Dangerous SPAM
|
|
Millie Thompson
Resident Moderator
Join date: 18 Dec 2002
Posts: 364
|
01-06-2005 11:18
A few months ago I received an e-mail from some (insert your choice of bad word(s) here) spammer. The e-mail sent sat happily on my host's mail server before being sent along the long journey from the UK to my inbox here on the east coast of the US.
Downloaded the e-mail and AVG antivirus happily let the e-mail though being free of any sort of virus. Being the last one to download MS Outlook Express happily displayed this last e-mail in the preview pane.
Ding! "Your current security settings prohibit running ActiveX controls on this page. As a result the page may not display correctly." [Ok]
A brush 2 months earlier with an ActiveX control from a website had SEVERELY infected my PC with a small sampling of the latest and greatest mass mailing worms, a failed Code Red infection, 4 active trojans, 5 keyloggers, and a nice little application that ran and downloaded 17 ad displaying pieces of adware. Basically severely crippling my beloved gaming PC and initiating a 72 hour long battle with one of the adware companies trying to get ANY sort of information on manually removing their (bad word here) application. They sent me an uninstaller (failed and installed several more adware applications and crippled my firewall) to "rid" my PC of their (bad word here). Eventually I had to wipe the drive and start anew, a painful process of install this, update that, patch this too.
Anyway, back to this e-mail...
I forwarded the e-mail to another e-mail account and ran it on a testing machine. BAM!! Popups and two keyloggers. The firewall I had disabled to see the effects of the embedded ActiveX control in the e-mail, and not suprisingly the firewall (software based) wouldn't restart when I tried running it again.
Windows XP Service Pack 2... sure I have my doubts about it, but without its ActiveX blocking tool this spammer (RealSavingz) would no doubt have a zombie machine to do someone's bidding.
Personally I think anti-spam laws are useless unless the spammers can be caught and given 5 years for every 10,000 e-mails sent. I can remember the days when all you had to worry about was going over the allocated free e-mails CompuServe gave you and you had to pay a little extra on the next bill.
_____________________
Millie Thompson I am a Resident Moderator. I am a volunteer moderator on this forum, NOT a Linden. If you have any issues or concerns with your Second Life experience please go to Second Life Support
|
|
Cubey Terra
Aircraft Builder
Join date: 6 Sep 2003
Posts: 1,725
|
01-06-2005 11:22
Protect your computer by avoiding Outlook and Outlook Express. If you feel that you *must* use them for some reason, turn off the preview pane. Preview just ensures that every mail that's highlighted is opened. That ensures that your computer WILL get infected.
_____________________
C U B E Y · T E R R A planes · helicopters · blimps · balloons · skydiving · submarines Available at Abbotts Aerodrome and XstreetSL.com 
|
|
Einsman Schlegel
Disenchanted Fool
Join date: 11 Jun 2003
Posts: 1,461
|
01-06-2005 11:43
I've been looking for an alternative to Outlook/Outlook Express for many many months. So far, the only liable alternate would be Yahoo. But, a lot of registry accounts don't allow that as a main e-mail account due to fraud issues.
Microsoft, being the main target of attack, it seems utterly pointless to use any of its products.
|
|
Maxx Monde
Registered User
Join date: 14 Nov 2003
Posts: 1,848
|
01-06-2005 11:50
Perhaps try Mozilla's Thunderbird v1.0 . I have used it to see how compatible it was with Exchange server, and it seemed to work well...
|
|
Ulrika Zugzwang
Magnanimous in Victory
Join date: 10 Jun 2004
Posts: 6,382
|
01-06-2005 11:53
Get a new Apple! Next week at the Mac Expo they're expecting Apple to unveil a new headless (no monitor) computer aimed at Windows and iPod users for only $599. It's rumored to have an integrated KVM switch, which will allow it to share a keyboard, mouse, and monitor with a PC. This means with a touch of a button you'll be able to switch back and forth between your PC and a slim little Apple which can be tucked under your monitor. How cool is that? With that said, I use Apple's Mail program. Check out the link. Its best feature is that it supports message threading. I don't know how I lived without it. Oh yes, and no more ActiveX garbage or viruses.  ~Ulrika~
_____________________
Chik-chik-chika-ahh
|
|
Grim Lupis
Dark Wolf
Join date: 11 Jul 2003
Posts: 762
|
01-06-2005 17:13
From: Cubey Terra Protect your computer by avoiding Outlook and Outlook Express. If you feel that you *must* use them for some reason, turn off the preview pane. Preview just ensures that every mail that's highlighted is opened. That ensures that your computer WILL get infected. Apparently you glossed over the part where Outlook Express is the only reasong her computer didn't get infected.
_____________________
Grim
"God only made a few perfect heads, the rest of them he put hair on." -- Unknown
|
|
Jack Moseley
Registered User
Join date: 24 Aug 2004
Posts: 39
|
01-06-2005 22:26
From: Ulrika Zugzwang With that said, I use Apple's Mail program. Check out the link. Its best feature is that it supports message threading. I don't know how I lived without it. Oh yes, and no more ActiveX garbage or viruses.  I second that... I've moved to using apple's mail as my primary mail client and except for some minor problems its by far the best mail client I've used.
|
|
Hiro Pendragon
bye bye f0rums!
Join date: 22 Jan 2004
Posts: 5,905
|
01-06-2005 22:35
Wow, thanks for sharing that story. I love to hear about stuff like that. Glad you avoided the payload!
That being said, Outlook is a horribly unsafe email program. Go GMAIL.
_____________________
Hiro Pendragon ------------------ http://www.involve3d.com - Involve - Metaverse / Emerging Media Studio
Visit my SL blog: http://secondtense.blogspot.com
|
|
Xtopherxaos Ixtab
D- in English
Join date: 7 Oct 2004
Posts: 884
|
01-07-2005 07:22
From: Ulrika Zugzwang Get a new Apple! Next week at the Mac Expo they're expecting Apple to unveil a new headless (no monitor) computer aimed at Windows and iPod users for only $599. It's rumored to have an integrated KVM switch, which will allow it to share a keyboard, mouse, and monitor with a PC. This means with a touch of a button you'll be able to switch back and forth between your PC and a slim little Apple which can be tucked under your monitor. How cool is that? With that said, I use Apple's Mail program. Check out the link. Its best feature is that it supports message threading. I don't know how I lived without it. Oh yes, and no more ActiveX garbage or viruses.  ~Ulrika~ I'm planning to grab one for my work desk....but that's not sure fire to solve the spam/spy problem, but will help me bunches in tech support
|
|
Artillo Fredericks
Friendly Orange Demon
Join date: 1 Jun 2004
Posts: 1,327
|
01-07-2005 07:52
MMM MMM GOOD! 
_____________________
"I, for one, am thouroughly entertained by the mass freakout." - Nephilaine Protagonist --== www.artillodesign.com ==--
|
|
Driftwood Nomad
Registered User
Join date: 10 May 2003
Posts: 451
|
01-07-2005 08:17
Outlook is not a horribly unsafe email client if used correctly. Microsoft has recently addressed many security issues with Service pack 2, and also changed many default settings in Outlook to lock things down.
Just be smart about how you do things, and all will be ok. This is true for any email client.
That said, I sometimes like to check my email through a webmail client that is installed on our email server. I like SquirrelMail and Horde/IMP. The advantage is that since it runs in your browser, it takes advantage of your browser security settings, and making a mistake in downloading a malicious email is a bit harder to do.
|