Telecom and Logistics Associates 

Security NEWs Service: TLAnews

publication: Christian ALT  new6.gif (1031 bytes) TLAalert    Security Service 
Translate this page from:  Save Time and Money 

16.5.2000 SecurityMicrosoft Adds New Security Features to Outlook
Microsoft Corp.  will offer new security features, the 22 may for its Outlook e-mail program in the wake of the destructive I Love You virus.

En français: Microsoft ajoute des nouvelles fonctions de sécurité à Outlook
Microsoft propose des nouvelles fonctions de sécurité, à partir du 22 mai pour le programme de messagerie Outlook, ceci à la suite du virus I Love You



:-)

English version
 The Outlook Email Security Update, scheduled to be available for download free of charge the week of May 22, will offer three security features designed to combat viruses such as the I Love You virus that hit computers worldwide earlier this month and exploited vulnerabilities in Microsoft software.

The update includes a feature that prevents users from accessing several file types when sent as e-mail attachments, including executables and batch files that contain executable code used to spread viruses. Another feature prompts customers with a dialog box when an external program tries to access their Outlook address books or send e-mail on their behalf.

The third security measure increases the default Internet security zone setting within Outlook from "trusted" to "restricted," which disables most automatic scripting and ActiveX Controls from opening without the user's permission.

Résumé en français

La mise à jour de sécurité disponible à partir du 22 mai propose trois elements de sécurité pour combattre les virus du type I Love You.

Empecher l'utilisateur d'accèder à certains types de fichier, lorsqu'ils sont envoyés comme fichiers attachés.

Une boîte de dialogue va prevenir l'utilisateur lorsqu'un programme externe essaie d'acceder au carnet d'adresses.

La sécurité par default sera ameliorée par la troisième caractèristique qui desactivera l'execution automatique de "script", en faisant passer la securité par default de "trusted" à restricted". L'effet en étant par exemple, que les éléments "ActiveX Controls" ne seront plus executés sans  la permission de l'utilisateur.

Nous avons ajouté une notice d'Axent sur le moyen de se prevenir des worms transmis par E-mail

 

Microsoft, based here, said the security update limits certain functionality within Outlook to provide a higher level of security.

"Given the global impact of the I Love You virus and the growing threat of malicious hackers, we strongly believe we must take the unprecedented step of limiting certain popular functionality in Outlook to provide a significant, additional security option for our customers," said Steven Sinofsky, senior vice president of Microsoft Office at Microsoft, in a prepared statement.

The I Love You virus spread rapidly via an e-mail attachment that used Microsoft Outlook to send copies of itself to addresses in a user's address book. Besides clogging e-mail systems, the virus also overwrote picture and audio files. Damage from the worm and its multiple variants has been estimated at $6.7 billion.

The security update will be available for Outlook 98 and Outlook 2000 customers at http://officeupdate.microsoft.com.

 

 

      Prevent Current and Future E-Mail Worms
http://www2.axent.com/swat/News/Advisory.asp?id=2000-044

By Woody Thrower, Stan Burnett, and Gary Wahlquist - AXENT Technologies


The recent ILOVEYOU worm and its many variants (see CERT Advisory:
http://www.cert.org/advisories/CA-2000-04.html) have reminded the world
of the dangers of malicious E-mail file attachments.  Earlier, Bubbleboy
(http://www.zdnet.com/zdnn/stories/news/0,4586,2390778,00.html)
demonstrated that it is possible for E-mail to automatically execute
malicious code, even without the user opening an attachment.

The malicious possibilities of scripted E-mail are virtually unlimited.
While Microsoft has released an update
(http://www.microsoft.com/msdownload/iebuild/scriptlet/en/scriptlet.htm)
to fix the specific scripting vulnerabilities exploited by Bubbleboy,
other scripting vulnerabilities can be expected in the future. Indeed,
new scripting vulnerabilities continue to be discovered. Take a look at
what the next generation of worms might look like in a recent ZDNET
article, Mere Child's Play:
http://www.zdnet.co.uk/news/2000/18/ns-15326.html.

In spite of the latest Microsoft patches, insecurely configured Outlook
98, Outlook Express 5, and Outlook 2000 are still vulnerable to attacks.
For example, JavaScript can be embedded in E-mail sent to these clients
that automatically opens a browser window to a URL specified by the
sender. Using this method, attackers could submit form data on your
behalf, or load web pages to exploit vulnerabilities not directly
exploitable via E-mail. This vulnerability can also be used in
conjunction with the newly discovered cookie leak in Internet Explorer
(http://www.peacefire.org/security/iecookies/) that allows malicious web
sites to collect cookies from other sites.  Cookies are often used as a
form of authentication, or contain other sensitive information. If you
are using the current default configuration for Outlook 98, Outlook
Express 5, or Outlook 2000, an attacker could steal your cookies simply
by sending you E-mail.

