Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Bagle blitz unleashed

Reply
Thread Tools

Bagle blitz unleashed

 
 
Imhotep
Guest
Posts: n/a
 
      09-24-2005
"Hackers have spammed out multiple new variants of the Bagle Trojan to
millions of email addresses this week. The attacks came in two waves on
Monday and Tuesday and forced many anti-virus firms to issue multiple
signature updates over a greatly compressed period.'

http://www.securityfocus.com/news/11325

Imhotep
 
Reply With Quote
 
 
 
 
Jim Watt
Guest
Posts: n/a
 
      09-24-2005
On Sat, 24 Sep 2005 01:14:45 -0400, Imhotep <>
wrote:

>"Hackers have spammed out multiple new variants of the Bagle Trojan to
>millions of email addresses this week. The attacks came in two waves on
>Monday and Tuesday and forced many anti-virus firms to issue multiple
>signature updates over a greatly compressed period.'
>
>http://www.securityfocus.com/news/11325


I believe you remove ALL executable attachments from email
rather than scanning them for malware.

--
Jim Watt
http://www.gibnet.com
 
Reply With Quote
 
 
 
 
Hairy One Kenobi
Guest
Posts: n/a
 
      09-24-2005

"Jim Watt" <_way> wrote in message
news:...
> On Sat, 24 Sep 2005 01:14:45 -0400, Imhotep <>
> wrote:
>
> >"Hackers have spammed out multiple new variants of the Bagle Trojan to
> >millions of email addresses this week. The attacks came in two waves on
> >Monday and Tuesday and forced many anti-virus firms to issue multiple
> >signature updates over a greatly compressed period.'
> >
> >http://www.securityfocus.com/news/11325

>
> I believe you remove ALL executable attachments from email
> rather than scanning them for malware.


If they're the one's I /think/ they are, then they're packaged as ZIPs.

I've been seeing a fairly constant stream (one or two a day). No peaks.

Couldn't find the original story at El Reg (they usually attribute), but I
did find something interesting:

http://www.theregister.co.uk/2005/09..._security_bug/

Fairly standard "arbitrary command" vuln.

--

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!


 
Reply With Quote
 
Art
Guest
Posts: n/a
 
      09-24-2005
On Sat, 24 Sep 2005 10:47:30 +0200, Jim Watt <_way>
wrote:

>On Sat, 24 Sep 2005 01:14:45 -0400, Imhotep <>
>wrote:
>
>>"Hackers have spammed out multiple new variants of the Bagle Trojan to
>>millions of email addresses this week. The attacks came in two waves on
>>Monday and Tuesday and forced many anti-virus firms to issue multiple
>>signature updates over a greatly compressed period.'
>>
>>http://www.securityfocus.com/news/11325

>
>I believe you remove ALL executable attachments from email
>rather than scanning them for malware.


The best advice to average users is to delete all unsolicted email
attackments. There are various ways of hiding actual file extensions.
Some malware comes as:

purtygurl.jpg .exe

for one example where spaces are used to hide the .exe extension.

Another trick is to use the scrap file extension .SHS which Windows
hides:

purtygurl.jpg.shs

appears in Windows as:

purtygurl.jpg

and the actual scrap file _ is_ executeable. The same can be done
with .SHB files.

Perhaps the most powerful piece of social engineering of late has
been the malware with a message seeming to come from your ISP
containing a attackment which you are encouraged to open. The
variations on this theme are amazingly real looking, and it's no
wonder average users will unzip and open and Run the attackment.

Art

http://home.epix.net/~artnpeg
 
Reply With Quote
 
Imhotep
Guest
Posts: n/a
 
      09-24-2005
Jim Watt wrote:

> On Sat, 24 Sep 2005 01:14:45 -0400, Imhotep <>
> wrote:
>
>>"Hackers have spammed out multiple new variants of the Bagle Trojan to
>>millions of email addresses this week. The attacks came in two waves on
>>Monday and Tuesday and forced many anti-virus firms to issue multiple
>>signature updates over a greatly compressed period.'
>>
>>http://www.securityfocus.com/news/11325

>
> I believe you remove ALL executable attachments from email
> rather than scanning them for malware.
>
> --
> Jim Watt
> http://www.gibnet.com


I do (in a corporate environment), it just makes sense...I guess it is
people at home that may not have that option....

Imhitep
 
Reply With Quote
 
Jim Watt
Guest
Posts: n/a
 
      09-24-2005
On Sat, 24 Sep 2005 13:15:30 GMT, "Hairy One Kenobi"
<abuse@[127.0.0.1]> wrote:

>
>"Jim Watt" <_way> wrote in message
>news:.. .
>> On Sat, 24 Sep 2005 01:14:45 -0400, Imhotep <>
>> wrote:
>>
>> >"Hackers have spammed out multiple new variants of the Bagle Trojan to
>> >millions of email addresses this week. The attacks came in two waves on
>> >Monday and Tuesday and forced many anti-virus firms to issue multiple
>> >signature updates over a greatly compressed period.'
>> >
>> >http://www.securityfocus.com/news/11325

>>
>> I believe you remove ALL executable attachments from email
>> rather than scanning them for malware.

>
>If they're the one's I /think/ they are, then they're packaged as ZIPs.


I filter them too and receive them by appointment only

Although zips were a godsend in the days of BBS's they are
past their best-by date today. Most of the files I want to receive
are already compressed anyway.
--
Jim Watt
http://www.gibnet.com
 
Reply With Quote
 
Jim Watt
Guest
Posts: n/a
 
      09-24-2005
On Sat, 24 Sep 2005 16:16:14 GMT, Art <> wrote:

>Perhaps the most powerful piece of social engineering of late has
>been the malware with a message seeming to come from your ISP
>containing a attackment which you are encouraged to open. The
>variations on this theme are amazingly real looking, and it's no
>wonder average users will unzip and open and Run the attackment.


Yeah I got one from 'the support team' at my domain.

I got a really neat message from an Ebay user with an address to
complain about anything suspicious, the complaint site of course
required one to sign in with a username and password ...

Not phishy of course
--
Jim Watt
http://www.gibnet.com
 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      09-24-2005
From: "Imhotep" <>

| "Hackers have spammed out multiple new variants of the Bagle Trojan to
| millions of email addresses this week. The attacks came in two waves on
| Monday and Tuesday and forced many anti-virus firms to issue multiple
| signature updates over a greatly compressed period.'
|
| http://www.securityfocus.com/news/11325
|
| Imhotep

I'll take by Bagle with cream cheese with a side of blintzes

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Imhotep
Guest
Posts: n/a
 
      09-25-2005
David H. Lipman wrote:

> From: "Imhotep" <>
>
> | "Hackers have spammed out multiple new variants of the Bagle Trojan to
> | millions of email addresses this week. The attacks came in two waves on
> | Monday and Tuesday and forced many anti-virus firms to issue multiple
> | signature updates over a greatly compressed period.'
> |
> | http://www.securityfocus.com/news/11325
> |
> | Imhotep
>
> I'll take by Bagle with cream cheese with a side of blintzes
>


ummmmm blintzes.....
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Glieder (aka Bagle, version eightysomething) NonDisputandum.com Computer Security 0 06-02-2005 06:15 PM
Accidentaly opened I-Bagle - and then opened virus vault ?? Morph Computer Information 2 02-01-2005 03:43 AM
Bagle Times Three Jay Calvert Computer Security 1 10-30-2004 02:31 PM
Win32.Bagle.AG Patrick Dunford NZ Computing 3 08-10-2004 02:42 AM
Bagle 0 Paula Computer Support 2 04-12-2004 04:33 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57