E-mail (and spam) senders trick you into loading a virus in the following ways: Pretend to be from someone you know and trust Hide the fact that an attachment is executable Offer help handling virus infections Include HTML code to activate programs located on Web sites
142 Part II Practicing Safe Broadband
When you get an attachment you don t expect, verify the sender and ask that person about the le you received. If the person sent it on purpose, you ll have no problem. If that person has no idea that an e-mail with an attachment came bearing their address, both of you need to disinfect your systems. Don t open attachments if they are executable les. You can tell this by checking their le extension (the letters to the right of the dot at the end of the le name). Unless you are positive the sender and les are trustworthy, do not click the attached les. Files with the following extensions can cause problems by executing when you open them:
.bat .com .exe .pif .reg .vb .vbs
When you look at the les on your computer, you will notice many of your les have these extensions and the les are trustworthy. Your operating system and all your applications rely on these le types. However, when you click an unexpected le in an e-mail message, the application will begin working so quickly your system will be compromised before you can react.
Protecting yourself
Microsoft Windows hides the extensions from you by default. This setting makes it easier for virus attachments to get by users. Change this setting immediately. Go to Start; then open the Control Panel and choose Folder Options View, to see the selection options shown in Figure 7-1. The check box is named Hide Extensions for known le types and that s what it does. If Windows believes it knows what type of le the extension describes, you ll never see the extension. Devious virus writers try and fool users by hiding the le extension of an executable program. Windows, in all recent versions, lets you have periods in the lename. If your Windows settings hide extensions (by default) the virus may come inside a program named Jokes.txt.exe. The le extension, the letters after the last period, remains hidden by Windows, so users think a text le of jokes can t cause them any harm. After you clear the check box shown in Figure 7-1, you ll see the entire lename and realize the trick. Any program with a le extension from the list before Figure 7-1 might wreak havoc and even go so far as to erase all your data and reformat your hard disk if allowed to run. Many attackers aim at Microsoft s Outlook and Outlook Express e-mail applications for the following reasons:
7 Understanding Computer Security
Figure 7-1: Make sure the box the arrow points to is unchecked.
The majority of personal computer users rely on them. Microsoft opens application interfaces so one program can change data for other programs. You can t blame Microsoft s problems on lack of market penetration and dominance. The minute Microsoft included an e-mail and Web browser application in its operating systems, it took over the market share lead. If you re a hacker or virus monger, you want to attack the leading programs to make more of a splash. You can blame Microsoft for building in all types of programming hooks between their e-mail client (Outlook and Outlook Express), browser (Internet Explorer), address book, and execution support for Visual Basic. Any code in any program within the Windows operating systems and the Of ce application suite can trigger actions in other programs without requiring security checks or authentication. The handy way you can send someone an e-mail and have it show up on their calendar. Viruses use the same tricks to read your address book and launch malware-laden e-mails with your name as sender and return address.
