Home > Microsoft Exchange Tips > Exchange Security Tips > How to combat e-mail viruses
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SECURITY TIPS

How to combat e-mail viruses


Brien M. Posey
02.10.2004
Rating: -4.20- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


I was bombarded with e-mails from people who were infected by the MyDoom virus, which MessageLabs called the fastest-spreading computer virus of all time.

Did you have an effective anti-virus strategy in place when MyDoom struck? I'm sure many of you did, but preventing e-mail viruses from spreading within any organization is not easy. No one strategy is sufficient when trying to prevent e-mail viruses, and the only way to really conquer them is to use a combination of techniques.

One of your first priorities is educating your users. Seems obvious, but you need to explain to them what constitutes a suspicious attachment. Even though this is critical, don't expect your users to keep viruses out of your organization once you do educate them. I have received way too many phone calls over the years that start off with, "I know that you told us not to open attachments from people that we don't know, but..."

Fortunately, Outlook lends a helping hand by blocking malicious attachments. Outlook 2000 (Service pack 2 and later), XP, and 2003 block about 60 different file extensions that Microsoft considers dangerous. For example, many E-mail viruses use the .PIF file extension. Should someone running Outlook 2003 receive an E-mail message with a .PIF file attached, Outlook will prevent the user from opening the file, and prevent the virus from executing.

Blocking potentially harmful E-mail attachments directly through Outlook is a huge step in slowing the spread of E-mail viruses, but it isn't enough for several reasons. For starters, there are still people in the world with older versions of Outlook that don't support file attachment blocking. There are also people running E-mail clients other than Outlook. Even if a user is running a current version of Outlook, it is possible for the user to disable file extension blocking by editing the Registry.

By default, Windows is configured to hide file extensions for known file types. Many viruses, including MyDoom, exploit this by using multiple file extensions. For example, a file might be named FILE.DOC.EXE. While the .EXE extension indicates that this is an executable file, Windows hides the .EXE extension and would simply display the filename as FILE.DOC. A user might then see this file and assume that it is a harmless Microsoft Word document. To prevent this from happening, I often recommend configuring all of your user's computers to show all file extensions. However, in some cases revealing the true file extension would not do anything to stop the spread of MyDoom.

ZIP seemed harmless, but wasn't

The MyDoom virus managed to circumvent Outlook's file blocking for a lot of people because one of the extensions that it used was ZIP. ZIP files themselves are harmless, so if users viewed the file extension, they might assume the file was harmless. The actual virus is compressed within the ZIP archive. Outlook does nothing to block the .ZIP file because ZIP is considered a safe file type. Furthermore, Outlook does not block the contents of a ZIP file regardless of file type.

Imagine for a moment that one of your users has a friend whose computer became infected with MyDoom and the virus on that computer gets sent to someone in your organization in the form of a ZIP attachment. Even a well-trained user might try to open the attachment. After all, it's a harmless ZIP file from a friend. In this case, the user opens the attached file and activates the virus. Sure, your anti-virus software should kick in and stop the virus in its tracks, but what if the virus definition files haven't been updated to recognize the new virus yet?

The MyDoom virus uses one of the following subject lines when it gets sent out: test, hi, hello, Mail Delivery System, Mail Transaction Failed, Server Report, Status, or Error. You could tell your SPAM filter to block any message using one of these subject lines. More sophisticated SPAM filters will even allow you to block messages with certain attachment types. If you have such an application, you could for example block any inbound message that has a subject line of Hello and contains a ZIP file.

While I am a big believer in anti-virus software, I am an even bigger believer in prevention. My philosophy is that you should make every effort to block a virus from entering your organization in the first place. If a virus does get in, then your anti virus software should be your last line of defense, not your first.


Rate this Tip
To rate tips, you must be a member of SearchExchange.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Exchange Security Tips
Use the OWA Admin tool to 'segment' Outlook Web Access 2003 features
Why are .PST files a security threat to Exchange Server mailboxes?
OWA won't load after applying Exchange 2007 SP1 security patch
Minimize remote and mobile Outlook Web Access (OWA) security risks
Grant or deny permissions to access a user's Exchange 2007 mailbox
Create a global Safe Senders List in Exchange 2007 to filter spam
Migrating antispam settings from Exchange 2003 to Exchange 2007
Deploying ISA Server as a firewall for Exchange Server mobile devices
How to customize OWA authentication logon in Exchange Server 2003
Exchange 2007 out-of-office (OOF) feature adds usability and security

Antivirus Software and Virus Protection
Minimize remote and mobile Outlook Web Access (OWA) security risks
Secure Edge Transport servers using the Security Configuration Wizard
The six-layered secret of effective Exchange Server email filtering
Microsoft Outlook and Exchange Server 2003 Email Security Guide
How to install and configure an Edge Transport server for Exchange 2007
Process, compress and block Microsoft Outlook email attachments
How to configure attachment blocking in Outlook Web Access
Beware of bare linefeeds in Exchange Server email
Dell, Symantec simplify Secure Exchange for SMBs
Unsecured devices worry IT professionals

Microsoft Outlook
Slipstreaming Microsoft Office 2007 deployments
Does Exchange cached mode work with all versions of Microsoft Outlook?
How to access SharePoint sites through Microsoft Outlook
What makes Microsoft Outlook 2007's Search feature special?
Uncovering Microsoft Outlook 2007's hidden diagnostic tools
How Microsoft Office Communicator enhances Outlook 2007 functionality
Microsoft Outlook .PST file FAQs
Tool exports messages from Microsoft Outlook to Unix .EML file format
DetachPipe: Outlook add-in tool saves and restores email attachments
Install the Outlook Connector to use Hotmail in Microsoft Outlook
Microsoft Outlook Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
greylist  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts