Hello John,

On Tue, 23 Mar 2004 20:14:08 -0500 GMT (24/03/2004, 08:14 +0700 GMT),
John wrote:

J> Just read over some of the worm info from
J> http://www.pcmag.com/article2/0,1759,1552856,00.asp about Bagel.

From that website: "the worm can automatically run and install itself
when a user opens an e-mail. " The website goes on to say that it
requires OL or OE.

What is further described with the IE vulnerability sounds like a MITM
attack. If the mentioned bank's site is secure (and I have no doubt it
is), the user will have to click on the "accept certificate" dialog.
If the IE vulnerability is that this dialog doesn't come up (I didn't
read the linked MS site), it just confirms my warning: don't use
internet banking. New hacking methods always come up, and since this
allows a malicious hacker access to money, there are enough that work
hard on it.

J> What interests me most is that there is mention that this worm will
J> harvest email addresses from TBB and ADB files..

What I found was this:

"What it does: This new Bagle worm propagates through a vulnerability
in Outlook that downloads the virus rather than passing it through an
attachment."

TB is not vulnerable to such kind of virus. If you do manage to get
infected through other means, you have more problems than just
encrypting your TBB or ADB files.

-- 

Cheers,
Thomas.

Moderator der deutschen The Bat! Beginner Liste.

File - What your secretary does to her nails when the computer is
doing all of the work.

Message reply created with The Bat! 2.04.7
under Chinese Windows 98 4.10 Build 2222 A 
using a Pentium P4 1.7 GHz, 256MB RAM




________________________________________________
Current version is 2.04.7 | 'Using TBUDL' information:
http://www.silverstones.com/thebat/TBUDLInfo.html

Reply via email to