Feeds

bet365 sends Avril Lavigne worm to punters

Bad tip

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Online betting firm bet365 has apologised after sending out a copy of the Avril Lavigne worm to punters on its mailing list last night.

The embarrassing security breach occurred by accident during a process to decommission a Linux box formerly used by the company to run its mailing list.

In normal operation the box prevented external SMTP (mail) connections, according to techies at bet365's Stoke-on-Trent offices. However when this box was rebooted, a mistake in firewall rules meant external mail was let in.

Some external mail turned out to be copies of the Avril Lavigne worm (aka Avril, Naith or Lirva - AV vendors can't agree a name), sent to the mail server by subscribers to the list already infected with the bug. Because of the now, exposed insecure configuration of the mail server these infected emails subsequently propagated on the list.

Avril is pretty much your bog-standard Windows worm. It spreads mainly as an infectious attachment within emails and takes advantage of a year-old exploit in Outlook which permits its execution without a user double clicking on an infected attachment. It can also spread by IRC, ICQ, KaZaA, and open network shares

The worm tries to disable AV and security software and also attempts to email cached Windows dial-up networking passwords to its as-yet unknown creator.

Managed services firm MessageLabs reports capturing 11,165 copies of the virus so far, since first detecting it on Monday (January 6).

bet365 has an active customer base of 10,000 people. Figures for the number of people on the list, much less the numbers who received the Avril worm last night, are unclear. Techies prevented wider spread of the bug by pulling the plug on the insecure mail server before the mailout was completed.

The mail server has being taken completely offline and bet365 is going ahead with its plans to outsource its mailing lists.

"The irony is that it was the process of decommissioning that caused the problem," a systems admin for bet365 told us.

Although some people have complained to bet365 about receiving the virus, the company tells us no one has yet reported becoming infected as a result of its inadvertent viral mail-out.

bet365 apologises for ay inconvenience caused by the incident, which was confined to a problem with its mailing list.

The online bookies runs customer accounts through a completely separate system (running a different OS). These systems were untouched by the mailing list virus problem and bet365's confidential customer account records remain secure, the company assures us. ®

Related Stories

The return of the celebrity virus Avril Lavigne tribute worms up the charts
Kaspersky mailing list hijacked!
BBC in ironic virus infection

External Links

Write up of the Avril Lavigne worm by Symantec and Sophos

Beginner's guide to SSL certificates

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.