along.

      --

      I read the internet for the articles.
    2. Re:Virus Kits aren't that new by Tungz10 · · Score: 1

      They tend to have bugs because the authors don't want to test them on their own machines.

  35. The Death Sentence by Aceticon · · Score: 2
    "I didn't know what it (the worm) would do. I just clicked away... I did this without thinking and without overseeing the consequences and without the intent to cause damage to anyone," he said. "I am not a programmer; this was the first time I created something myself."

    We should send a message to all clueless amateurs out there that go around "clicking" in virus making kits and creating Outlook viruses that force law abiding companies to close down their e-mail systems and loose thousands of dolars in revenues (imagine all those suffering employees that cannot send the latest joke to all their collegues).

    If we don't act swiftly and decisively now, we risk having these "amateurs" playing around with Code Red Creation Kits.

    I say hang the guy in Dam square in Amsterdam - that will show them!!!

  36. just by the way ... by timothy · · Score: 1

    I got that quote from ESR's page, and it may not be what you think it is :)

    http://tuxedo.org/~esr/fortunes/rkba.html

    timothy

    --
    jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
    1. Re:just by the way ... by Anonymous Coward · · Score: 0

      And for the first time in recent history, the 120 char limit on sigs causes an internation incident...

    2. Re:just by the way ... by timothy · · Score: 1

      I only included part of the quote, because I'd like people to investigate what it means / where it's from.

      So I didn't run into the sig limit, really ;)

      Tim

      --
      jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
    3. Re:just by the way ... by Anonymous Coward · · Score: 0

      Perhaps if you made it into a clickable link, people would BE ABLE TO INVESTIGATE WHERE IT'S FROM, YOU JACKASS!

    4. Re:just by the way ... by timothy · · Score: 1

      Oh well. Guess they'll have to figure it out on their own.

      timothy

      --
      jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
  37. To put this in simple terms by Anonymous Coward · · Score: 0

    If you choose a OS that can be infected with Virii (M$ & some MacOSs, M$DOS) then you CHOOSE to recieve the consequences along with it. You CHOOSE an insecure OS that ALLOWS it to duplicate itself. For god's sake. What kind of an OS would execute a file by itself? I don't see any Unix, or most embeded OSs doing this!

    Don't complain when you get virii. Because you CHOOSE an OS that can get it. Stop your childish whining.

    1. Re:To put this in simple terms by Anonymous Coward · · Score: 0

      I guess you didn't realise viruses and worms exist for linux too.

    2. Re:To put this in simple terms by Spruitje · · Score: 1

      Well, that just the reason why I use MacOS.
      The change that you can get a virus is almost zero.
      The funny part about this is, that all those viri (or scripts) don't work with Outlook express for Macintosh.
      No automatic execution of scripts and/or programs like with Outlook and Outlook express for Windows.
      That's one advantage of the MacOS platform.
      I'm using Eudora Pro and never had one virus.
      And I avoid using any M$ product at all.
      That's the only way to make sure that the change that I will get a macro virus is almost zero.
      The problem with M$ software that it is very simple to make a macro- or script viri or worm.
      Not using this software is the best way of preventing spreading of worms and viri.
      And of course, you should always use anti-virus software with windows.
      And update it at least once a week.

    3. Re:To put this in simple terms by Anonymous Coward · · Score: 0

      You are on crack if you think the Mac is immune from viruses for any reason except it's relative lack of popularity.

      (Well, I'll backtrack a bit ... "Inside Macintosh" attempts to encourage programmers to check all return values for errors. That may have lead to better programming practices, but it's hit-n-miss.)

      None of the Outlook virues on Windows work for Outlook Express either. Anytime Outlook has auto-executed anything it's been considered a bug, and that is not how the Anna virus spread.

      Anyway, it's smartasses like you that make me want to whip together a Mac-based worm and call it anna.jpg. Enough dumbfucks would open it up to shut you up.

    4. Re:To put this in simple terms by Spruitje · · Score: 1


      Anyway, it's smartasses like you that make me want to whip together a Mac-based worm and call it anna.jpg. Enough dumbfucks would open it up to shut you up.


      Well, contrary to your remark reality already proves that you are wrong.
      There are about 56 viri for the Mac.
      Almost all of them don't work anymore due to the fact that they aren't written correct and use obsolete API calls which aren't available anymore since MacOS 7.0.
      Compare that with the almost +/- 60000 viri for windows pc's....
      Second, most viri for the Mac are just stupid programmerglitches.
      Like for instance the hypercardvirus.


