![]() |
![]() |
|
September 22, 2003Microsoft fake emailsWent away on a shorty holiday to the interior lakes to collect my thoughts and re-energize. What do I find when I get home? 1970 fake email messages that passed spam assassin that have malicious attack codes attached. Even though Spam Assassin did catch over 300 of the messages, it still allowed WAY to many through to a single account. After spending an hour wading through the imap inbox I got it cleaned up, only to have another 75 delivered or so. That means I was getting hit with more than 1 a minute and escalating. Me thinks someone finds it funny to nail my mail server with W32.Swen.A@mm. *sigh* I fixed the problem by adding a filter in postfix to simply filter out exe files. Well, actually since I was reconfiguring the server with some pcre goodness I set it up to filter out any executable content from even entering the mail spool. I had this configured in exim for years, but when I moved to postfix I decided I would like to try it with a more lax policy as it relates to attachments. Seems if you let your guard down even a little, it will be nailed. Hard to do anything but scold myself for this one. I preach about least privilege, and then allow attachments which have no business being sent in email. Alas, we are all human. And we CAN learn from our mistakes. I sure did. So, if you feel like sending me attachments that are not compressed or encrypted with one of my public keys, it is probably going to get rejected. The fix stopped the attacks cold... with only 3 new fake emails in the last 12 hours. Much more manageable. Thank you must go out to the idiot who wrote the damn attack, as I appreciate you keeping me on my toes and making me realize that the weakest link is the human factor, and that includes me. Posted by SilverStr at September 22, 2003 07:12 AMComments
Not just you, I got a few and I'm sure others did too. Seems like you just have more people who a) use a microsoft email client b) have you in their address book and c) like clicking on executables :) As for attachments, just make sure you're not sending out a rejection as well, I get more of those going through bogofilter than I do actual spam, and it's a PITA since I'm pretty sure I'm not sending out penis enlargement ads :) Posted by: Arcterex at September 22, 2003 09:39 AM |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
December 2005
November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|