Slashdot Mirror


Profile of the Mind of a Virus Writer

zdburke writes "Clive Thompson, writing for the NY Times, has profiled several young computer virus writers around the world. A young Austrian wrote a Batch Trojan Generator which has simple options for constructing your next virus: fomat drive C? Overwrite every file? It's very well written by an author who clearly knows his stuff."

39 of 310 comments (clear)

  1. Well, if the source of many viruses is correct... by Anonymous Coward · · Score: 5, Funny

    ...they're pretty proficient in VB.

  2. In other news... by La_Boca · · Score: 5, Funny

    ...US Slashdot editors get tricked once again by the "news media" to post another dupe.

  3. am I the only one???? by snatchitup · · Score: 3, Insightful

    Or do the pictures of these guys remind you of the Calvin Cline ads awhile back that bordered on kiddie porn? These kids look like they are wearing makeup and exude a bit of homo-erotic teasing.

    It just gave me the creeps, knowing that this is an article for nerds.

    1. Re:am I the only one???? by Anonymous Coward · · Score: 3, Interesting

      I'm sorry these pictures are arousing previously unearthed feelings for you. I can sympathize with your feelings of uneasiness as the facade of homophobia slowly melts away to reveal your true inner self.

      On a more serious note, get a grip. If the sight of some bare shoulders on a guy is having you squirm like a pre-pubescent girl, you've got some serious growing up to do.

      As for whatever brain donors modded his whining "Insightful," quit trying to rival the goatsecx guy and pull your heads out of own asses already.

  4. Some you win, some you lose by stevey · · Score: 5, Informative

    On the down side this is a duplicate article, on the plus side this version has a link to the Google partner version of the article. (So no login required).

    I guess this means that I can't gain karma by posting a mirror. Do you think I'm in with a chance of anything else? ;)

  5. Hmmm. by DarkHelmet · · Score: 5, Insightful
    You know, maybe I don't get it... Maybe it's just me.

    But it says right there... "Please write the online editor at daddypants@slashdot.org for any corrections.".

    I decide to write that it was a dupe. Sure enough, the thing gets posted anyway.

    I mean, that's partly what subscribers are for. And that's also why subscribers can't do comments early. Right?

    It's silly. Not only should the editors actually read slashdot, they should more importantly look at email from subscribers saying "It's a dupe!" before posting the thing.

    But maybe it's just me thinking in a perfect world. Forget it.

    --
    /^[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,4}$/i
    1. Re:Hmmm. by __past__ · · Score: 4, Funny
      I mean, that's partly what subscribers are for. And that's also why subscribers can't do comments early. Right?
      Do I understand correctly - you actually pay money for being allowed to do the job of the (paid, but incompetent) editors, so that I (freeloader) don't have to read dupes?
  6. Automatic virus creation is nothing new. by juuri · · Score: 4, Informative

    This has been around for something like 12 years, IIRC, Nowhere Man of that funny group of happy guys at [NuKE] wrote the VCL (Virus Creation Lab) in 92 (maybe 93?). Basically it was a text based GUI app with windows and drop downs that let you design a virus and produced a working one ready for distribution.

    Today's viruses are absolutely pathetic compared to some of the older stuff.

    --
    --- I do not moderate.
    1. Re:Automatic virus creation is nothing new. by GigsVT · · Score: 5, Funny

      Heh, do you remember the "Help on Help on Help" (I think it was) in VCL?

      Basically, "Help on Help" told you how to navigate the Help system. "Help on Help on Help", was a very funny rant, detailing how to buy a gun and kill yourself. :)

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    2. Re:Automatic virus creation is nothing new. by fungus · · Score: 3, Funny

      And the password for VCL's installation was "ChibaCity"...

      Wow how can I remember something like this?

  7. Re:Stiffer punishment by Trurl's+Machine · · Score: 3, Insightful

    Why it's so easy for us to accept the typical cracker/hacker defense ("I am just exposing vulnerabilities in this computer system or data encryption scheme") and reject similar defense of a virus writer ("I am just teaching computer users to handle binary attachments with care")?

  8. Since I missed it the first time around... by andih8u · · Score: 5, Insightful

    Downstairs, his mother is cleaning up after dinner. She isn't thrilled these days, either. But what bothers her isn't Mario's poster. It's his hobby. When Mario is bored -- and out here in the countryside, surrounded by soaring snowcapped mountains and little else, he's bored a lot -- he likes to sit at his laptop and create computer viruses and worms.