Combined with self-replication as performed by the ILOVEYOU worm, these
vulnerabilities are truly disturbing. One unimaginative but dangerous
possibility is a self-replicating distributed denial-of-service (DDoS)
agent. Previous DDoS attacks have involved dozens, or maybe hundreds of
systems. Imagine being bombarded by a denial-of-service attack from
every ILOVEYOU victim.

A troubling, underlying issue with E-mail security is that some products
install powerful scripting capabilities by default. Most people do not
want or need scripting support in E-mail. The majority of users do not
need or want Microsoft's Windows Scripting Host enabled. Very few people
need the ability to run VBScripts by double-clicking.


Countermeasures

AXENT recommends the following countermeasures for a significantly safer
E-mail environment.

 * Disable E-mail scripting in Outlook/Outlook Express.

   Vulnerabilities in the default configuration of Outlook 98, Outlook
   Express 5, and Outlook 2000 make systems susceptible to serious
   compromise simply by viewing E-mail (without opening any
   attachments). Protect yourself by reconfiguring Outlook 98, Outlook
   Express 5, and Outlook 2000 as described in the pages listed below.
   Note: Outlook 97 does not appear to support scripting in e-mail, and
   is therefore not vulnerable.

   Outlook 98: http://www2.axent.com/swat/News/mailsecurity/O98.html
   Outlook Express 5: http://www2.axent.com/swat/News/mailsecurity/OE5.html
   Outlook 2000: http://www2.axent.com/swat/News/mailsecurity/O2000.html

 * Disable Windows Scripting Host.

   Windows Scripting Host (WSH) can be used legitimately to automate
   tasks when using the Windows operating system, but it can also be
   exploited by worms such as ILOVEYOU and Bubbleboy. Though some users
   with legitimate scripting needs may choose not to disable WSH,
   disabling Windows Scripting Host will virtually eliminate the
   possibility of accidentally executing a malicious .VBS file.

   Instructions: http://www2.axent.com/swat/News/disableWSH.html

 * Remove the VBS (Visual Basic Script) file extension from the
   Registered File Types list.

   The ILOVEYOU variety of worm requires that your system have the VBS
   extension "registered" in order to spread. If this association is
   removed, users cannot execute VBScripts by double-clicking the
   script. Remove the VBS extension from "Registered file types" for a
   more secure system. If necessary, users can still run legitimate
   VBScripts using the Wscript.exe program. Note: Other file types (such
   as .REG files) can also be dangerous, and can be removed from the
   Registered File Types list for a more secure system.

   Instructions: http://www2.axent.com/swat/News/disableVBS.html

 * Install Microsoft fixes.

   Install the Microsoft update that fixes the scriptlet.typelib/Eyedog
   vulnerabilities (these vulnerabilities allow Bubbleboy and other
   worms to work). AXENT also recommends that you install two additional
   E-mail related fixes: "Active Setup Control" Vulnerability and "File
   Access URL" Vulnerability. Check the Microsoft Security Advisor
   (http://www.microsoft.com/security/default.asp) regularly for
   Bulletins and fixes to other vulnerabilities that are published
   weekly.

   scriptlet.typelib/Eyedog update:
   http://www.microsoft.com/msdownload/iebuild/scriptlet/en/scriptlet.htm

   Active Setup Control update:
   http://www.microsoft.com/technet/security/bulletin/ms99-048.asp

   File Access URL update:
   http://www.microsoft.com/technet/security/bulletin/ms99-049.asp

 * Filter out scripts, binary executables, batch files, etc. sent as
   E-mail attachments.

   It is unlikely that many people in your organization need to be
   exchanging code by E-mail. Those who do can simply send a compressed
   copy to avoid being filtered.

 * Continue to exercise extreme caution with file attachments.

   Don't open unexpected attachments from trusted sources until you
   confirm that they actually sent them. Never open attachments from
   suspicious or unknown sources.


Resources

 * Mere Child's Play (ZDNET article on the future of worm attacks)
   http://www.zdnet.co.uk/news/2000/18/ns-15326.html

 * Frequently Asked Questions About Malicious Web Scripts Redirected by
   Web Sites
   http://www.cert.org/tech_tips/malicious_code_FAQ.html

 * CERT Advisory CA-2000-04 Love Letter Worm
   http://www.cert.org/advisories/CA-2000-04.html

 * 'Bubbleboy' Virus Propagates on Web
   http://www.zdnet.com/zdnn/stories/news/0,4586,2390778,00.html

 * Microsoft Update to Correct the 'scriptlet.typelib/Eyedog'
   Vulnerabilities
   http://www.microsoft.com/msdownload/iebuild/scriptlet/en/scriptlet.htm

 * Microsoft Security Program: Microsoft Security Bulletin (MS99-032)
   http://www.microsoft.com/technet/security/bulletin/ms99-032.asp

 * Microsoft Security Program: Frequently Asked Questions: Microsoft
   Security Bulletin (MS99-032)
   http://www.microsoft.com/technet/security/bulletin/fq99-032.asp

 * Microsoft Security Advisory Home Page
   http://www.microsoft.com/security/default.asp
      

 

 

 

 

Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: mai 16, 2000 .