      None of the Outlook virues on Windows work for Outlook Express either. Anytime Outlook has auto-executed anything it's been considered a bug, and that is not how the Anna virus spread


      Nope, it isn't a virus.
      It is just a stupid script which is executed by Outlook when you double-click on it.
      And that is just one of the biggest problems with Outleak.
      I'm a sysadmin at a small company.
      The only way to prevent that we receive any script- and/or .exe viri is by filtering all .exe, .scr and some other type files.
      So, in front of the exchangeserver there is a mailserver with sendmail and some filtering software and anti-spam software (with a large database).
      This seems to be the only way to secure an exchangeserver.
      And it works all the time.
      Since the "i love you" script we haven't had one virus.

    5. Re:To put this in simple terms by Anonymous Coward · · Score: 0

      Are you trying to contradict my post? Because you totally failed to do so.

  38. When CHOOSE an insecure OS. by Anonymous Coward · · Score: 0

    Oh? Why not blame a OS maker that makes an OS THAT AUTOMATICLY EXECUTES VIRII? You have no choice. The OS will execute it BY ITSELF. You choose M$ products, you CHOOSE to get a virus. Quit whining when you get one. If you don't want a virus, don't use an OS that can be infected with one. And don't be monkey brained enough to run the fscking thing.

    1. Re:When CHOOSE an insecure OS. by pgrote · · Score: 1

      Exactly. Risks are everywhere. There are risks associated with all choices people make. The idea is to minimize your risks if you want.

      It's a balance. No one should be surprised at this point that running Windows and Office is riskier.

  39. Of course. by Anonymous Coward · · Score: 0

    He is well within his rights [as is anybody] do do wtf they like on the computer with viruses or whatever.

    Releasing it is what made life hell for people, hence theres the crime.

    As long as its just him screwing with it and learning about stuff, who the hall can tell him what he can and cant do within the boundarys of his own computer?

    Oh hang on whats this DMCA thingy....

    Ali ( at london d0t c0m )

  40. Wow. A Virus SDK. by UnhandledException · · Score: 1

    In the name of all that's holy, don't let our marketing department hear about this!

  41. Bang by RetroGeek · · Score: 1

    The really interesting part is that this kid wasn't even a programmer.

    The really interesting part is that he did not make the gun, just pointed it and pulled the trigger.

    --

    - - - - - - - - - - -
    I am a programmer. I am paid to produce syntax not grammar. Deal with it.
  42. The 1990s UK Case - not about viruses by Vainglorious+Coward · · Score: 1

    The conviction in 1990 wasn't for creating a virus. I know, because I was network manager at one of the sites involved and was responsible for logging network activity which formed part of the evidence. In that case, the individual had found a vulnerability in the ICL 3980 mainframe series - in essence, root password changes were logged to a journal which was publicly readable. He had already taken over several machines in the UK before we were alerted, but as it happened he hadn't managed to root us because we were "slack" in our password changing and the root password hadn't actually been changed for many months. Other more diligant sites who changed the password weekly or monthly weren't so fortunate.


    For a couple of weeks I created logs of his connections to our machine; they were traced back to a dial-up connection at one of the colleges in London. Once the evidence was in place, the authorities gave him (I quote the detective who interviewed me) "the wobbly door treatment" one evening, much to the amazement of his mother who was cooking dinner while her son was "playing" with his computer in his bedroom


    At the time, the Computer Misuse Act was only just going through parliament and therefore he had to be charged under existing laws. The prosecution case was that modifying the magnetic fields on hard drives amounted to criminal damage, and it was for this that he was tried and convicted. He was sentenced to 12 months, with a further 6 months suspended. He came out after 11 months to an operator job with a company using ICL mainframes.


    --
    My next sig will be ready soon, but subscribers can beat the rush
    1. Re:The 1990s UK Case - not about viruses by spectecjr · · Score: 2

      The conviction in 1990 wasn't for creating a virus. I know, because I was network manager at one of the sites involved and was responsible for logging network activity which formed part of the evidence.

      Uh, actually, no, it was for creating a virus, and had nothing to do with mainframes as you suggest.

      I had corresponded with the author (he was part of the SAM Coupé programming community). I know who he is. I have tons of his source code. And he was convicted for (on the surface of it) creating the first assembly-language polymorphic virus, and putting it into a virus kit.

      The virus was called Smeg.

      Here's a link that you might find informative:

      News story

      Simon

      --
      Coming soon - pyrogyra
  43. Shit Happens by Anonymous Coward · · Score: 0

    mod up the above post

    its funny
    in the context of the post by the indignant Arab, although i can understand both their anger. reportedly muslim taxi drivers in NYC are afraid to go to work and ignorant racists have mistakenly attacked Sikhs (who wear turbans and are not muslim).
    This tragedy has however usually brought out the best in _MOST_ people

    1. Re:Shit Happens by LoudMusic · · Score: 1

      Actually I'd rather they didn't mod me up. This entire thread has nothing to do with the origonal post. And you're an anonymous coward ... like our recent terrorists.

      Get a name, log in, be somebody for a change.

