Re: Windows Virus using group posters

From: Richard (riplin_at_Azonic.co.nz)
Date: 08/12/04


Date: 12 Aug 2004 12:53:22 -0700


"JerryMouse" <nospam@bisusa.com> wrote

> Your email address absolutely does put you at risk - a mope can't send you
> malicious mail if he doesn't know, or can't guess, your email address.

It only puts 'at risk' of being sent email, some of which I wish to be
sent. The excess email doesn't put me 'at risk' of anything. It
doesn't even get into my system, I delete it on my ISP. I won't be
sending money to Nigeria, I won't be executing viruses or loading
spyware.

> All operating systems allow malware to run.

No they do not, that is a typical myth created by Microsoft
apologists. Outlook will execute code in emails, in some cases merely
by opening the mail, in others cases simply selecting it.

On other systems (or indeed using non-Microsoft email clients such as
Eudora) the email programs do not execute code, cannot execute
attachments.

> The most catastrophic attack in
> the history of the internet was propagated on Unix boxes.

Isn't it interesting that Microsoft apologists drag up the same single
incident from 20 years ago. The difference is that Unix/Linux
_learnt_ from that experience and it hasn't had any significant
repitition, while Microsoft never learnt anything and attacks continue
to happen every month.

> With the impending lock-down of XP boxes (SP2),

>From what I have read the 'lock down' is going to be of an
inconvenience to users than to the malware. It will also only take
out a small proportion of the systems. Most Windows users don't have
two clues and won't want to have 260 Megabytes come down over a 5Kb
modem connection.

> the degenerates will have to concentrate on
> Linux, OS10, BSD, and Unix systems to get their kicks.

You wish. I don't doubt that as more Linux boxes are used then there
will be a proprtion that will be security risks, simply because there
will be more dumb (ex Windows) users. But, for example, there are
considerably more Apache sites than IIS, yet IIS is attacked because
it is vulnerable.
 
> Yep. That's millions of boxes trying to get into your machine. And they only
> have to be successful once.

Well email is not a way that they could be successful. The problem
with email is Outlook and Outlook Express. There will execute
attachments which will place the vius where it wants to be. There is
no such mechanism on my machine or any Linux machine or in Windows
machines using non-Microsoft email.

> Whatever. All the more reason for you to take what steps you can to protect
> yourself.

I have, I have eliminated MS software.

> You can't do anything about the millions of MS machines attacking
> you; you can obfuscate your email address.

I don't need to. Security by obscurity does not work (or not by
itself).

> You can curse the darkness or blow out your candle. (...that doesn't sound
> right... but you get the idea)

Exactly. Stop using Outlook and IE and replace them with Eurdora (or
one of many others) and Firebird and then you can use your real email
address without risk.



Relevant Pages

  • Re: Preview pane - dangerous?!
    ... I take into the consideration if the risk outweighs the ... an attacker would have to host a Web site ... opens HTML e-mail messages in the Restricted sites zone if the Outlook ...
    (microsoft.public.outlook.general)
  • Re: Enabling macros in ThisOutlookSession / putting them elsewhere
    ... > Does signing the module still risk the possibility that some rogue code can ... I would put some minimal code statement in the Application_Startup event handler to make sure VBA is invoked when Outlook starts. ... >>> the first time the rule runs? ... >>> security risk, and if so is it different from that in question? ...
    (microsoft.public.outlook.program_vba)
  • Re: SP2 Security Holes
    ... > internet or e-mail attachment. ... The risk here is that it could be any ... > drag the file to the command window. ... > execute any file based on content rather than extension and ignore ...
    (microsoft.public.windowsxp.basics)
  • Re: SP2 Security Holes
    ... > internet or e-mail attachment. ... The risk here is that it could be any ... > drag the file to the command window. ... > fact that the command processor will execute any file based on ...
    (microsoft.public.windowsxp.basics)
  • Re: What is the best way to Invoke a java application from ASP.NET
    ... Anybody accessing the web server would be able to execute the program ... >have to give the ASPNET user execute permissions). ... what kind of risk would be raised by giving the ...
    (microsoft.public.dotnet.framework.aspnet)