Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Vicious Worm Infects Without Attachment
Enterprise Security Today ^ | 3/19/2004 | James Maguire

Posted on 04/03/2004 1:18:27 PM PST by Swordmaker

A handful of Bagle worm variants are attacking Windows users with an insidious new twist: They can infect computers without tricking them into opening a file attachment -- opening an e-mail is all it takes.

The passel of new worms sport a virtual alphabet soup of labels: "Bagle.q," "Bagle.r," "Bagle.s" and "Bagle.t." Some security firms have dubbed the new variants "beagle." They are mutations of the original Bagle worm first discovered in January.

Bagle exploits a flaw in Outlook, revealed in October of 2003, that allows a hacker to upload and execute a file on a user's PC without that user opening the file. Microsoft has issued a patch for the flaw in October, but users who have not updated their systems with this patch are at risk.

"This steps up the game," Sophos security analyst Chris Belthoff told NewsFactor. "The education part of protecting against viruses -- 'Don't click open attachments' -- got thrown out the window with these variants."

Two-Step Process

The e-mails carrying the new Bagle variants do not have attachments. Experts speculate that the virus writers developed this non-attachment technique to bypass a common firewall technique called "gateway scanning," which intercepts any e-mail with an attachment.

When a user open an e-mail carrying one of these new Bagle variants, the e-mail "goes back out to the Internet and tries to find a certain server that has the Bagle executable on it and bring it down through HTTP," Belthoff said.

This is a two-step process, he explained. First, the carrier e-mail connects though Port 81 to the host server, and opens up a maliciously coded HTML file. Then, a visual basic script (VBS) file is sent to the victim's machine, which connects to the same server and downloads the virus via HTTP.

"That shouldn't be allowed to happen," Belthoff said. "Opening an e-mail doesn't give some remote machine the authority to drop down a VBS script onto your system. The vulnerability allows that to happen."

If a user's machine is properly patched, Bagle poses no threat, he said.

One-Upmanship Game

There have been so many variations on the original Bagle worm that some security experts speculate that virus writers are playing a game of one-upmanship as they create and spread new mutations.

"There have actually been messages between the virus writers embedded within the viruses," Neel Mehta, Internet Security Systems research engineer, told NewsFactor. "The authors of Netsky, Bagle and MyDoom are really at each other's throats trying to create more viruses and outdo each other.

"It's having a horrible impact on the end-users who are the target of these attacks."

Disabling Firewalls

Like earlier versions of Bagle, the new variations disable many firewall and antivirus applications, a technique that has become common among virus writers. They also spread like the original Bagle, by resending themselves to all addresses found on a user's hard drive, disguising the return address of the e-mail to conceal the identity of the infected machine.

The mass-mailed worm uses a broad array of typical spam-virus subject lines, such as "Fax message received" and "account notify."

P2P Networks

The Bagle virus is coded to survive and propagate rather than delete files, as some worms do. "They are not generally destructive, but they put a huge load on e-mail servers, they cause outages, and there's a cost associated with un-infection," Mehta said.

Bagle infects every .exe file on a victim's system, meaning it lurks stubbornly even on apparently cleaned systems. The worms will keep hundreds of software programs from running, and they deactivate configuration applications, such as regedit and msconfig, that are used to delete viruses.

Bagle places itself -- with a variety of invented file names -- in folders that are commonly used for file-swapping. So, a large P2P network like Kazaa becomes an effective tool for mass propagation.


TOPICS: Announcements; Crime/Corruption; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: email; lowqualitycrap; microsoft; security; viruses; windows; worms
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 121-128 next last
Another reason to use a Mac!
1 posted on 04/03/2004 1:18:28 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker
I thought this was going to be about Bill Clinton.
2 posted on 04/03/2004 1:19:41 PM PST by IncPen
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000; antiRepublicrat; LasVegasMac; Action-America; eno_; N3WBI3; zeugma; TechJunkYard; ...
"This steps up the game," says Sophos security analyst Chris Belthoff. "The education part of protecting against viruses -- 'Don't click open attachments' -- got thrown out the window with these variants."

