Simple question... is is possible to get a virus from reading an email
message? My thought is that since a virus is 'code' it would have to be
'executed'. Mail messages are just text files that are 'read'. Is my
assumption correct? Thanks!
--Tom
<*>----<*>----<*>----<*>----<*>
Thomas Connolly
tcon...@umabnet.ab.umd.edu
Webmaster - Joe Gibbs Racing Online!
http://www.git.net/jgr/
"Why is Christmas like a day at the office?
You do all the work and the fat guy in the
suit gets all the credit."
In <Pine.A32.3.94.961206...@umabnet.ab.umd.edu>, Thomas Connolly <tcon...@umabnet.ab.umd.edu> writes:
>Simple question... is is possible to get a virus from reading an email
>message? My thought is that since a virus is 'code' it would have to be
>'executed'. Mail messages are just text files that are 'read'. Is my
>assumption correct? Thanks!
Congratulations ! You are the 100.000th a.c.v. poster to ask this question.
Since your assumption was correct, you qualify for our Grand-Prize
Sweepstake.
(1st prize is one Doren Rosenthal Virus Simulator,
2nd prize is two Doren Rosenthal Virus Simulators,
3rd prize is three Doren Rosenthal Virus Simulators)
Pierre Vandevenne, http://www.datarescue.com
Simple answer... :-)
>is is possible to get a virus from reading an email
>message?
From the mini-FAQ:
* Note that you cannot catch a virus simply by reading certain e-mail or
newsgroup messages. For a virus to spread, infected code must be run.
>My thought is that since a virus is 'code' it would have to be
>'executed'. Mail messages are just text files that are 'read'. Is my
>assumption correct? Thanks!
Your assumption is correct. It'd be a good idea to read the FAQ's before
posting next time around, though.
Regards,
George Wenzel
--
("`-''-/").___..--''"`-._ George Wenzel
`6_ 6 ) `-. ( ).`-.__.`) <gwe...@gpu.srv.ualberta.ca>
(_Y_.)' ._ ) `._ `.``-..-' Club Secretary,
_..`--'_..-_/ /--'_.' ,' University of Alberta Karate Club
(il),-'' (li),' ((!.-' http://www.ualberta.ca/~gwenzel/
Talking of whom... where's he disappeared to? What happened to all the
media coverage it was about to get? Who wrote the EICAR test file?
These and other questions should be answered.
Regards
Graham
---
Graham Cluley CompuServe: GO DRSOLOMON
Senior Technology Consultant, UK Support: sup...@uk.drsolomon.com
Dr Solomon's Anti-Virus Toolkit. US Support: sup...@us.drsolomon.com
Email: gcl...@uk.drsolomon.com UK Tel: +44 (0)1296 318700
Web: http://www.drsolomon.com USA Tel: +1 617-273-7400
NEW:Evaluate Dr Solomon's FindVirus 7.66! Download it from our webpage
In very loose terms it is possible.... if you open a WORD.DOC file received
via a file attachment that contains a macro virus you can get infected.
Thomas Connolly <tcon...@umabnet.ab.umd.edu> wrote in article
<Pine.A32.3.94.961206...@umabnet.ab.umd.edu>...
> Hello All!
>
> Simple question... is is possible to get a virus from reading an email
> message? My thought is that since a virus is 'code' it would have to be
[virus by eMail]
>In very loose terms it is possible.... if you open a WORD.DOC file
received
>via a file attachment that contains a macro virus you can get infected.
Even then, you have to use a program that understands the Macros, i.e.
MS-Word.
WordPad, EDIT, etc. will not cause the virus to become active (though you
will of course spread it on to others when you give away copies of the
infected file)
Bye! Stefan
>Actually....
>
>In very loose terms it is possible.... if you open a WORD.DOC file received
>via a file attachment that contains a macro virus you can get infected.
>
>Thomas Connolly <tcon...@umabnet.ab.umd.edu> wrote in article
><Pine.A32.3.94.961206...@umabnet.ab.umd.edu>...
>> Hello All!
>>
>> Simple question... is is possible to get a virus from reading an email
>> message? My thought is that since a virus is 'code' it would have to be
>> 'executed'. Mail messages are just text files that are 'read'. Is my
>> assumption correct? Thanks!
