
More worm chaos in your inbox...
Published: 18 March 2004 18:00 GMT
The return of the Bagle worm is exploiting an old Outlook flaw to spread even more quickly.
Users no longer have to click on an attachment to spread the Bagle virus because the latest variants are exploiting an old flaw in Microsoft Outlook that allows the worm to spread even more quickly.
Until the appearance of Bagle variants Q, R and S, users had to click on an emailed attachment to be infected by the worm. However, these attachments were easily spotted by antivirus programs and eliminated. To fool antivirus software, the next batch of Bagles was sent with the infected attachment hidden inside an encrypted Zip file, with the password to open the file contained in the email's text. Antivirus companies dealt with this change within a few days, so in the next variant the password appeared in a small graphic file, making it more difficult to scan.
The latest Bagle incarnation has done away with the attachment altogether and spreads when a vulnerable user opens the email using an unpatched version of Microsoft Outlook. If their Outlook preview pane is open, the victim's machine will be compromised automatically. Because of this change in tactics, experts fear the worm could spread very quickly.
Sophos's senior technology consultant, Graham Cluley, said: "This is a really sneaky, cunning trick. It's exploiting a five- or six-month-old Outlook security vulnerability so that just previewing an email - not the attachment - in an unpatched copy of Outlook will result in the virus being dragged from an infected machine to your machine. This has the potential to spread very quickly because so many people, particularly home users, have not applied the patches."
Mikko Hyppönen, director of antivirus research at F-Secure, said the latest variant uses a list of about 600 IP addresses, which all seem to be home computers connected to an ADSL service that have been infected by previous versions of Bagle. These "zombie" machines have been updated and are now used to send copies of the new worm to any computer on which the victim uses a vulnerable copy of Outlook to view an infected email message.
Outlook uses elements of Internet Explorer to render the HTML for its preview pane, so to avoid the new Bagle worms, users should apply a patch for Internet Explorer that Microsoft released in October 2003.
Munir Kotadia writes for ZDNet UK
Sophos's senior technology consultant, Graham Clul...
Anonymous
WHY CAN'T PEOPLE PUT THEIR KNOWLEDGE TO GOOD CAUSE...
Anonymous
Pity there's no link to the patch - otherwise this...
Anonymous
I agree, good service shame about the missing patc...
Anonymous
could you advise me how to find the patch to put i...
Anonymous
XEN, Vmware Virtualization Management of PF Sense Firewalls with Failover Setups Clustered File Systems (GFS,LVM) Puppet, CF Engine System Management ...
I have an urgent requirement for an IT Helpdesk/Support Technician with excellent skills in Windows Active Directory, SQL Server 2005 databases, ...
Windows Vista Desktop Desktop Application experience from Microsoft Office products and Outlook, Printer/Sender issues (HP JetAdmin), Internet ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business