WINDOWS users be afraid, be very afraid... and patch your systems... AGAIN!

3 posted on 04/03/2004 1:19:51 PM PST by Swordmaker (This tagline shut down for renovations and repairs. Re-open June of 2001.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
For those looking for a Windows alternative to Outlook/OE, try Thunderbird. I'm finding it quite a nice package.
4 posted on 04/03/2004 1:20:12 PM PST by bcoffey (There are 10 types of people: those who understand binary and those who don't.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

5 posted on 04/03/2004 1:20:28 PM PST by Support Free Republic (I'd rather be sleeping. Let's get this over with so I can go back to sleep!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Another reason to use a Mac!

And terrorism is another reason to be a Spaniard.

6 posted on 04/03/2004 1:23:57 PM PST by Agnes Heep (Solus cum sola non cogitabuntur orare pater noster)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Microsoft has issued a patch for the flaw in October, but users who have not updated their systems with this patch are at risk.

Well, duh. Activate automatic updates. Voila - no problem. Old news.

7 posted on 04/03/2004 1:24:17 PM PST by Leroy S. Mort
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Uh-oh. Here we go again.
8 posted on 04/03/2004 1:25:37 PM PST by 7.62 x 51mm (© ®)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
opening an e-mail is all it takes

This is in error... being dumb enough to use Outlook for your email is all it takes.

9 posted on 04/03/2004 1:26:43 PM PST by thoughtomator (Voting Bush because there is no reasonable alternative)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Another reason to use a Mac!

Another reason to use Linux!

10 posted on 04/03/2004 1:29:09 PM PST by P8riot (A friend will help you move. A good friend will help you move a body.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: thoughtomator
I agree. I've been using pegasus mail for over 5 years. Outlook was the first thing I disabled on my computers.
11 posted on 04/03/2004 1:37:52 PM PST by Liberty Valance (I'll tell you what I like about Texas...everything between the Red River and the Rio Grande)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Liberty Valance
NotesMail here... never had a virus, never will.
12 posted on 04/03/2004 1:39:13 PM PST by thoughtomator (Voting Bush because there is no reasonable alternative)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker
Another reason to use a Mac!

Careful what you ask for, if you have your way then there would be enough Mac users for malware authors to actually bother to write a virus for it.

13 posted on 04/03/2004 2:29:38 PM PST by battousai (Islamic terrorists are like cancer... can you negotiate with Cancer?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bcoffey
Thanks for the tip, I'll give it a look. I personally use Poco Mail. Anything to avoid the stupid gaping security holes of Outlook...
14 posted on 04/03/2004 3:09:59 PM PST by egarvue (Martin Sheen is not my president...)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

"These worms are getting worse all the time."
15 posted on 04/03/2004 3:10:20 PM PST by NewRomeTacitus
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Bunk, Mac isn't superior, just used so much less that nobody bothers to create a bug that would affect only 1% of the market.
16 posted on 04/03/2004 3:13:22 PM PST by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Easy fix for me, I only use websites for my Email, like the way some use Yahoo.
17 posted on 04/03/2004 3:14:26 PM PST by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: P8riot
No, just lucky your part of the market is so "tiny" that nobody wants to create bugs for it.
18 posted on 04/03/2004 3:15:45 PM PST by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: NewRomeTacitus
Don't you work the border with that?
19 posted on 04/03/2004 3:16:44 PM PST by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Leroy S. Mort
Activate automatic updates. Voila - no problem. Old news.

Not an option for many organizations. One I worked at covering several hundred thousand systems always did regression testing of any patch in-house, and users were to update by downloading fixes from our web site after they were found not to mess with any apps, stability or open their own security holes (it's happened). This constant Microsoft patching kept several security experts employed full-time.

20 posted on 04/03/2004 3:46:31 PM PST by antiRepublicrat
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 121-128 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson