Microsoft enables admins to block all e-mail attachments

Opinion
May 30, 20054 mins

* Dangerous e-mail attachment blocking

In any list of best practices for preventing malicious attacks of your computer network, the advice “Be wary of any e-mail attachments” ranks way at the top. E-mail attachments are the most common route for computer infections. That’s why enterprise e-mail administrators are going beyond being “wary” and are becoming “ruthless” when it comes to heading off dangerous attachments. They are simply not allowing suspect attachments to enter or circulate through the corporate e-mail system.

This practice is known as “dangerous attachment blocking.” It complements the practice of virus scanning and other desktop security measures. E-mail administrators know that a virus can enter a network and do significant damage long before the countermeasures (such as an update to the anti-virus software) can be implemented. Thus, a pre-emptive strike is warranted.

In the past, we used to rely on e-mail users to use their judgment before opening up any attachments. Unfortunately, people tend to be too trusting and make decisions based on social knowledge rather than technical knowledge. That is, using logic such as “if this e-mail came from a familiar person, it must be OK to open the attachment.”  Few users want to think that a friend or colleague would send them an infected attachment. The reality today is that a malicious e-mail can come from any source – friend or foe, known or unknown, internal or external. The smart thing to do is suspect the attachment based on what it is rather than who it is from.

Microsoft gave this practice a boost when it started to include the dangerous attachment-blocking feature in products such as Outlook 2002 and later versions, Outlook Web Access for Exchange 2000, Microsoft Office Outlook Web Access 2003, and Microsoft Office XP. It is also a key feature of Windows XP Service Pack 2.  What’s more, the blocking feature is enabled by default, so even administrators who aren’t knowledgeable about it benefit from the automatic deployment of it.

Microsoft has identified some 70 or so types of file extensions that it believes could harbor dangerous executable content designed to take advantage of buffer overflows and compromise your system. File extensions on the “danger” list include:

* .bat – Microsoft batch file

* .cmd – command file for Windows NT

* .scr – screen saver (portable executable file)

* .vb – Visual Basic file

* .wsf – Windows script file

The flip side of the list is the “low-risk” category of files – the kind that cannot hold executable files that could damage your PC or network. They include .log, .txt, and .text. 

To see the extensive lists of files that Microsoft considers to be high-risk or low-risk, visit https://support.microsoft.com/?kbid=883260

An administrator who implements dangerous attachment-blocking for his organization might hear some griping from users who are accustomed to receiving files as e-mail attachments. Instead of seeing the attachment, the user might see a message that says the attachment was blocked and it cannot be accessed through e-mail. If the user really wants to receive the file, he will have to make alternate arrangements with the sender. 

There are many alternative ways to exchange legitimate files. Here are a few to suggest to users who absolutely must have their attachments.

* Host files on a Web site – rather than attaching files to e-mail messages, give the recipient a link to a Web site where he can download the attachment.

* Package the file in a zip file, then attach the zip file – dangerous attachment blocking doesn’t prevent the transmission of zip files, although this is no guarantee that the zipped file is clean.

* Use a file sharing site or service and post files there – users can download files from the shared site as needed.

Not only are these techniques useful in reducing the risk from suspect files, but they also reduce the size of files going through your e-mail system and saving bandwidth and storage space.

Following the old adage “it’s better to be safe than sorry,” it’s time to implement dangerous attachment blocking for your e-mail system now.

Linda Musthaler is vice president of Currid & Company.  You can write to her at mailto:Linda.Musthaler@currid.com