- Recommend:
- 0 Comments
How Can We Stop the Spread of Worms?
Banning executable attachments is the first step, security expert says.
Automatic software security measures can ensure malicious executable and program files such as that in the latest W32/Palyh-A e-mail worm do not make it into users' inboxes, a security expert claims.
Companies that block Windows-based programs at the mail gateway will help to both prevent and reduce the spread of self-propagating viruses across the Internet, according to Paul Ducklin, Sophos' head of technology for Asia-Pacific. Ducklin's comments follow the announcement over the weekend of the latest W32/Palyh-A e-mail worm.
The offending e-mail, which purports to come from support@microsoft.com, carries a hoax Windows program with the file extension ".pif" (program information file). PIF is an older programming file type that was used in Windows version 3.1 and DOS as a shortcut for loading an application. The W32/Palyh-A attachment is accompanied by the message text "All information is in the attached file".
Although the worm is not technically malicious, opening the attachment allows the file to copy itself to the user's PC Windows folder and then send the .pif-based program to any e-mail address stored on the hard drive.
Worth the Risk?
Ducklin said the huge risks associated with accepting program files such as .pif, .vbs (visual basic script), or the more common .exe (executable) as attachments via e-mail outweighs the usefulness of distributing such files in this manner.
"There's no business sense for distributing programs via e-mail," he said.
To illustrate the point, Ducklin said six of the top 10 viruses reported to Sophos in April spread as Windows programs inside e-mails.
"By getting rid of these viruses through e-mail, you're likely to protect yourself from future worms like Palyh-A," he said.
Businesses could also block files that they don't need but which might otherwise be useful to other companies, such as .doc files, he said, as a way of reducing their virus risk.
Monitor Your Mail
But despite the introduction of many straightforward mail monitoring software products, many companies are yet to take that step and block the exchange of programs, Ducklin said.
"We continue to hear administrators saying that it would be 'unbusinesslike' to block executable e-mail attachments. What many of them seem to mean is that their users still haven't allowed themselves to be weaned off joke programs like 'frog-in-a-blender', which are commonly circulated by e-mail for amusement," he said.
"It's unfortunate that simply disallowing programs in e-mail, as a matter of corporate policy, hasn't caught on as an equally important part of 'best practice'." Ducklin also said smaller SME organizations can benefit from implementing e-mail monitoring or scanning programs in their operations.
"You don't need a terribly powerful machine [to run these programs]," he said.
Alternatively, SMEs could sign up for a similar e-mail scanning service with their ISP, he said.
Both businesses and home users should also have regularly updated antivirus desktop products in place as an "extra layer of protection" against viruses, he added.

For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Become an Android authority
Play music or games, run productivity apps and essential utilities.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- How Do I Make Web Mail My Default Email, Part 2
- Must-Have Tools and Tricks
- Free SugarSync for Outlook Handles Large File Attachments Neatly
- Stop Gmail From Downloading Too Many Messages to Your E-Mail Client
- E-Mail Strategies: Attachments, Subject Lines
- Prevent E-mail Disasters: 5 Tools to Protect You from Slip-ups
- 4 Security Tips Spurred by Recent Phishing Attacks on Gmail, Hotmail, and Yahoo
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.






