    Maybe this is just crazy talk, but couldn't this woman just take his computer away from him? She knows that he's upstairs doing illegal stuff...he's 16, take away his laptop. "Oh, well little Billy's just upstairs making pipe-bombs...I'll leave him alone."

    Parents are there to be...parents.

    --


    slashdot, news for crazed liberal socialist zealots
    1. Re:Since I missed it the first time around... by mxf8bv · · Score: 5, Insightful

      Well, he claims it is for educational purposes and even published it on his website. So probably it's not illegal what he's doing - as long as he doesn't (admit to) realease his creations into the wild.

    2. Re:Since I missed it the first time around... by Anonymous Coward · · Score: 5, Insightful

      I think we should start looking at intent. The article said it: These people publish their works on the Internet knowing, even wanting, their viruses to be used by script kiddies. Just read what some of the people that were interviewed said. Things like "When my first virus was issued as an alert, I was thrilled." That says illegal to me, or at least should.

  9. Deja-vu by hyperherod · · Score: 5, Funny

    I think I've been here before... I've been told this usually happens because of a glitch in The Slashdot...

  10. script kiddies by tuxette · · Score: 4, Insightful
    The people who release the viruses are often anonymous mischief-makers, or ''script kiddies.'' That's a derisive term for aspiring young hackers,

    Aspiring young hackers?! Aspiring young hackers don't cut and paste other people's code.

    --
    People say I'm crazy, I got diamonds on the soles of my shoes...
  11. Re:Stiffer punishment by 0123456 · · Score: 5, Insightful

    "Throw these antisocial delinquents in the slammer for 10 years for each offense."

    I believe the average sentence for murder in America is about eight years. Are you really suggesting that writing a virus is a more serious crime than murder?

    (Ok, I'd agree, if that virus caused infrastructure damage that killed people... but then they should be jailed for manslaughter, not virus writing)

  12. Warning: E-mail viruses detected by SiChemist · · Score: 5, Funny

    Our virus detector has just been triggered by a message you sent:-

    To: editor@slashdot.org
    Subject: Profile of the Mind of a Virus Writer
    Date: Mon Feb 9 6:00:55 2004

    Any infected parts of the message have not been delivered.This message is simply to warn you that your computer system may have a virus present and should be checked. The virus detector said this about the message:

    Report: message.zip contains Worm.MyDupe.Slashdot

  13. Cool by Dark+Lord+Seth · · Score: 5, Insightful

    It has pictures, name and locations.

    Now the sysadmins have someone to beat up and the legal department can take some potshots at them for paying damages caused by virusses.

  14. Timothy, do you ever check the fucking stories? by theolein · · Score: 4, Insightful

    This one is a dupe, yet again. Christ, man, use the fucking search feature or hand over the moderator status to someone who will. And yes, you are definitely the worst one when it comes to duplicating stories.

  15. Sadly, this NY Times story got more readers... by SpaceRook · · Score: 4, Insightful

    This article is about as ill-informed as that BBC article that was posted last week. From the article:

    MyDoom's ultimate target was an obscure software company named SCO. Champions of the open Net have portrayed SCO as the Antichrist since it sued to establish part-ownership of a popular and free computer operating system called Linux. Linux has become an icon of the so-called open-source movement, which is seeking to limit the influence of companies like SCO and the industry giant, Microsoft, which closely guard their software.

  16. at the same time... by tuxette · · Score: 4, Interesting
    ...better IT education from an early age is needed. The author of the article writes "[s]cript kiddies often have only a dim idea of how the code works and little concern for how a digital plague can rage out of control." It looks like we need to do a better job (than the seemingly non-existant now) in teaching children why they shouldn't cut and paste "strange code" and what the consequences are of doing such a thing. It is not enough to say "don't do it."

    --
    People say I'm crazy, I got diamonds on the soles of my shoes...
    1. Re:at the same time... by nomadic · · Score: 5, Insightful

      That doesn't really fall within IT training though, more like civics or ethics. These kids know exactly what they're doing, and they're doing it on purpose.

  17. Oh, the irony by rjshields · · Score: 5, Funny

    "Stephen Mathieson, Detroit. The 16-year-old virus writer is dismissive of hackers who release other people's viruses: "The kids just cut and paste.""

    So, we have a 16 year old virus writer accusing other hackers of being childish. Doesn't that seem just a tad ironic?

    --
    In this world nothing is certain but death, taxes and flawed car analogies.
  18. Challenge, schmallenge by W1K-Galoot · · Score: 3, Interesting

    Michelangelo was a master. A spray-can toting kid is just a vandal. These aren't "masters" either, no matter how much they label themselves as such. Want to show off your elite skills, kids? Want to show how much better than Microsoft you are? Write a self-replicating program that patches holes instead of exploiting them.
    Nope. They're vandals posing as artists.

