GFI
English Deutsch Français Italiano Nederlands Español
Unternehmen > News > 2001 > Mail essentials protects against dangerous...

Mail essentials protects against dangerous security hole

Innocent-looking attachments may actually be harmful files

London, UK, 11 July 2001 - GFI, leading developer of email content checking & anti-virus software, warns that not all innocent-looking email attachments are actually harmless. Thanks to a dangerous new exploit, email attachments containing scripts (for example, vbs) can be disguised as text (.txt) files by using the CLSID of the extension instead of the actual file extension. Mail essentials, GFI's email content checking and anti-virus solution, detects files which have a CLSID extensions, and quarantines script files, even if they are disguised as .txt files.

Detects hidden attachment extensions
Through its file-checking module, Mail essentials for Exchange/SMTP automatically quarantines all mails containing attachments with CLSID extensions. It does this by matching all attachment extensions against a CLSID format pattern - {xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx} - where x is any alphanumeric character.

Windows hides CLSID extensions, so a malicious user can disguise a CLSID extension as any file type, such as a seemingly harmless text file. This is because CLSIDs are used to associate files with Windows applications, and in the same way an extension can be associated instead (e.g., a .txt file). This means one can create a file called 'testdoc.txt.{00020906-0000-0000-C000-000000000046}' which will be opened by MS Word. The user who receives such a file by email is likely to think it is a simple .txt file. An executable could similarly be disguised as a .jpg or .gif file, for instance. This is because CLSIDs exist for VBS, HTA and other dangerous applications.

There is no practical reason for someone to send a file with such an extension. So if such an attachment is sent by email, it will most probably have been done deliberately and with malicious intent, posing a great security risk.

As no patches have yet been issued against this exploit, the only way to protect the corporate network against such a threat is to have adequate protection at email server level. By using Mail essentials for Exchange/SMTP, organizations are protected from malicious CSLID files because the product detects and blocks them before they can reach the user, who could innocently trigger a virus by double-clicking on such a file.

For more information about this security hazard, please read the security advisory hosted at this link: http://www.guninski.com/clsidext.html.

About Mail essentials
Mail essentials is the market-leading email content checking solution with more than 10,000 servers sold since its launch. It removes all types of email-borne threats before they can affect an organization's email users. Spam, viruses, dangerous attachments and offensive content can be removed before they reach the corporate mail server. More information can be found at http://www.gfi.com/me/index.html. Pricing starts at US$350 for 10 users.

Über GFI
GFI Software bietet als führender Software-Hersteller eine umfassende Auswahl an Netzwerksicherheits-, Inhaltssicherheits- und Kommunikationslösungen aus einer Hand, um Administratoren einen reibungslosen Netzwerkbetrieb zu ermöglichen. Mit seiner mehrfach ausgezeichneten Technologie, einer konsequenten Preisstrategie und der Ausrichtung an den Anforderungen kleiner und mittlerer Unternehmen erfüllt GFI höchste Ansprüche an Effizienz und Produktivität. Das Unternehmen wurde 1992 gegründet und ist mit Niederlassungen auf Malta sowie in London, Raleigh, Hongkong, und Adelaide vertreten und betreut über 200.000 Installationen weltweit. GFI bietet seine Lösungen über ein weltweites Netz von mehr als 10.000 Channel-Partnern an und ist Microsoft Gold Certified Partner. Weitere Informationen stehen zum Abruf bereit unter http://www.gfisoftware.de.

Alle hier aufgeführten Produkte und Firmennamen sind Marken der jeweiligen Eigentümer.



 Infos zum Produktangebot von GFI
>  GFI MailEssentials for Exchange/SMTP
>  GFI MailSecurity for Exchange/SMTP
>  GFI MailArchiver for Exchange
>  GFI FAXmaker for Exchange/SMTP
>  GFI LANguard Network Security Scanner
>  GFI EventsManager
>  GFI EndPointSecurity
>  GFI Network Server Monitor
>  GFI WebMonitor for ISA Server

   © 2008. Alle Rechte vorbehalten. GFI Software Home Produkte Download-Versionen Support Bestellungen Sitemap Über GFI Kontakt