Slashdot Mirror


Sober Code Cracked

An anonymous reader writes "The algorithm used by the Sober worm to 'communicate' with its author has been cracked. According to F-Secure, it can now calculate the exact URLs the worm would check on a particular day. Mikko Hyppönen, chief research officer at F-Secure, explained that the virus author has not used a constant URL because authorities would easily be able to block it. From the article: "Sober has been using an algorithm to create pseudorandom URLs which will change based on dates. Ninety nine percent of the URLs simply don't exist...however, the virus author can precalculate the URL for any date, and when he wants to run something on all the infected machines, he just registers the right URL, uploads his program and BANG! It's run globally on hundreds of thousands of machines," Hyppönen said. Sober is expected to launch itself again on January 5, 2006."

1 of 303 comments (clear)

  1. Re:Hard to admit, but that is quite clever by Dare+nMc · · Score: 0, Offtopic

    > "why do talented people waste their abilities on viruses?"

      "why do talented people waste their abilities on posting to slashdot?"

    Money?
    Acclaim (within a small community)?
    Politics?

    I would guess money. Spam pays very well, and a lot of companies have had monetary ulterior motives, as always, follow the money.