Security Incidents mailing list archives

RE: Possible Intrusion Attempt?


From: "Rob Shein" <shoten () starpower net>
Date: Fri, 23 May 2003 14:34:14 -0400

I'm a little fuzzy about this part...how do you prevent people from
accepting HTML mail, and considering how many mail clients out there send it
by default, what do you do when all of a sudden a large percentage of people
can't email you anymore?

-----Original Message-----
From: Whiteside, Larry [contractor] [mailto:BAE14 () SSP NAVY MIL] 
Sent: Thursday, May 22, 2003 3:31 PM
To: Matt LaFelero
Cc: incidents () securityfocus com
Subject: RE: Possible Intrusion Attempt?


<snip>

my 2 cents:

You should first stop allowing HTML email. That is one of the easiest ways
for arbitrary code to be executed on your host. Then you should revamp your
security program to teach your users not to open things from unknown
sources. As long as you allow HTML email, you can be subject to this type of
attack. 

<snip>



----------------------------------------------------------------------------
*** Wireless LAN Policies for Security & Management - NEW White Paper ***
Just like wired networks, wireless LANs require network security policies
that are enforced to protect WLANs from known vulnerabilities and threats.
Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

To get your FREE white paper visit us at:
http://www.securityfocus.com/AirDefense-incidents
----------------------------------------------------------------------------


Current thread: