From The Register, http://www.theregister.co.uk/content/56/35625.html

Bagle-B clobbers weary Net users
By John Leyden
Posted: 17/02/2004 at 17:26 GMT
Stay up to date wherever you are, with The Register Mobile


Long-suffering Net users are finding their in-boxes clobbered again today with the appearance of yet another mass mailing worm.


Mercifully, Bagle-B is much less prolific than the recent MyDoom worm.

Bagle-B (AKA Tanx-A) normally arrives in emails with a subject line of "ID" followed by random characters and the message text: "Yours ID". Its payload includes a backdoor component which surrenders control over the infected machine to hackers. This comes in an attached .exe file with a randomly-generated filename.

Run this attachment on a Windows machine and your PC gets the pox. Mac or Linux boxes are immune.

The worm harvests email addresses from infected PCs and forwards itself to other prospective victims using a spoofed "From:" field.

Most AV vendors rate Bagle-B as a medium-level risk.

Standard precautions apply to defending against the bug: update AV signature files and (if you're an admin) consider introducing controls to block executables at the gateway. If you're a regular user, be careful of those unsolicited attachments, even from people you know. �



--------------------------------------------------
Chris Byrne
New Media Scotland
P.O. Box 23434, Edinburgh EH7 5SZ
Tel. +44 131 477 3774
[EMAIL PROTECTED]
http://www.mediascot.org
--------------------------------------------------

-------------------------------------------------
a m b i t : networking media arts in scotland
post: [EMAIL PROTECTED]
archive: http://www.mediascot.org/ambit
info: send email to [EMAIL PROTECTED]
and write "info ambit" in the message body
-------------------------------------------------

Reply via email to