Re: Spam, a security risk?

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 07/10/03


Date: Thu, 10 Jul 2003 17:33:29 -0400


...actually, to add to your response, there is a security risk, but the
messenger spam is merely a useful warning of another larger one - that ports
on the computer are open from the Internet.

.Lionel Fourquaux wrote:
> "Terance Muller" <terancem@surebondinternational.com> a écrit dans le
> message de news:01e801c3471c$858a36f0$a501280a@phx.gbl...
>> Is there any truth to this
>> claim, or is this just their sales pitch to get you to
>> buy a product???
>
> It's true, but it doesn't mean you have to buy anything.
>
> Spammers are (mis)using a built-in Windows service that
> was designed to transmit messages from the administrator
> to users on a computer. It's quite easy to disable this:
> stop the Messenger service (not the Messenger Application:
> there is no connection between these two, except the name.
> I'm speaking of a WinNT service, a special kind of program
> that runs in the background). Of course, you may not want
> to do it if you are actually using this service normally. In this
> case, you should set up a firewall to block incoming connections
> to the Messenger service.
>
> It's one more annoying form of spam, but this one is really
> quite easy to avoid. As far as I know (and, of course, provided
> there is not security bug in the service), there is no real security
> risk in this. (Of course, if spammers can access this service on
> your computer, it's quite likely that one can access several other
> unneeded server programs, possibly with nastier security
> implications in some cases. Shut them down or set up a firewall).
>
> Hope this helps.
>
> -- Lionel Fourquaux



Relevant Pages

  • [NT] MSN Messenger OCX Buffer Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Messenger OCX. ... Microsoft signed OCX. ... accept the pop-up "Install Now" signed by Microsoft. ...
    (Securiteam)
  • Re: windows security bulletin
    ... > Important windows security bulletin,buffer overrun in messenger ... messenger service, as some people recommend, only hides the symptom, ... Messenger Service of Windows ... Disabling the messenger ...
    (microsoft.public.windowsxp.general)
  • Re: Pop up Messages
    ... Are you trying to give people a false sense of security by ... advice, however well-intended, was to turn off the warnings. ... to completely get rid of messenger popups, ... >>messenger service are misinformed at best. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Why does Microsoft make things so difficult?
    ... answer was because Messenger and it's variants are imbedded into the ... OS when they should be independent stand alone utilities that are more ... independently evaluated by security minded professionals. ...
    (microsoft.public.windowsxp.messenger)
  • Re: Hiding IP in E-Mail..
    ... >>to get around having your IP show, use a web mail service and a proxy to ... >>header for good reason, you shouldn't try and get around this. ... It's only a security risk if your system or network is at risk. ...
    (Security-Basics)