Search OutlookPower's 8,981 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
EMAIL SECURITY
Another month, another virus
By Diane Poremsky

Another month, another virus. This time it's the fast moving MyDoom (a.k.a. MiMail.R) that's driving everyone bonkers. You'd think by now people would learn, and for the most part, users are better at recognizing an infected message on their own. Many antivirus programs and firewalls automatically filter out messages containing *.EXE, *.PIF, *.SCR, and others, but allow the *.ZIP extension to pass. Unfortunately, enough people opened the ZIP and executed the contents before the antivirus filters were updated to create a flood of viruses and bogus virus warnings for the rest of us.

"What can administrators do to stop the lunacy?"

My pet peeve today is more with antivirus installations that have notifications enabled than the users who open the attachments without thinking. MyDoom collects addresses from any number of sources: text files, Outlook Express's mail store (*.DBX), the Windows Address book (*.WAB), HTML files, and others. If that doesn't provide enough addresses, it makes them up, using common first names and domains it finds in the files it scans. So, we have a virus sending messages to and/or from bogus addresses and antivirus programs blocking delivery, then creating more load on already swamped servers by sending notification to a falsified address that they sent an infected message, creating even more NDRs (Non-Delivery Receipts).

What can administrators do to stop the lunacy? They can begin by turning off the virus notifications to Internet addresses. These notifications create more useless traffic, often exceeding the bandwidth caused by the actual virus because of all the NDRs generated, and often needlessly scaring users into thinking they are infected when they aren't.

One administrator had this to say:

I spent more time today assuring clients that they haven't got the virus because of these types of NDR. The worse one had this as part of their text:
'This notice is sent as a courtesy so that you have the option of contacting your user and helping them get rid of the virus. This message was sent by Declude Virus. If your mail server had better virus protection, it would have caused less work for our server and could have prevented one of your users from getting a virus.'
I told my client that if the NDR sender had a better administrator 90% of their problems would disappear.

To learn more about how MyDoom works, see http://www.viruslist.com/eng/viruslist.html?id=841769.

This is also a good time for network administrators to review and update the policy on which extensions are blocked and find a new way to transfer files. Email is a convenient way for users to transfer files, but network security is more important.


1  ·  2  ·  Next »
Other articles you might like
Home > Online Safety > Virus protection (7 articles)
   Readers clock in on Microsoft v. Symantec
   The great Windows Vista antivirus war
   How the SoBig.F virus works
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
Running auto-respond rules when Outlook is closed
Running rules when Outlook is closed
Disappearing text that's not supposed to disappear
What to do when Outlook complains about a program you know you uninstalled
Nothing says new year better than emails from crazy people
Say goodbye to the Uh-Ohs. Long live the Tens.
How to have a clean inbox in 2010
OutlookPower News Center
EML to PST Converter - Conversion of Email Formats to Outlook
Windows 2000, XP SP2, Vista RTM support nears end
Windows 7 Just Being Honest About Battery Life
Remo Software Launches Data Recovery Software
US scientists get free cloud on-ramp
Leaky anti-virus defences letting malware through
Patch Tuesday Release Will Tie Microsoft's Record
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad: Apple's latest heartbreaker
David Gewirtz Online: CNN commentary and analysis
DominoPower: Lotusphere 2010: mobility and collaboration
-- Advertisement --

ONLINE GROUP CALENDAR - FOR UP TO 100 OF YOUR CLOSEST FRIENDS
Stay organized and in control with 24/7 access to all of your important events, projects and files --whether you're at work, at home or on the road.

You can share your calendar, projects and files so everyone in your office is up to date. Plus, search your entire group to find times when everyone is available to meet, manage company resources and much more.

Organize your entire team for as low as $9.95 per year (and yes, that's where the decimal place is supposed to be!)

Tap here to get started right away.

-- Advertisement --

Sent Items Organizer
When you need to file your sent email into their proper folders based on keywords or who it's to. It's also perfect for shared mailboxes.

It also adds a "Send And File" toolbar button while you're composing (similar to the way Lotus Notes used to work) for quick and easy filing.

Find out more!

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login