On TechRepublic: 10 lame phrases to cut from your resume
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 16 of 34:
Next »
« Previous
Did you even bother to read what I wrote?
You wrote:"First, scripting is turned off in Outlook by default now, unlike in 2000, by setting the IE-in-Outlook security to restricted and turning off all scripting in this zone. This means these scripts you're talking about don't even get a chance to run. Most users also opt to view emails as text only although we still allow them the option of HTML for now. " and "Any non-approved email or any email with executable attachments (including zips) it gets quarantined based on the rules engine."

I wrote: "2) The email itself contains the social engineering and a URL to one of many compromised webservers." and "4) The hostile webpage itself exploits a combination of known vulnerabilities in Microsoft's Internet Explorer that Microsoft has chosen not to release an update to fix."

Note, the email itself does not contain *ANY* scripting, only html or maybe some social engineering and a URL. Blended attacks are exploited initially by Javascript coded script in the browser, by which the mallware may install visual basic or native coded worm.
http://www.safecenter.net/UMBRELLAWEBV4/ie_unpatched/index.html

Scripting languages, including Javascript and Visual Basic remain the favored tools of "The Virus Underground"
http://www.nytimes.com/2004/02/08/magazine/08WORMS.html

As I stated back in 2000
http://www.google.com/groups?threadm=slrn8j2cen.pns.heretic%40localhost.localdomain
It is a LOT easier to create a Visual Basic or Jscript virus than
to create a binary executable virus.

Any teenager with half a brain can now grab a copy of a trojan love,
melissa or any number of new visual basic scripts. He can modifiy it by
trial and error until it passes the virus scanners. Then embed the trojan
in ANY type of Microsoft Office 2000 <ocument. He can then attach
the document to the email or have a URL to the document on a web/ftp server.

You wrote:"Secondly, we run an email "white list" that will only allow in email from known sources... "

But I wrote: "1) Hostile emails are increasingly using the tactic of grabbing the email address, In-Reply-To and subject headers from the outlook inbox, making it appear that the email is a reply to a legitmate email."

Note that it the worm itself, via the MAPI interface or by hyjacking Outlook, which delves into the outlook/exchange Inbox.

You wrote:"... and restricts outgoing email. Any non-approved email or any email with executable attachments (including zips) it gets quarantined based on the rules engine. "

This is good news and a good firewall setup with an outgoing SMTP server/proxy can stem the outgoing spread of emailed viruses.

You wrote:"... While there is still the possibility that something could get through, it is highly unlikely to have a high impact. "

However the problem is that, under the above scenario, and apparently according to the Zdnet article most of the companies are deploying anti-virus software, your systems remain vulnerable.

http://zdnet.com.com/2100-1105-5176420.html
The numbers indicate that antivirus software isn't proof against infection. Almost all of the companies surveyed said that at least 90 percent of their desktops have antivirus protection, but still a third of the companies suffered virus disasters.

You wrote:"... We would run the same kind of server side restrictions no matter the OS or mail server. ".

But I wrote:"3) The URL links to a SSL (https://) site. The connection is encrypted from the website to the browser -- no chance of the firewall proxy reading the content.".

You wrote:"Start ranting about ActiveX BHO exploits in IE for a change. I might even agree with you then."

Now I know that you did not even bother to read my reply. The blended attack thread uses exploits in IE.

The Microsoft scripting execution environments for document embbedded scripting and code,whether embbedded in HTML, XML or Microsoft Office documents, remains one of the primary issues of concern with Microsoft securty. That has not changed since September 2000.
http://www.google.com/groups?threadm=slrn8j2cen.pns.heretic%40localhost.localdomain

Other desktop environments and applications can provide significantly more secure platform for dealling with day to day business.
Posted by: David Mohring   Posted on: 03/20/04 You are currently: a Guest | Members login | Terms of Use
Reply to Story No further replies to this post will be accepted.

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

blah  carbon-12 | 03/19/04
does anyone see a correlation?  stephen732@... | 03/19/04
One train, just switch to Linux  FilledOut | 03/19/04
Costs too much  jfrankcarr | 03/19/04
your forgetting something  stephen732@... | 03/19/04
That is a consideration  jfrankcarr | 03/20/04
RE: That is a consideration  nite_w0lf | 03/20/04
Delegating virus software  jfrankcarr | 03/20/04
2000/05/28:Microsoft Applications Security And The Internet  David Mohring | 03/19/04
Pretty dated information there.  jfrankcarr | 03/19/04
If anything, its worse - Phishing for IE vulnerabilities  David Mohring | 03/19/04
Have to somewhat disagree based on my experience  jfrankcarr | 03/20/04
a laptop solution  Iain_Peters | 03/20/04
Do you plan on collecting your bonus anytime in the future?  David Mohring | 03/20/04
You're still talking about 2000 era threats  jfrankcarr | 03/20/04
Did you even bother to read what I wrote?  David Mohring | 03/20/04
The exploits are scripting related  jfrankcarr | 03/20/04
So how much does Windows really cost???  DonnieBoy | 03/19/04
Still think M$ has a lower TCO?  carbon-12 | 03/19/04
TCO THIS!  spinit | 03/20/04
If Everyone Used Linix == Same problems  lslade | 03/20/04
RE: If Everyone Used Linix == Same problems - rubbish  Iain_Peters | 03/20/04
RE: If Everyone Used Linix == Same problems - rubbish  seosamh_z | 03/21/04
The problem is when MSCEs talk *nix security  Richard Flude | 03/21/04
IIS vs Apache  doe_z | 03/20/04
Linux CAN be made secure relative to Windows...  deathbymilkfloat | 03/20/04
Linux CAN be made secure relative to Windows...  seosamh_z | 03/21/04
just out of curiosity, how did you ever find your way onto the net!  nite_w0lf | 03/20/04
If Everyone Used Linix -- Execute bit  SilverEagle_z | 03/27/04
TCO! TCO! Get The Facts! TCO!  B_HI | 03/20/04
Mindless Sheep?  TWRX | 03/20/04
Stupid response to a stupid post?  ZorakQMantis | 03/21/04
And the viruses are spreading to automobiles  Squawkbox | 03/20/04
and where do we get these figures  JWatson77 | 03/24/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads