I guess that's why we still run the clearswift tools
(mailsweeper/mimesweeper) on the proxy and mail filters. These will
unpack embedded objects to a depth of 50, and quarantine any password
protected files so they can be manually vetted....
Dave Wade
________________________________
From: Brown, Larry [mailto:[email protected]]
Sent: 10 December 2010 13:28
To: MS-Exchange Admin Issues
Subject: RE: Embedded executables in Word Docs
I misspoke...not "run the file from Outlook"...I meant "run the
file from Word".
Larry
From: Brown, Larry [mailto:[email protected]]
Sent: Friday, December 10, 2010 8:25 AM
To: MS-Exchange Admin Issues
Cc: McCready, Rob; Bohn, Rick
Subject: Embedded executables in Word Docs
Exchange 2007 with 1 CCR & 2 Hubs internally and 2 Edge
Transports on a DMZ. Client: Outlook 2007
We block a whole list of attachments (.exe, .bat, .com, etc)
from entering the domain. Internally, Outlook keeps users from seeing
"dangerous" files if they are sent as attachments.
So I was gob-smacked yesterday when someone showed me that they
could embed a .exe in to a Word doc and send it both internally and
externally...and then run the file from Outlook.
Maybe this is a known issue with an easy fix, but it was news to
me. I've done a couple of searches with Google and nothing has turned
up.
I'm assuming that a known virus will still get caught by our AV.
What worries me is a new scam with an embedded virus saying, "Click me
to see the pretty pictures" or some such silliness.
Is there a way to block Word attachments with embedded files?
Larry C. Brown
LAN/WAN CS Support
Dayton Power & Light
(937)-331-4922
---
To manage subscriptions click here:
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe exchangelist
---
To manage subscriptions click here:
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe exchangelist
**********************************************************************
Stockport Council, in partnership with the Police, have launched the Safer
Stockport initiative to show how working together with local communities can
help to create safer places in which to live, work and visit. To find out how
you can get involved, visit http://www.stockport.gov.uk/safer
This email, and any files transmitted with it, is confidential and
intended solely for the use of the individual or entity to whom they
are addressed. As a public body, the Council may be required to disclose this
email, or any response to it, under the Freedom of Information Act 2000,
unless the information in it is covered by one of the exemptions in the Act.
If you receive this email in error please notify Stockport ICT, Business
Services via [email protected] and then permanently remove it from
your system.
Thank you.
http://www.stockport.gov.uk
**********************************************************************
---
To manage subscriptions click here:
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe exchangelist