    --
    Been using sigs for 20 years. Nothing funny left to say.
    1. Re:Challenge, schmallenge by globalar · · Score: 3, Insightful

      It's a sign of immaturity that you have to prove yourself and exercise your ability in every small way. For example, locksmiths don't go around opening people's doors and leaving strange notes just because they can. They have a job where these abilities are applied for a wage. Their capabilities are productive and non-intrusive.

      Some hackers find problems with popular software, others create security schemes, some experiment with protocols, some reverse engineer drivers, etc. Some hackers are productive and non-intrusive.

  19. Re:Stiffer punishment by kfg · · Score: 5, Insightful

    Tha Riot Be Tha Rhyme of The Unheard -jediman1138-

    As it happens a very appropriate sig to the matter at hand.

    I'd point out, however, that the rioter is often expressing a generalized anger, often against the innocent, indeed often against the very supporters of his own cause. It reduces the cause to an act of thuggery in way no different than any other act of violence.

    A thoughtful and directly relevant resistence is more fruitful, just and likely to draw further support.

    John Brown's taking of the Harper's Ferry Armory is still the stuff of legend. Tim McVeigh's bombing of the Murrah Federal Building is, and shall remain, an act of infamy.

    Some virus writers are angry young men with legitimate cause for their anger.

    Wiping Grandma's C drive as part of an act of generalized vandalism is a poor way to express that anger and does nothing to actually relieve it's cause. It does not even leave one with an idea what the virus writer percieves that cause as being.

    John Brown is considered a terrorist by a good many to this day, but at least we know what the hell he was mad as heaven about.

    If one has a distaste, or even an anger, about certain aspects of society or orginizations within that society, well and good. Oppose them. Oppose them with your words, your actions and even your very life if need be, but please, leave my mom and my grandmom out if it unless they are directly involved.

    As to the issue of punishing minors as adults, I will accept this only at such time as the legally defined as adults. To deny a person of youth the franchise as a full citizen because he is too young, ignorant and immature, but hold him responsible, without the proper rights and benfits of full citizenship and representation, because he "is old enough to know the difference between right and wrong" is hypocritical, unjust and undemocratic.

    This issue came to a head in the 60s when teenagers were being drafted for the Vietnam war, and yet those same teenagers were denied the right to vote on representation or other issues which had obvious life or death consequences to them.

    That is why the age of majority was lowered from 21 to 18.

    Rights and responsibilites should always, always, always march hand in hand.

    KFG

  20. Don't believe a word of it by heironymouscoward · · Score: 3, Interesting

    Call me cynical but I think this story is a well-constructed lie.

    First, the accurate but uncheckable details: name of some guy in Austria, his 15-year old girlfriend.

    Secondly, as has been remarked, the photos. They are just too well shot, and I can't for a second believe that a virus author would sit still while the makeup girls did their thing, lighting got the shadows right... no frigging way!

    Thirdly, the technical details are obviously wrong. Formatting hard drives? Deleting files? That is so 1980's. Today's virus writers are obsessed with the social interface: how to confuse people into clicking the attachment.

    Forthly, the timing. A long, detailed investigation into youthful virus writers just as the worst ever virus hits the Internet, with no mention of mafia connections, of zombie spam engines, of "sorry, andy, but this was just my job",...? WTF?

    Conclusion: it's a set-up. These young dudes don't exist as described, the shots are of actors, and the story was invented behind a desk. Someone wants to create a convincing enemy for new legislation which will paint uncontrolled hacker youthdom as the enemy of all that is right and proper. Long prison sentences for simply creating the wrong kind of software ("because it could be released and do harm"). Rapid implementation across the globe ("cause these guys are in, like, Austra!").

    Now, allow me to get really cynical and ask this question: why is no-one bothering with profiles of the organized criminals behind most of the damage done to people's computers? Could it be because misdirecting the blame at youth hackerdom means the problem will not be solved, and so the hand of oppressive government can become stronger and stronger...

    Of course, I could be wrong, and really viruses like mydoom could just be the work of guys like this.

    --
    Ceci n'est pas une signature
  21. Re:Stiffer punishment by nomadic · · Score: 3, Insightful

    Who's us? I find both of those excuses unconvincing.

  22. Go ahead a flame away, but... by Ghengis · · Score: 3, Insightful

    Come on! Get it together /.! You guys had this article on Friday! Don't you read your own site?

