E-Bitz SBS MVP - Tech Bitz
The ramblings of a Part-Time Network Admin trying to stay safe in the CyberWorld











Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Thursday, March 21, 2002
 

If you receive an email from Microsoft with an attached email.....it is NOT from Microsoft.

THIS IS NOT FROM MICROSOFT! We DO NOT send security fixes by email and    we donot have an MS Internet Security Center. For more information, please see:


http://www.sophos.com/virusinfo/analyses/w32gibea.html

 <Start False Email>
 ==============
Microsoft Customer,

this is the latest version of security update, the

"2 Mar 2002 Cumulative Patch" update which eliminates all known security vulnerabilities affecting Internet Explorer and MS Outlook/Express as well as six new vulnerabilities, and is discussed in Microsoft Security Bulletin MS02-005. Install now to protect your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer.

Description of several well-know vulnerabilities:

 - "Incorrect MIME Header Can Cause IE to Execute E-mail Attachment"
vulnerability. If a malicious user sends an affected HTML e-mail or
hosts an affected e-mail on a Web site, and a user opens the e-mail or visits 
the Web site, Internet Explorer automatically runs the executable on the 
user's computer.

 - A vulnerability that could allow an unauthorized user to learn the
 location of cached content on your computer. This could enable the
unauthorized user to launch compiled HTML Help (.chm) files that
contain shortcuts to executables, thereby enabling the unauthorized user to 
run the executables on your computer.

 - A new variant of the "Frame Domain Verification" vulnerability could
enable a malicious Web site operator to open two browser windows, one
in the Web site's domain and the other on your local file system, and to pass
 information from your computer to the Web site.

 - CLSID extension vulnerability. Attachments which end with a CLSID
file extension do not show the actual full extension of the file when saved 
and viewed with Windows Explorer. This allows dangerous file types to  
look as though they are simple, harmless files - such as JPG or WAV files - that do not need to be blocked.

System requirements:

 Versions of Windows no earlier than Windows 95.

 This update applies to:

Versions of Internet Explorer no earlier than 4.01

Versions of MS Outlook no earlier than 8.00

Versions of MS Outlook Express no earlier than 4.01

How to install

Run attached file q216309.exe

How to use

You don't need to do anything after installing this item.

For more information about these issues, read Microsoft Security
Bulletin  MS02-005, or visit link below.
http://www.microsoft.com/windows/ie/downloads/critical/default.asp

If you have some questions about this article contact us at
rdquest12@m...

Thank you for using Microsoft products.

With friendly greetings,

MS Internet Security Center.

 ----------------------------------------

 ----------------------------------------

 Microsoft is registered trademark of Microsoft Corporation. Windows
and Outlook are trademarks of Microsoft Corporation.

                </End False Email>

This email's attachment will infect your computer with the GIBE virus that leaves behind a back door.


10:17:15 PM    
comment



Click here to visit the Radio UserLand website. © Copyright 2002 E-Bitz - MS Small Business Server MVP.
Last update: 3/21/2002; 10:17:18 PM.
This theme is based on the SoundWaves (blue) Manila theme.
March 2002
Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31            
Feb   Apr