Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - PC could be infected without opening an infected mail?!

 
Thread Tools Search this Thread
Old 02-28-2004, 02:18 AM   #1
Default PC could be infected without opening an infected mail?!


Looking for confirmation of the following:

Heard somewhere that one could infect a PC just by viewing a mail message
containing malicious code, "in the lower pane", even without "opening" it or
execute its attachment.

Is it true? Any comments are appreciated.

Thanks and have a nice weekend.




Doug Fox
  Reply With Quote
Old 02-28-2004, 02:42 AM   #2
Will Dormann
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
Doug Fox wrote:

> Looking for confirmation of the following:
>
> Heard somewhere that one could infect a PC just by viewing a mail message
> containing malicious code, "in the lower pane", even without "opening" it or
> execute its attachment.
>
> Is it true? Any comments are appreciated.



Absolutely true. At least if your Outlook Express/IE is not totally up
to date with security patches. When you view a message just in the
preview pane, it *is* "opening" the message.

Some exploits use a vulnerability in OE/IE to trick it into executing
code automatically. (such as mucking with the MIME type of an
attachment, for example)


-WD


Will Dormann
  Reply With Quote
Old 02-28-2004, 03:05 AM   #3
Doug Fox
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
In terms of prevention, in addition to "patch" the holes using Windows
Update. What else can we do in this regards?

Thanks again.


"Will Dormann" <> wrote in message
news:HeT%b.16697$...
> Doug Fox wrote:
>
> > Looking for confirmation of the following:
> >
> > Heard somewhere that one could infect a PC just by viewing a mail

message
> > containing malicious code, "in the lower pane", even without "opening"

it or
> > execute its attachment.
> >
> > Is it true? Any comments are appreciated.

>
>
> Absolutely true. At least if your Outlook Express/IE is not totally up
> to date with security patches. When you view a message just in the
> preview pane, it *is* "opening" the message.
>
> Some exploits use a vulnerability in OE/IE to trick it into executing
> code automatically. (such as mucking with the MIME type of an
> attachment, for example)
>
>
> -WD





Doug Fox
  Reply With Quote
Old 02-28-2004, 03:23 AM   #4
John
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
In article <sTS%b.38086$ ogers.com>,
says...
> Looking for confirmation of the following:
>
> Heard somewhere that one could infect a PC just by viewing a mail message
> containing malicious code, "in the lower pane", even without "opening" it or
> execute its attachment.
>
> Is it true? Any comments are appreciated.
>
> Thanks and have a nice weekend.
>
>
>


My email program (Pegasus) does not execute HTML *if* it requires
visiting a website. It instead gives a warning that the html delivered
in the message contains "lazy HTML" - which presents a security risk
because you must visit the web site to get it. Pegasus says you should
be very careful about overriding the warning and proceeding. So, if you
can read the message in Outlook Express it's already too late.

Once you are on the website you are subject to ActiveX scripts that may
be there - and executed by your Outlook Express or Internet Explorer.

I am very negative about ActiveX. I only use Internet Explorer to get
the Windows Updates (I have Microsoft in the "trusted zone" with full
ActiveX). There is no alternative there. Microsoft won't let you
download the patches with another browser. Otherwise I have ActiveX
turned OFF (completely disabled). The security risks from destructive
scripts are severe. I also deleted the VBS and VBE extensions from the
"list" of extensions my Win2K system recognizes.

I use Mozilla Firebird for normal web browsing and Pegasus Mail for
email. Both are free (and better software even leaving aside the
security issues).

ActiveX? Just say no.





John
  Reply With Quote
Old 02-28-2004, 03:37 AM   #5
Jbob
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
"Doug Fox" <> wrote in message
news:7AT%b.38684$ e.rogers.com...
> In terms of prevention, in addition to "patch" the holes using Windows
> Update. What else can we do in this regards?
>
> Thanks again.
>
>

Several things: First make sure you do have all the MS updates. Second put
OE security zone in the Restricted Zone and third go to the Restriced Zone
and turn off or disable all items. That should pretty much help keep OE
safe. As always you should also run a competent and updated Anti-Virus app.
There is also an option in OE for reading email in text only which will also
elimate any HTML threats.




Jbob
  Reply With Quote
Old 02-28-2004, 05:28 AM   #6
donutbandit
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
"Doug Fox" <> wrote in
news:7AT%b.38684$ e.rogers.com:

> In terms of prevention, in addition to "patch" the holes using Windows
> Update. What else can we do in this regards?


How about just saying "no" to Outlook Express? There are far better
programs for mail that are much more secure.


donutbandit
  Reply With Quote
Old 02-28-2004, 07:43 AM   #7
Will Dormann
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
Doug Fox wrote:

> In terms of prevention, in addition to "patch" the holes using Windows
> Update. What else can we do in this regards?



Sure. Don't use IE/OE. They are ridiculously insecure.

Mozilla Firefox and Thunderbird make excellent replacements for them.



-WD


Will Dormann
  Reply With Quote
Old 02-28-2004, 09:23 AM   #8
Hairy One Kenobi
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
"Doug Fox" <> wrote in message
news:7AT%b.38684$ e.rogers.com...
> In terms of prevention, in addition to "patch" the holes using Windows
> Update. What else can we do in this regards?


http://www.codecutters.org/outlook/

The specific problem is, I'd guess, the IFRAME exploit that should have been
patched a *long* time ago.

Opting to view all messages as plain text (at the bottom of the page)
eliminates this problem as long as you don't attempt to forward the message.

HTH

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!

> "Will Dormann" <> wrote in message
> news:HeT%b.16697$...
> > Doug Fox wrote:
> >
> > > Looking for confirmation of the following:
> > >
> > > Heard somewhere that one could infect a PC just by viewing a mail

> message
> > > containing malicious code, "in the lower pane", even without "opening"

> it or
> > > execute its attachment.
> > >
> > > Is it true? Any comments are appreciated.

> >
> >
> > Absolutely true. At least if your Outlook Express/IE is not totally up
> > to date with security patches. When you view a message just in the
> > preview pane, it *is* "opening" the message.
> >
> > Some exploits use a vulnerability in OE/IE to trick it into executing
> > code automatically. (such as mucking with the MIME type of an
> > attachment, for example)
> >
> >
> > -WD

>
>





Hairy One Kenobi
  Reply With Quote
Old 02-28-2004, 12:04 PM   #9
Thund3rstruck_N0i
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
Doug Fox spilled my beer when they jumped on the table and proclaimed in
<sTS%b.38086$ ogers.com>

> Looking for confirmation of the following:
>
> Heard somewhere that one could infect a PC just by viewing a mail message
> containing malicious code, "in the lower pane", even without "opening" it
> or execute its attachment.
>
> Is it true? Any comments are appreciated.
>
> Thanks and have a nice weekend.


IIRC, Klez was the first that did this. Of course if Outlook Express/OS is
properly patched, it neuters that particular problem.

NOI


Thund3rstruck_N0i
  Reply With Quote
Old 02-28-2004, 06:47 PM   #10
Gladys Pump
 
Posts: n/a
Default Re: PC could be infected without opening an infected mail?!
On 28 Feb 2004 05:28:36 GMT, donutbandit <>, whilst in the
alt.computer.security newsfroup, articulated the following sentiments :

>"Doug Fox" <> wrote in
>news:7AT%b.38684$ le.rogers.com:
>
>> In terms of prevention, in addition to "patch" the holes using Windows
>> Update. What else can we do in this regards?

>
>How about just saying "no" to Outlook Express? There are far better
>programs for mail that are much more secure.


I've personally always used Agent for mail and news.

http://www.forteinc.com/main/homepage.php

Super fast, rock solid and a good alternative to OE for those that desire
it. Version 2 now ready for download.

Is that spammy ? Sorry.

Imagine what they'll be doing by the time *they* get to version 6.

Regs, Pete.



Gladys Pump
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
File download dialog box is coming while opening the document using Servlet aarthi Software 0 04-24-2007 03:20 PM
How would you fix a badly infected PC? walterbyrd A+ Certification 6 11-12-2006 03:13 AM
How can You get infected by TROJANS? Abbas Software 1 08-29-2006 03:03 PM
Alternative to Netflix Throttling? root DVD Video 28 02-14-2006 01:13 AM
Re: Virus Problem ** Help!** David BlandIII A+ Certification 1 03-02-2004 06:00 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46