Search OutlookPower's 9,069 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
EMAIL SECURITY
Another month, another virus
By Diane Poremsky

Another month, another virus. This time it's the fast moving MyDoom (a.k.a. MiMail.R) that's driving everyone bonkers. You'd think by now people would learn, and for the most part, users are better at recognizing an infected message on their own. Many antivirus programs and firewalls automatically filter out messages containing *.EXE, *.PIF, *.SCR, and others, but allow the *.ZIP extension to pass. Unfortunately, enough people opened the ZIP and executed the contents before the antivirus filters were updated to create a flood of viruses and bogus virus warnings for the rest of us.

"What can administrators do to stop the lunacy?"

My pet peeve today is more with antivirus installations that have notifications enabled than the users who open the attachments without thinking. MyDoom collects addresses from any number of sources: text files, Outlook Express's mail store (*.DBX), the Windows Address book (*.WAB), HTML files, and others. If that doesn't provide enough addresses, it makes them up, using common first names and domains it finds in the files it scans. So, we have a virus sending messages to and/or from bogus addresses and antivirus programs blocking delivery, then creating more load on already swamped servers by sending notification to a falsified address that they sent an infected message, creating even more NDRs (Non-Delivery Receipts).

What can administrators do to stop the lunacy? They can begin by turning off the virus notifications to Internet addresses. These notifications create more useless traffic, often exceeding the bandwidth caused by the actual virus because of all the NDRs generated, and often needlessly scaring users into thinking they are infected when they aren't.

One administrator had this to say:

I spent more time today assuring clients that they haven't got the virus because of these types of NDR. The worse one had this as part of their text:
'This notice is sent as a courtesy so that you have the option of contacting your user and helping them get rid of the virus. This message was sent by Declude Virus. If your mail server had better virus protection, it would have caused less work for our server and could have prevented one of your users from getting a virus.'
I told my client that if the NDR sender had a better administrator 90% of their problems would disappear.

To learn more about how MyDoom works, see http://www.viruslist.com/eng/viruslist.html?id=841769.

This is also a good time for network administrators to review and update the policy on which extensions are blocked and find a new way to transfer files. Email is a convenient way for users to transfer files, but network security is more important.


1  ·  2  ·  Next »
Other articles you might like
Home > Online Safety > Virus protection (7 articles)
   Readers clock in on Microsoft v. Symantec
   The great Windows Vista antivirus war
   How the SoBig.F virus works
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
Removing an Office installation that doesn't want to go away
Using Office on more than one computer
How to fall back in love with your email
Where'd my To-Do Bar go?
Running auto-respond rules when Outlook is closed
Running rules when Outlook is closed
Disappearing text that's not supposed to disappear
OutlookPower News Center
Koobface gang refresh botnet to beat takedown
Intel Core i7-980X Extreme 6-Core Processor Review
DocAve v5.4 Delivers Beta Support for SharePoint 2010
ENow Announces New Exchange 2010 Monitoring and Reporting Features
Microsoft boffin wins Turing Award
Remote-Code Vulnerability Being Exploited in IE 6 and 7
Raxco Software Releases PerfectDisk 11 Disk Defrag Software
>> Read all the news
More from the ZATZ journals
Computing Unplugged: Make Mafia Wars an offer it can't refuse
David Gewirtz Online: CNN commentary and analysis
DominoPower: Application development, William Shatner, and the origin of the universe
-- Advertisement --

EASY DEDICATED AND VIRTUAL DEDICATED SERVERS FOR AS LOW AS $67.99 PER MONTH
Customize and configure your own dedicated server. Simply choose one of our popular plans or select your own Linux or Windows server and plan options.

NO LONG WAITS. Server provisioned within hours.

Tap here now and be up and running with your own server tonight.

-- Advertisement --

Influencer. Recommender. Decision Maker.
They all read OutlookPower Magazine. They all rely on OutlookPower Magazine.

If you want to reach the inner-circle of IT professionals, you won't find a better resource than OutlookPower Magazine.

Click for our Media Kit

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login