Search OutlookPower's 9,596 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
EMAIL SECURITY
Another month, another virus
By Diane Poremsky

Another month, another virus. This time it's the fast moving MyDoom (a.k.a. MiMail.R) that's driving everyone bonkers. You'd think by now people would learn, and for the most part, users are better at recognizing an infected message on their own. Many antivirus programs and firewalls automatically filter out messages containing *.EXE, *.PIF, *.SCR, and others, but allow the *.ZIP extension to pass. Unfortunately, enough people opened the ZIP and executed the contents before the antivirus filters were updated to create a flood of viruses and bogus virus warnings for the rest of us.

"What can administrators do to stop the lunacy?"

My pet peeve today is more with antivirus installations that have notifications enabled than the users who open the attachments without thinking. MyDoom collects addresses from any number of sources: text files, Outlook Express's mail store (*.DBX), the Windows Address book (*.WAB), HTML files, and others. If that doesn't provide enough addresses, it makes them up, using common first names and domains it finds in the files it scans. So, we have a virus sending messages to and/or from bogus addresses and antivirus programs blocking delivery, then creating more load on already swamped servers by sending notification to a falsified address that they sent an infected message, creating even more NDRs (Non-Delivery Receipts).

What can administrators do to stop the lunacy? They can begin by turning off the virus notifications to Internet addresses. These notifications create more useless traffic, often exceeding the bandwidth caused by the actual virus because of all the NDRs generated, and often needlessly scaring users into thinking they are infected when they aren't.

One administrator had this to say:

I spent more time today assuring clients that they haven't got the virus because of these types of NDR. The worse one had this as part of their text:
'This notice is sent as a courtesy so that you have the option of contacting your user and helping them get rid of the virus. This message was sent by Declude Virus. If your mail server had better virus protection, it would have caused less work for our server and could have prevented one of your users from getting a virus.'
I told my client that if the NDR sender had a better administrator 90% of their problems would disappear.

To learn more about how MyDoom works, see http://www.viruslist.com/eng/viruslist.html?id=841769.

This is also a good time for network administrators to review and update the policy on which extensions are blocked and find a new way to transfer files. Email is a convenient way for users to transfer files, but network security is more important.


1  ·  2  ·  Next »
Other articles you might like
Home > Online Safety > Virus protection (7 articles)
   Readers clock in on Microsoft v. Symantec
   The great Windows Vista antivirus war
   How the SoBig.F virus works
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
The strange case of Outlook losing notes and requiring passwords
Why I'm choosing to stick with Outlook 2007
Three ways to avoid email distraction and take back control of your time
Twenty ways to use email to commit career suicide
The two most motivational words in the English language
Diagnosing corrupted email headers
Email offenders
OutlookPower News Center
New Filing Assistant from Allometa
Dropbox bridges gaps in Microsoft's mobile sync
SmartBear Software Releases AQtime 7.0 Pro
6 Super Wi-Fi Tools for Windows
Microsoft Revives Windows 7 Family Pack Discount
Microsoft releases FixIt for critical flaw in 100 apps
M-Files Cloud Vault Easy, Hosted Document Management
>> Read all the news
More from the ZATZ journals
Computing Unplugged: Smartphone smarts for a mobile world
David Gewirtz Online: CNN commentary and analysis
DominoPower: It's time for Lotus to double-down on Linux and open source
-- Advertisement --

Take Control Over Both Your Incoming And Outgoing Emails
File everything quickly and logically at the click of a mouse

Just tell QuickFile once where you want emails from each sender to be filed, and from then on a simple mouse click files them away automatically.

We know how important your sent emails are. With one click, your outgoing mail is sent and filed to the correct folder, automatically.

No more digging. It's all where it's supposed to be. Automatically.

Tap here to download a fully-functional 30-day trial.

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login