Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Bagle turns to anti-spam trick

Mar 15, 2004 1:45PM PST

Three new Bagle variants, N, O, and P, use an anti-spam trick to try to sneak past antivirus filters. Bagle first started sneaking past antivirus filters by coming as an encrypted .zip file attachment, with the password to open it given in the text of the e-mail, tricking unwary users into opening the attachment. However, antivirus companies quickly modified their products to grab passwords form the text to open and scan .zip files. The new variants produce a graphic of the password to prevent the scanners from reading it; the same trick is often used by websites to make sure viewers are human rather than a computer trying to harvest e-mail addresses. Graham Cluley of Sophos says his company has already updated their scanner to grab passwords from the graphic. The new variants are also using .rar files, a compression scheme similar to .zip.

http://news.zdnet.co.uk/0,39020330,39149030,00.htm

Discussion is locked