Home > Enterprise Desktop Tips > > Interesting times in your e-mail inbox
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Interesting times in your e-mail inbox


Tom Lancaster
02.03.2004
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Recently, numerous new mass mailing viruses -- including Beagle.A, Novarg.A, and MyDoom.B -- have been discovered. What makes these viruses so powerful and such great potential sources of infection is that not only do they harvest e-mail addresses from e-mail address books and other files likely to contain e-mail addresses to identify designated message recipients, but they also use harvested addresses to identify the sender as well. For example, MyDoom.B looks in files with these extensions: .adb, .asp, .dbx, .htm, .php, .pl, .sht, .tbb, .txt and .wab.

Why is this significant, you may ask? Because so many antispam and e-mail filtering techniques rely on the use of white lists (that is, lists of sender addresses that are allowed to make their way into your inbox), it's inevitable that some of the harvested addresses that purport to identify the senders of infected messages will be on a white list that lets them into your inbox. In my own experience, within 48 hours of the discovery of the Beagle.A worm, I'd already received half-a-dozen e-mails that claimed to originate from senders whose messages I'd never normally question. I'm sure it's been the same for most e-mail users: SearchSecurity.com published estimates on Jan. 28 that one in every 12 e-mails contained the MyDoom virus.

Fortunately, antivirus software already in place on most desktops is able to catch and block receipt of the infected attachments that permit the virus to spread to other computers. But this situation does illustrate that simple-minded address-checking is not enough to stop all malicious e-mail from making its way into your inbox. Other simple checks, such as for specific subject lines, payload text, or attachment names, will also help to keep unwanted e-mail from arriving in your inbox, even if it claims to originate from some user you would normally trust. This explains why content-oriented e-mail gateways, such as Alladin's eSafe, are gaining more interest and acceptance in the marketplace, since they can screen e-mail not only on the basis of addressing information, but also based on content terms and patterns, attachment types, and so forth. It also explains why it's so important to screen your e-mail, and to keep anti-virus software and signatures absolutely up-to-date!

Follow links to learn more about the following viruses:
W32.MyDoom.B@mm
W32.Novarg.A@mm
W32.Beagle.A@mm


Thomas Alexander Lancaster IV is a consultant and author with over 10 years experience in the networking industry, focused on Internet infrastructure.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network intrusion detection and prevention and malware removal
20 days to a more secure enterprise
Improvements to offline file synchronization in Windows 7
Underlying causes of inconsistent patch management
Windows security tools for the busy desktop administrator
Check IT List: Five steps for rootkit detection
Top Windows client security tools for end users
Hacking Exposed Windows: Windows security features and tools
Tools for virus removal and detection
Windows security testing: Five tips for the summer
Buffer overflows can be prevented by GS cookies

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts