Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 2002

Safe Email Practices

Avoid the latest round of virus attacks
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Every day for 2 weeks last month, the latest round of the Klez email virus pummeled my computer. So I'd like to dedicate this month's column to safe email practices. To avoid the spread of viruses, you should use a combination of technology and common sense. These 10 tips can help you ensure that you're practicing safe email.

10. Install an antivirus product—Almost all the popular antivirus products automatically scan incoming email for viruses. Such protection is an absolute requirement. However, antivirus products are always one step behind the latest viruses, so don't think you can forget about virus protection just because you install a product.

9. Don't assume you're safe just because you don't use Microsoft Outlook 2002—Although Outlook is one of the most popular virus targets, no email client is immune from this kind of attack. Many viruses spread in the form of attachments, so all you need to do is open one and you're infected.

8. Remember that Microsoft doesn't send updates through email—A popular exploit among virus authors is to use subject tags and text to trick you into opening attachments or clicking on embedded links in email text. The latest ironic twist to this trick is disguising viruses as security patches. Never open an email attachment that appears to be a Microsoft update—it isn't.

7. Never run the executable files in a pop-up window that an email message displays—Another popular virus-author tactic is to embed executable files in an email message's HTML text. When you open the message, a pop-up window prompts you to open the executable files. To eliminate these annoying pop-up windows, turn off the Outlook Preview Pane by selecting View and clearing the Preview option.

6. Install the most recent Microsoft Internet Explorer (IE) and Outlook security updates, if possible—Virus writers constantly uncover new exploits, but Microsoft has been diligently filling the holes people find. Getting caught by a known exploit is equivalent to getting caught with your pants down. You can find Microsoft's security updates and information at http://www.microsoft.com/security.

5. Take advantage of Outlook's security settings—You might not be able to use the Outlook Security Update (http://www.microsoft.com/office/outlook/evaluation/security.asp) because it won't let you receive executables. However, you can increase Outlook's security level by selecting Tools, Options, Security, Zone Settings. Select the Internet zone, then click Custom Level. In the Security Settings dialog box, disable the ActiveX controls and plugins options and the Active scripting option.

4. Don't open email attachments that have file extensions of .bat, .vbs, .shs, .pif, or .scn if you can help it—Safe attachments rarely use these extensions, but they're a favorite choice among virus writers because they carry executable instructions.

3. Don't open attachments that have double file extensions—Although you can create and use files that have double extensions, the practice is unusual except among virus writers, for whom it's a common subterfuge.

2. Configure Windows to show file extensions—Microsoft's decision to make Windows automatically hide file extensions is the worst design decision the company has ever made. If you can't see the extension, virus writers can easily fool you about a file attachment's true nature. In Windows 2000, you can view file extensions by opening Windows Explorer and selecting Tools, Folder, Options, View, and clearing the Hide file extensions for known file types check box.

1. Never directly open an attachment—Save all attachments and scan them for viruses before you open them. Anyone, even your best friend, can inadvertently pass along a virus.

End of Article



Reader Comments
In the decmber 2002 issue of the magazine, John E. Quigley writes in "Letters to the Editor" to avoid ".src files", I think he means "*.scr files".

Kind regards,


André van den Beukel January 15, 2003


This is a really cool reminders I hope there would me more soon about how to avoid malicious things over the internet.

syd July 04, 2004


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Where is Microsoft NetMeeting in Windows XP?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing