Managing Internet and E-mail Threats and Security: Spam, Viruses and Securing your Computer

Understanding Email and Internet Threats and Security

Since the first electronic mail jumped between two computers on the early Internet in 1971, email has become ever more ubiquitous and essential in our daily lives. As we conduct more and more of our businesses electronically, there are ever greater numbers who wish to disrupt or exploit it. No longer content to merely damage or disturb, the newest email threats are sophisticated both in delivery and in purpose. The latest worms can perpetrate identity theft, industrial espionage and worse. It’s no longer enough to simply run virus protection; today’s email user can only win by understanding how spammers and virus writers play the game.

  1. Make sure Windows stays up to date by right-clicking My Computer.
  2. Select Properties.
  3. Completing the options under the Automatic Updates tab.

NOTE: Always install critical updates when prompted by Windows.

File Attachments

Attachments are checked for viruses by the campus anti-virus appliance and by your own anti-virus client but some viruses are too new to be detected while others may hide in .zip files. As a rule, if you’re not expecting an attachment from the sender, contact them before you open it or simply delete it. Never open attachments ending with the .exe, .pif, .rar, .scr, .bat, or .cmd extensions.

Spoofing

With anti-virus software in widespread use, a successful "Trojan Horse" virus needs to trick you in order to infect your machine. One of the ways they do this is by “spoofing,” a technique where the virus harvests the address books of an infected machine and then uses its own e-mail engine to send out copies of itself. In this way you can receive an infected e-mail from people who are not infected themselves.

Worms can also spoof addresses and portray themselves as official communication from an organization (support@binghamton.edu, administration@binghamton.edu, support@microsoft.com, accounts@chase.com). Past attempts have been clumsy, full of strange grammar and misspellings, but more recent efforts have been harder to spot.

NOTE: For the record Information Technology Services communicates using only Dateline and B-line; we never send file attachments.

Phishing

A relative of both spam and spoofing, phishing is a technique where users are directed by an official-looking email to what looks exactly like a bank, government or other web site and asked to enter data such as their credit card, social security number, ATM pin number, or other personal information for one reason or another. No business or government entity would ever require you to send it sensitive information it already possesses so treat these messages like spam and delete them. If you’re really unsure of the validity of the message call a contact number for the organization obtained from paper correspondence or the telephone book.

 

Spam

Spam

Unsolicited commercial email or “spam” is a nearly universal problem that assaults the productivity and patience of most everyone with an Internet connection.

Sources around the Internet almost uniformly agree that the word "spam" came to represent unsolicited, off-topic or otherwise annoying electronic communication based on the Spam sketch by Monty Python's Flying Circus, the 70's British sketch comedy troupe. For an exhaustive exploration of the how Hormel’s tinned pork product came to be synonymous with the flood in our inboxes, visit: http://www.templetons.com/brad/spamterm.html.

What You Can Do To Stop Spam

Though the University's spam filter stops a large amount of spam, it can’t possibly stop it all. Fortunately, there are a number of steps you can take to help stem the tide of spam!

The people who send unsolicited commercial e-mails are highly motivated by the profit potential. The famous Nigerian 419 scam, for example, managed to steal nearly $345,000 from a mere sixteen gullible people.

Spammers find ways around software filters and can nearly always reach you given a valid e-mail address. The key, therefore, is to deny spammers your personal information. Just as you probably wouldn't give out your phone number to just anybody who asked, you should be just as careful with your e-mail address. Once your email address "makes the list" expect spam for all eternity.

Some ways to protect your e-mail address include:

Unfortunately, once they’ve got you, they've got you. If your email address falls into the hands of a spammer it's tainted and will be passed around among the unscrupulous individuals and companies that produce most spam.

