eWeek Security Watch
Advertisement
Advertisement
February 27, 2008 8:34 PM

So, Who Wrote the Slammer Worm?



david_litchfield.jpgExactly five years after the Slammer worm wreaked havoc on the Internet, database security guru David Litchfield has come up with an idea that might help pinpoint the author of the worm code.

Litchfield (right), who was credited with discovering the MS02-039 vulnerability that was exploited by Slammer, says there are already clues in the worm code that suggests it may have been written by two people.

"There are two distinctive styles at play," Litchfield wrote on his blog, pointing to examples in the worm code where both styles (one efficient, one not-so efficient) were used.

Now, Litchfield believes that someone with the time and energy might be able to look around the Internet for signs of the culprit.

Litchfield writes:

All of this leads me to think that there may be some mileage in attempting to recognize a "fist." (For those that don't know, during World War II radio snoopers listening to German comms could recognize a particular radio operator's "fist"--the way the operator actually sent the message, like pauses between dots and dashes.)

If an exploit (worm) is released and the author is not silly enough to put a signature in it then their coding style may give them away. If we have known exploits attributable to a specific person and the coding styles match then this may point to them being the author.

Who wants to start rummaging through Milw0rm.com?

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12824

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise