The Hacker's Target

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

The Hacker's Target

Post by b0b »

Here's an interesting article on hacking into Microsoft:
www.theregister.co.uk/content/1/14344.html

It seems that some of these annoying email worms are actually part of criminal hackers' efforts to gain access for profit.

Never run email attachments. Never. Even if they're from me.

------------------
<img align=left src="http://b0b.com/Averybob.gif" width=64 height=81><small>
</small> -b0b-   <small> quasar@b0b.com </small>
-System Administrator
User avatar
Jack Stoner
Posts: 22146
Joined: 3 Dec 1999 1:01 am
Location: Kansas City, MO

Post by Jack Stoner »

Or get Outlook 2000 with the security updates. The security updates will not let you run an exe, Active X, etc., even if you wanted to - just won't let you do it.

That seems a little overkill, but it can save your butt.
User avatar
Jim Smith
Posts: 7949
Joined: 4 Aug 1998 11:00 pm
Location: Midlothian, TX, USA

Post by Jim Smith »

I got the security updates for Outlook 2000 as part of the Office 2000 service pack. Now I can't figure out how to receive an executable when I want to. I can see that there is an attachment by the paper clip on the message but when I try to save it, it says there are no attachments. Anyone know how to at least selectively turn that off?
User avatar
Jack Stoner
Posts: 22146
Joined: 3 Dec 1999 1:01 am
Location: Kansas City, MO

Post by Jack Stoner »

Jim, once the security update is installed, it's bascially all over. They have categories for different files and the .exe is in the category that can't be modified.

I know, it sucks as they don't give you any option on certain types of files. Microsoft was taking a lot of heat for the security holes and it looks like they over reacted. It will protect the dummies, but it puts a crimp in legitimate operations.

My suggestion would be to have Outlook Express also installed and if you knew someone was going to send you an .exe, use the outlook express to receive the message.
Jeff Agnew
Posts: 741
Joined: 18 Sep 1998 12:01 am
Location: Dallas, TX

Post by Jeff Agnew »

Sorry, but instead of trying to stay ahead of the myriad Outlook/OE security holes, why not get a security-aware e-mail client?

Both Poco and The Bat are shareware apps without the most glaring holes in MS products, are smaller, offer more useful features, and ship with more secure default settings. Let's face it, not many folks stay current with MS patches and rarely change from default configurations.

Also, users would be wise to remove Windows Scripting Host from their systems, disable *all* ActiveX, enable display of all file extensions, and never, ever, use HTML in e-mail.