There are a few things you can do to avoid making a bad thing worse:

 

Computer Viruses

Computer Viruses

 "Computer viruses" are one category of "malicious software". Generally, malicious software can be divided into three different categories: "viruses", "trojan horses" and "tapeworms" (or simply "worms"). Because people have only heard of "viruses", they tend to call any sort of malicious software a virus. One of the dangers of this misuse of terminology is that people come to expect all malicious software to act like a virus. If you read about a virus that has tremendous powers, for instance, the ability to physically damage a portion of your computer, it's probably a hoax.

Virus programs seem to have a few strikes against them from the start - they pop up at inopportune times for a lengthy scan of your hard disks, they may slightly impact the performance of your computer, and they may occasionally cause conflicts with other software. Or, at least those are some of the reasons lots of folks use for not running them.

Today's computer viruses are social - they don't just want your machine, they want our whole network and will use every form of technological and sociological deception to get it:

Viruses

A computer virus is a program (a block of executable code), which attaches itself to, overwrites or otherwise replaces another program in order to reproduce itself without the knowledge of the computer user. (See chart on next page for more details.) Many viruses are comparatively harmless, and may be present for years with no noticeable effect. Some, however, may cause random damage to data files (sometimes insidiously, over a long period) or attempt to destroy files or make disks unreadable. Still others cause unintended damage. Even so-called benign viruses cause significant damage by occupying disk space and/or main memory, by using up CPU processing time, and by the time and expense wasted in detecting and removing them. One of the most famous computer viruses was the Michelangelo virus. This virus received wide attention in the media, and sent waves of panic and hysteria through the computer user community in 1992. While Michelangelo itself did relatively little damage to computer systems, the reaction to Michelangelo resulted in a lot of wasted time, effort and money.

Trojan Horses

A Trojan Horse is a program intended to perform some covert and usually malicious act, which the victim did not expect or want. It differs from a destructive virus in that it doesn't reproduce — though this distinction is by no means universally accepted. An infamous "trojan horse" is a fake version of a popular "shareware" archiving program, "PKZIP". This "Trojan Horse" first surfaced in May of 1995, but warnings about it are still circulating on the Internet.

Worms

A worm is a program, which spreads on its own. Unlike a virus, it does not attach itself to a host program. Unlike a trojan horse, it reproduces and spreads by itself. In practice, worms are not normally associated with personal computer systems. The most famous worm is probably the one set loose on the Internet in 1988 by Robert Morris, Jr. Morris’s worm was a small program, which wreaked havoc on machines across the country by overloading them with invisible tasks, preventing users from being able to use the machines effectively.

FEATURESVIRUSESTROJAN HORSESWORMS
ReproductionViruses reproduce by modifying or replacing other software. The "infected" (or "host") software then acts as a "vector", infecting other software.Trojan Horses do not reproduce.Worms reproduce on their own by making copies of themselves.
Transportation"Infected" software is transported to another computer, usually by disk or downloading, where the infection process starts again.Computer users are duped into installing Trojan Horses by claims that they do something good."Network worms" find their own way to other computers over a network. Other worms spread via "infected" disks.
DependenciesViruses function by "infecting" other software. They are essentially code fragments.Trojan Horses are self-contained programs.Worms are self-contained programs, or systems of programs.

Common (and not-so-common) Virus Terminology

Real Virus or Virus Hoax?

"Help! I've got email from a friend telling me about a terrible new virus on the Internet. It says if I read this certain email message, it will erase my hard disk and permanently damage my computer! What should I do?" Chances are you can ignore it. There are lots of hoax virus warnings out there. So many, in fact, that CIAC (U.S. Dept. of Energy Computer Incident Advisory Capability) wrote: "The Internet is constantly being flooded with information about computer viruses and Trojans. However, interspersed among real virus notices are computer virus hoaxes. While these hoaxes do not infect systems, they are still time consuming and costly to handle. At CIAC, we find that we are spending much more time de-bunking hoaxes than handling real virus incidents..."So, how can you find out if this virus warning is for real? Check out these web sites:

Email Virus Trail

Email leaves a trail wherever it goes, recorded in the header data that accompanies every message. In Outlook you can view the header data by right-clicking on the message and selecting Options from the menu. In Eudora, open the message and click the “Blah,blah,blah” button on the toolbar.

