Full Disclosure mailing list archives

Re: Administrivia: Testing Emergency Virus Filter..


From: Valdis.Kletnieks () vt edu
Date: Wed, 20 Aug 2003 11:09:58 -0400

On Wed, 20 Aug 2003 09:39:21 CDT, "Schmehl, Paul L" said:

Do you really believe this?  I don't.  One only has to look at the Sobig
outbreak yesterday to realize that some subset of the 100% of users out
there will execute an attachment *despite* being repeatedly warned about
the dangers.  My God, when all you have to do is put "See attached file"
in the body and people *still* execute the virus, it becomes self
evident that *no* amount of education is going to completely solve the
problem.

Have to admit that mimail did a good social engineering job - when it gets sent
from 'admin@<yourdomain', and says "Your account is about to expire, see the
attachment for details", a lot of otherwise clued people will bite.

Of course, the *average* e-mail user doesn't understand the distinction between
"internet" and "web", even after you point out that e-mail isn't web....

In April 1951, Galaxy published C.M. Kornbluth's "The Marching Morons".
The intervening years have proved Kornbluth right.

Attachment: _bin
Description:


Current thread: