Re: Blank Emails



John Gregory wrote:

Over the past week or two, I've begun receiving blank emails from unknown sources for no apparent reason. I did note that a number seemed to be originating from an edu extension in New York state. I never open then but I can tell they're blank from the preview window my Outlook 2003 Inbox. Here's the latest Xqogfkq@xxxxxxxxxxxxx I guess this is webmail.

John,

Even Microsoft doesn't have enough resources to keep up with Outlook/OE Preview Pane exploits. Don't take this the wrong way, but are you nuts? I wouldn't use a preview pane with email from people that I know, let alone from the creeps that are sending you email.

I have both Outlook and Outlook Express, but would never use them. Every month I patch them, though, since MS has been kind enough to embed them into WinXP and the Office Suite. I don't think that I can remember a month in the past year where one or the other or both didn't require some kind of fix, in many cases a critical fix. Here is an advance notice of next week's fixes:

(http://www.microsoft.com/technet/security/bulletin/advance.mspx)

Look here for all of the recent Outlook/OE exploits:

(http://secunia.com/)
(http://www.us-cert.gov/)
(http://isc.sans.org/)

And then do a Google for Preview Pane exploits and see if you can find a knowledgeable person not affiliated with MS who thinks that the indiscriminate use of the Preview Pane in Outlook/OE is a good idea.

,-----quote------

Preview pane is just as safe as opening a message (actually a bit safer, as it can't run as much active content as an opened message), especially in newer versions with all of the current windows and Outlook patches installed.

,-----endquote---

This is from an MS Outlook MVP. Sounds reassuring as hell, doesn't it? Is there any security professional in the world who recommends opening mail from unknown sources? Beam me up, Scottie! Please!

Ron :)
.



Relevant Pages

  • Re: russian e mails?
    ... which in turn opens the e mail in the preview pane ... >> I am now running in plain text mode due to your advice ... >> however i am still a bit concerned about the way outlook express views ... >> would you reccomend another mail program? ...
    (alt.computer.security)
  • Re: Evault custom form & preview pane code
    ... Set that bit on a regular message – no preview pane. ... Remove that bit from a message that has a one-off form and a script – Outlook ... Eric Legault (Outlook MVP, MCDBA, MCTS: ... Basically Enterprise vault works by trawling your mailbox, ...
    (microsoft.public.outlook.program_vba)
  • Re: Is this thing on?
    ... Outlook Express works fine for me. ... Left pane: columns for Subject, ... It's good to have a backup for Google - even though newsreaders suck. ...
    (rec.games.pinball)
  • outlook gremlins - anybody else?
    ... I am unable to replicate ... After a few minutes, Outlook will start to ... the preview pane. ... but many of my users report the same trouble. ...
    (microsoft.public.windows.server.sbs)
  • Re: Message has frozen Outlook Express and OS 9.1
    ... untick the Preview Pane option as soon as the application launches. ... a chance that you'll have to lose the contents of your Inbox in order to ... saving anything from the inbox of even the entire Outlook Express ...
    (microsoft.public.internet.outlookexpress.mac)