Pictured below is an Internet worm that was sent to the readers of the PEC listserv. Recipients may have thought the listserv itself was infected but the headers tell the real story.

In this example, while it appears a worm infected the pec-l listserv, it’s actually another campus machine that had permission to post to the listserv that was infected. In the example, a sender portrayed themselves as “The Binghamton.edu team”, using the spoofed address noreply@BINGHAMTON.EDU [2]. Reading down through the headers reveals that the message originated on a machine at the IP 128.226.47.91 [1]. Typically the last “Received: from” line will reveal the IP address of the sender. Finally, note the spelling and grammar [3] in the body, which is often a giveaway that a message isn’t authentic.

NOTE: You can forward infected messages to abuse@binghamton.edu and cite the IP you find in the message headers. If the message originates from a campus IP (128.226…) ITS can locate and clean the infected machine.

Typically, the last “Received: from” line in the headers will reveal the sender by their unique, numeric IP address. Reading down through the headers reveals that the message originated on a machine at the IP 128.226.47.91 [1]. From this we can determine that the infected machine was on-campus (128.226… is a campus address) and that it probably had an address book entry for the listserv that was harvested by the worm. In this example, the worm portrayed itself as “The Binghamton.edu team”, using the bogus return address noreply@BINGHAMTON.EDU [2]. Note the spelling and grammar [3] in the body, which is often a giveaway that a message isn’t authentic.

Remember: Viruses are Simply Software

When dealing with computer viruses, it's important to remember that they are software. That means:

 

Email Filtering at Binghamton University

Email Filtering at Binghamton University

Viruses, worms and spam (unsolicited commercial email) have become increasingly prevalent in electronic mail sent to the University community, some of it capable of causing damage to our infrastructure and resulting in costly downtime. In order to protect the integrity of campus computing, Information Technology Services filters incoming e-mail. All mail sent to binghamton.edu email addresses (inbound mail) is scanned and checked for e-mail borne viruses and spam. The spam filter, based on a conservative “blacklist” of known spammers, has proven successful in discarding some 55,000 unsolicited commercial e-mails each day. Since this list generally contains only the most egregious unsolicited commercial e-mail senders, some spam will make it through.

All incoming mail is scanned for viruses at the server level using McAfee anti-virus software and definition files. (McAfee for your desktop is available free from Information Technology Services at http://its.binghamton.edu/software/anti-virus)

  1. Clean mail is passed through.
  2. Infected mail is disinfected, if possible. Disinfected mail is then passed through.
  3. Infected mail that can’t be disinfected is quarantined.

All attachments to incoming mail are also screened for file extensions that are indicative of viruses and other dangerous material:

NOTE: The content of messages is not scanned. Many commercial and free software products such as Mailwasher (http://www.mailwasher.net) are available that attempt to filter unsolicited commercial email to some extent on your computer, but the efficacy of these solutions has not been adequately demonstrated.

 

Installing McAfee Anti-virus Protection Software for PCs

Installing McAfee Anti-virus Protection Software for PCs

McAfee Enterprise version 8 will install on the following Windows Operating Systems:

NOTE: Important McAfee 7 Enterprise will NOT install on Windows 95, 98 or Millenium.

Preparing your Computer for Installation of McAfee 8 Enterprise

You must be logged onto the Local Machine (not a domain such as BGM), and have an Administrator level account.

  1. Save your work and close all open applications
  2. Press Start on the lower left of your screen
  3. Select Log Off username... or select Log Off username from the Shut Down menu. Windows will close.
  4. Press <CTRL><ALT><DELETE> to login. You will be presented with your network logon window.
  5. Select your local machine from the Log On To: list. (If you do not see a drop-down list under password called Log On To:, click the Options button.
  6. Enter your Administrator username and your Administrator password. Click OK.
  1. To do this, go to -> Settings-> Control Panel -> Add/Remove Programs.
  2. The Add/Remove Programs window displays all the software currently installed on your machine. Search through this list and remove all other virus checkers including any versions of Command Anti Virus, Symantec, Norton and McAfee.
  3. Click the Remove button to remove each selected item of software.
  4. Restart your computer.
  5. Your machine will now be functioning without a virus scanner, so be sure to install the new one before you do anything else. (Save all your work and close all programs before beginning installation.)
  6. Go to the Binghamton University ftp site, (ftp://ftp.binghamton.edu/pub/windows/virus-protection/) and double–click in the McAfee8 folder.
  7. Double-click on the McAfee8.exe file to run the executable.
  8. A splash screen will appear and then disappear and the installation will proceed in the background.
  9. You will know the installation is complete when the McAfee icon appears in your system tray in the lower right-hand corner of your computer screen.
  10. McAfee is now protecting your computer. It will update the virus definition files every hour of every day.

NOTE: If the Update process fails following installation, restart your computer and then right-click the McAfee icon on your system tray. Choose Update Now from the menu.

 

Installing Virex Anti-virus Protection Software for Macs

Installing Virex Anti-virus Protection Software for Macs

Installing Virex

  1. Go to http://its.binghamton.edu/software/anti-virus.
  2. Under Macintosh - Virex Software, click on the appropriate link for your operating system. Download and unzip/unstuff the file.
  3. Double-click the software icon to start the Installer and follow the on-screen steps to install the software.
  4. Read and accept the license agreement. If you do not accept the license agreement, the installation cannot continue.
  5. Click Install to perform the Installation. The Authenticationdialog box appears. Enter your Administrative username and password and click OK.
  6. When the Installer finishes, it notifies you with a dialog box recommending you perform an On-Demand scan. Click OK.
  7. Click Restart to complete Virex installation. This will ensure that Virex starts properly. Virex is now located in your computer's Applications folder.

To Update Virex Manually:

  1. Double-click on the icon for the Virex application.
  2. Click on the eUpdate icon in the upper right hand corner of the main Virex window.
  3. Virex will contact their home office for a copy of the latest "signature file" including all the latest viruses, worms, and Trojan horses.
  4. When it is finished, Quit the application.

To Schedule eUpdates for Virex:

  1. From the Virex Schedule menu, choose Edit Schedule.
  2. Click the Add button in the lower left hand corner of the Schedule Editor window.
  3. Press (and hold) the button labeled Diagnose to reveal a pop-up menu.
  4. Choose eUpdate from this menu.
  5. Press (and hold) the button labeled After Startup and choose At Specific Time from the pop-up menu.
    • Check to see that the eUpdate event will run monthly. Adjust the date field to show the 1st or 2nd of the month.
    • Adjust the time field so it shows a relatively early time. This is suggested so that at the beginning of each month, your Virex will check for a new signature file when you turn on your Mac.
    • Click on the name of the event, and change it to a name you will recognize. I.e.: Monthly update.
  6. Click Save.
  7. From the File menu, choose Quit. Your Virex will now keep itself up-to-date every month.

 

5 Easy Steps to Securing Your Computer

5 Easy Steps to Securing Your Computer

  1. Install virus protection software, such as McAfee and Virex, on your computer. McAfee and Virex are available free from http://security.binghamton.edu.
  2. Make sure that all critical security patches for your computer’s operating system are applied.
    • For Windows: It is recommended that all users keep their Windows machines "patched". Because bugs are constantly discovered in much of the complex computer software we use, patches for these mistakes are periodically made available. Most Windows user should find a link to Windows Update at or near the top of their Start menu. You can also go to http://windowsupdate.microsoft.com. Download and install any critical updates that Windows Update suggests you need. Remember to run Windows Update at least once a month.
  3. If you use peer-to-peer file sharing services (such as Kazaa), disable sharing of files on your computer.
  4. Secure all accounts and passwords used by your computer.
  5. Disable file and print sharing.