    --

    "The best laid plans of mice and men gang oft agley..." - ROBERT BURNS

  23. Men are pigs..and virus writers! by cabazorro · · Score: 3, Insightful

    On the creator of the Sobig.F virus...
    ''The F.B.I. is out for the Sobig guy with both
    claws, and they want to make an example
    of him,'' David Perry.

    Women don't write viruses?
    Women don't read slashdot?
    I feel so pigeonholed!!

    --
    - these are not the droids you are looking for -
  24. When reading articles like this... by vasqzr · · Score: 4, Insightful

    Just sit back and laugh. Journalists can't cover this stuff. It's a joke.

    Now, think about how off-center computer-related articles are. Anything that deals with technology.

    Have you ever had first-hand experience with a story your local paper covered? And while reading the story, you think to yourself, "Where the hell did they get their (mis)information??"

    Apply that to EVERY story in the news. Scary, isn't it?

  25. How can you criticize Microsoft? by Futurepower(R) · · Score: 4, Insightful


    How can you criticize Microsoft for this? There have been only 60 extremely serious vulnerabilities in Internet Explorer in two years.

    The real source of the problem is..., well yes, Microsoft. One would think that Microsoft would be better at coding than someone who taught himself programming and writes programs on the weekends.

  26. VB? WTF?! by fudgefactor7 · · Score: 4, Interesting

    Visual Basic is a computer language popular among malware authors for its simplicity; Philet0ast3r has used it to create several of the two dozen viruses he's written.

    Jeez...VB? Real virus hax0rz work in assembly, it's smaller, neater, and faster. These guys are a bunch of script kiddie punks. No wonder they were hip to being interviewed, they had no talent and wanted a name for themselves.

    Perhaps we should kill them.

  27. Re:Stiffer punishment by jwthompson2 · · Score: 3, Insightful

    I think that what virus writers do is to some degree helpful and harmless, the idiots that distribute the viruses are the people that should be drawn-and-quartered. Writing something is not the same as doing something with it. These 'programmers' have every right to produce and publish their programs. But the fact that these programs are destructive is why it's illegal to distribute/release/run them. I have no problem with these folks writing these things and publishing them, it allows me to see what they are up to and at least keep up with them when I can't get ahead of them security wise.

    The article paints an interesting contrast between the writers and the 'script kiddies' we all loathe who are the real evil dolts behind most virus and worm activity.

    Of course I use a Mac desktop and GNU/Linux servers so until these guys start using something other than VB I am not too terribly worried about them trying to exploit any hidden flaws in my systems, but it is helpful to know what they are up to, same reason I subscribe to 2600.

    --
    Even if I knew that tomorrow the world would go to pieces, I would still plant my apple tree. -Martin Luther
  28. Re:Stiffer punishment by IWantMoreSpamPlease · · Score: 4, Interesting

    What's worse is, that under certain circumstances, premeditated murder carries a *maximum* penalty of 2 years in jail (basically for environmental crimes. I studied several cases in detail)

    Food for thought.

    --
    So rise up, all ye lost ones, as one, we'll claw the clouds.
  29. Stop Whining! by sdcharle · · Score: 3, Funny

    As a subscriber, you got to see the dupe before the rest of us!

  30. Re:Stiffer punishment by Hatta · · Score: 3, Interesting

    There ought not be a draft at all. If the cause is so unpopular you can't get a volunteer militia, you really shouldn't be fighting it at all. Besides, conscripts make terrible warriors.

    --
    Give me Classic Slashdot or give me death!
  31. MOD down :: Improve your reading by ph43thon · · Score: 3, Insightful


    First, that sort of thing is in numerous articles.. so it's a useless starting point.

    Second, the photos aren't very good. It's easier to tell if you look at the pictures in the NYTimes magazine. One's blurry and grainy, another is heavily dodged (darkened) everywhere except where that "Benny" guy is, and the detroit kid does seem to have on makeup, but the picture is just slow shutter with soft focus and a light flare.

    Third, when I read the article.. it talked about how formatting hard drives was old and boring. The writers were interested in odd, creative payloads like flashing images or stupid messages. The guy who wrote the virus generator added the "format harddrive" option to his program.. but that's the main mention of modern hdd formatting. To quote the article: "the prevalence of hard-drive-destroying viruses has steadily declined to almost zero."

    Fourth, it is explicitly stated in the article that the main fear is from for-profit or organized virus writing (spammers, mafia, terrorists). It goes on to mention how Sobig is being tested and, so far, has been released six separate times with a built in expiration. They can't profile organized criminals because they don't want to be profiled or found.

    anyway, so what's the deal? why troll get food from mods?

    p