      ~LoudMusic

      --
      No sig for you. YOU GET NO SIG!
  44. Anti Virus by Anonymous Coward · · Score: 0

    AV pr peeps always predict ludicrously high "damages" purely to push sales to their product, they make it sound worse situation than it actually is by use of high "damage" estimates.

    $50,000.000.000 and so on ..

    if they have you all fearing the damage some lame VB worm "can cause", then they have you all buying their "solution" (which don't do very good jobs anyway).

    in short : Blown out of all proportion by av companies and pr, to sell stuff.

    brought back down to reality by the courts, It just show's you how over exajerated AV "news" really is.

    Don't trust the media , learn to read between the lines.

  45. Visual Virus 1.0 by Camel+Pilot · · Score: 1

    Outlook makes virus propagation so easy all you have to do is come up with a catchy subject line and the rest is a CS101 project.

    1. Re:Visual Virus 1.0 by Anonymous Coward · · Score: 0

      I would consider SirCam (Delphi, not Outlook-specific) to be a CS101 project. An Outlook-specific VBS virus doesn't require anything more than a spare hour and the help file.

  46. haha by ArchieBunker · · Score: 0

    If they announced kernel 2.6 was pushed back a year then all the linux fundies would be spouting off about how its better to wait. Just look at any mozilla story for another example.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
  47. What's the matter with people? by Adrian+Lopez · · Score: 1

    Eighteen months in jail is nothing like getting your wrists slapped! That's a year and a half in confinement at a very dangerous place. It's a jail sentence, not a slap on the wrist.

    What the hell is the matter with people who think they're entitled to take away people's freedom for causing a little economic damage? People are more important than money!

    A lot of these hackers might learn their lesson through public humiliation and education. Jail does nothing to fix people, so why the hell resort to it except in hopeless cases?

    --
    "In prison you just have to shut your eyes and take it. Here you have to shut your eyes and give it."
  48. my mistake by Adrian+Lopez · · Score: 1

    The guy who got 18 months was a different person. That's what I get for not reading the story.

    I think they should return the kid his computer. They should delete the viruses and let him keep his computer and data. Just because he released a virus shouln't be reason to seize his entire digital "assets".

    --
    "In prison you just have to shut your eyes and take it. Here you have to shut your eyes and give it."
  49. Robert Morris by evil_one · · Score: 1

    didn't write a virus. It was a worm. It sought out vulnerabilities that were (at the time) unknown to the majority of internet users. It replicated and attempted to spread at such a rate it crippled the internet.

    --
    Desperation is a stinky cologne
  50. Outlook Express "security" by thrig · · Score: 1

    Google lists a few. Looks pretty insecure to me.

    Not convinced? How about doing a search for Outlook Express at Security Focus?

    Or browse a few Crypto-Gram by Bruce Schneier. Good reading, IMHO.

  51. Virus kits... by BarefootClown · · Score: 2

    ...c'mon, where's the craftsmanship? Where's the pride in your work? When I wrote viruses, it was all about doing it yourself, accomplishing something. Now you don't even have to be a programmer, you just have to know how to point-and-click. I tell ya, when pride in craftsmanship goes down the toilet, there's nothing left.

    --

    "Make it ten--I am only a poor corrupt official."
    --Captain Louis Renault (Claude Rains), Casablanca

  52. CmdrTaco's Weird Idea of Sentences by OnanTheBarbarian · · Score: 2

    CmdrTaco appears to be one of those people out there who have a rather confused notion of how severe sentences actually are. This is the second posting about how 18 months in juvie or 240 hours of community service + a criminal record amounts to a slap on the wrist.

    This is pretty dumb. Jail is boring, obnoxious, demeaning and occasionally dangerous, particularly for these type of people. A sentence of several months is not a slap on the wrist. Community service sounds about right.

  53. Me and Anna by Anonymous Coward · · Score: 0
    I went to Anna's house to-day in order to inform her about what happened on Tuesday.

    "Anna," I said, "You have to hear this: SKIDP's are dead. I'm sorry I had to bring you such horrendous news."

    "That's okay," she said, much to my surprise. "You wanna see what I did?"

    "Sure," I said.

    She then took off her panties, which was all she was wearing, and showed me: She had shaved her pussy, and I could see that it was glistening with her juices. Without a word, I dropped to my knees, and she flung her right leg over my shoulder. I immediately began licking her swollen clitoris, and sucking the warm smagma off of her labia. She moaned in ecstasy. I spread the lips with one hand in order to get my tongue more completely into her. I moistened the middle finger of my other hand with her juices, and slipped it into her asshole. As I did this, she came, flooding my mouth with her pussy's hot liquid. I drank some of it, and kept some of it in my mouth. I then stood up to kiss her, and she drank her own juices as though she was dying of thirst. Sliding my hard, throbbing cock into her was like sliding into melted butter. After fucking her like this for some time, I pulled out of her cunt and slid my pussy-drenched cock into her ass. She wrapped her legs around me (I was still standing up), and I began to pound her ass with my cock, fucking her harder and faster with every thrust. She screamed when she came, and as she did, I shot my hot load of cum into her asshole.

    After a few cigarettes smoked in silence, Anna asked me, "Did you say SKIDP's are dead?"

    "Yes," I replied. "Dead as Dr. Laura's battered, used-up fuckhole."

    She nodded sadly. She finished her cigarette and began to gently rub her own clit. I finished my cigarette and went back to work on her.

    1. Re:Me and Anna by Anonymous Coward · · Score: 0

      encore please. I need it. NOW!!! Thanks.

  54. Time to think by muffen · · Score: 1

    I think it is a great thing that he is going to trial. It is time for everyone to stop seeing people such as Jan de Wit as innocent. He created something that caused companies problems. The fact that he used a creationkit to create the worm is beside the point. Everyone are responisble for their own actions, and everyone should be prepared to take ALL consekvenses that their actions may have... always!

    If you look at most "new" viruses that are added to the databases of Antivirus products, you can see that they aren't actually new. Most of them are modified versions of some existing virus. So, if we get another case where someone modifies an existing virus to avoid detection by AV products, is he the creator of it? I say that he is the creator just as much as Jan de Wit is the creator of this worm.

    I hope that he this guy gets a penalty. I hope that this will prevent some other people from creating viruses. Something else that is good about this case is that the creator of the kit, [K]alamar, stopped creating more kits (his name was in on Argentinan TV and this scared him).

    Viruses are bad. Even though they fund an entire industri, I think everyone would be happier without them, even people in the industri. Bringing people that create or spread them to justice is a good start in the path toward a virusfree world.

  55. Re:Virus code and their evolution... by Anonymous Coward · · Score: 0

    Wow. The moderators have been horrible lately. What's wrong with this post? The fact that you don't agree with it does not make it flamebait. The person who moderated this down does a little bit to much of a different bait word.

    An Short:
    Fuckin Jerk-offs.

  56. I stand corrected by Vainglorious+Coward · · Score: 1

    Looks like the link you provided is indeed the case referred to in the article. The case I was involved in happened five years earlier in 1990 and I as far as I know, then and now, was the first time there was a conviction in court for a "computer misdemeanour". Just a coincidence that both perps ended up doing 11 months, I guess.

    --
    My next sig will be ready soon, but subscribers can beat the rush
  57. Justice? I don't think so! by natet · · Score: 1
    This is rediculous. For actually attacking computers on the internet, or for writing a virus that maliciously attacked other computers, these jokers got a wrist slap.

    For writing software that MIGHT be used to violate copyright law and therefore violates the DMCA, Dimitry Sklyarov gets the book thrown at him. Where the hell is the justice in that? Nothing that Mr. Sklyarov did was malicious, and yet his "crime" is treated far worse than those whose actions were deliberately intended to do damage. There is something seriously wrong with this picture.

    --
    IANAL... But I play one on /.
  58. At least admins actually worked now. by Anonymous Coward · · Score: 0

    For once admins had to actually work for the king's ransom that they get paid, and they actually whine about it? Buck up, this is what you are getting paid to do. I'm sorry that you had to be awakened from your sleep and actually do something useful for once, but you admins have it easy.

  59. the UK man that was jailed by bnjf · · Score: 1

    he is the black baron, or chris pyle. responsible for SMEG.

  60. Re:top notch by Anonymous Coward · · Score: 0

    nice work, man. but then,I'm pretty easy to please.

  61. Re:Keep this crap off of Slashdot! by Anonymous Coward · · Score: 0

    If you are interested in men, then you have more to "keep this crap off" than just slashdot. :)

  62. Reality check on sentencing by njdj · · Score: 1

    Anyway, the requested sentence is amazingly light -- 240 hours of civil service.

    How often people say that a sentence is "amazingly light". I think that should be a crime punishable by whatever sentence the speaker/writer says is "amazingly light".

    Just to remind people: at the trial, no evidence that this guy's activity had harmed anyone in any way was presented. Yes, viruses are bad; yes, he should be punished; but for a first offence, wouldn't probation and a fine be more appropriate? If he doesn't learn his lesson and offends again, OK, then throw the book at him.

  63. Too many spreads by Anonymous Coward · · Score: 0
    May be he is guilty for spreading it?

    No more goatsex references, please.

  64. Re:Justice? I don't think so! by aoeuid · · Score: 1

    Yes but Dimitry Sklyarov committed his crime under US law. The US has the highest incarceration rate in the world. The wristslapping in the last few days occured outside America, and hence, the sentancing is a little more level headed.

  65. Virii should be legal by SlugLord · · Score: 0

    ...that way we might get secure, commercially-available email clients.