>
Right ... but ( ;-) ) if is a macro-virus you can be "infected" by
viewing a Worddokument, 'cause the macro is integretated in the
doc-file
cu
Scylla
Wow. An intelligent question.
Mail messages WERE text code that were harmless. That was then, and
this is now.
As I read your mail, I have 3 or 4 html hotspots on almost every email
message I see. Those hot spots can send me packing OR they can reformat
my hard disk. I'm still safe since I can choose NOT to click on them,
right? Wrong!. I have been to home pages that checked my clock against
wwv time and offered to update my clock. All without me doing anything.
You say, well thats the web and this is email. Remember those
hotspots(urls) I talked of earlier. Many of them take me to homepages
which check my clock which
......
Besides that, the web and email ride on the same packet mechanism and
the line between is getting fuzzier by the
day.
And what about attachments. Do you always have to click on something
to get the attachments. Not on my machine. I have an option in Eudora
to automatically download so I expect there are dozens of readers that
automate the whole
process.
Finally, and this is most important. Who wrote the email program you
are using? Could they have written it so that it automatically follows
the urls and executes activex and java scripts? Sure, why not. It's
easy.
-------------------==== Posted via Deja News ====-----------------------
http://www.dejanews.com/ Search, Read, Post to Usenet
> As I read your mail, I have 3 or 4 html hotspots on almost every email
>message I see. Those hot spots can send me packing OR they can reformat
>my hard disk. I'm still safe since I can choose NOT to click on them,
Hmmm, how do html hot spots (I guess you mean URL) format hard disks ?
If they do, why are they dangerous in e-mail and not when you browse ?
>You say, well thats the web and this is email. Remember those
>hotspots(urls) I talked of earlier. Many of them take me to homepages
>which check my clock which
cuckoo ! cuckoo ! said the page...
> Besides that, the web and email ride on the same packet mechanism and
>the line between is getting fuzzier by the
Good point : the packet mechanism is called TCP/IP and is used rather
widely nowadays. It is not really dangerous or fuzzy as such.
> And what about attachments. Do you always have to click on something
>to get the attachments. Not on my machine. I have an option in Eudora
>to automatically download so I expect there are dozens of readers that
>automate the whole process.
Could be. But do they execute ? You still have the choice not to execute.
> Finally, and this is most important. Who wrote the email program you
>are using? Could they have written it so that it automatically follows
>the urls and executes activex and java scripts? Sure, why not. It's
>easy.
Easy ? Please write an e-mail program with all those nifty features,
with real agents, build in search engine. I'd like a JIT compiler too
BTW.
When you have done that, you'll be allowed to call me a customer !
Pierre Vandevenne, http://www.datarescue.com
E-mail messages still are plain text that is harmless.
> As I read your mail, I have 3 or 4 html hotspots on almost every email
>message I see.
What's the point? HTML links can point to viruses or other malware, but
you still have to download that malware manually, and you have to run it
once downloaded. Not a big deal.
>Those hot spots can send me packing OR they can reformat
>my hard disk.
Hogwash.
>I'm still safe since I can choose NOT to click on them,
>right? Wrong!.
Wrong.
>I have been to home pages that checked my clock against
>wwv time and offered to update my clock. All without me doing anything.
So what? Updating your clock is one thing, reformatting your hard drive
is another. Please post the addresses of these sites - I'd like to check
them out.
>You say, well thats the web and this is email. Remember those
>hotspots(urls) I talked of earlier. Many of them take me to homepages
>which check my clock which
You're speculating here, but you're not providing any evidence to back
your claims.
> Besides that, the web and email ride on the same packet mechanism
This is irrelevant. You can transfer mac viruses and IBM viruses on
floppies (the same packet mechanism) but that doesn't mean they're the
same thing.
>and
>the line between is getting fuzzier by the
>day.
Nope. TCP/IP is pretty much the same thing it was yesterday, and the day
before.
>
> And what about attachments.
These have to be executed to be dangerous (automatic execution of
attachments is possible with some e-mail programs, but it's not set as a
default).
>Do you always have to click on something
>to get the attachments. Not on my machine. I have an option in Eudora
>to automatically download so I expect there are dozens of readers that
>automate the whole
>process.
A file downloaded to your machine is harmless unless you execute it.
Considering most people don't go about execuring files in their
attachments directory, this is not a big deal.
>
> Finally, and this is most important. Who wrote the email program you
>are using?
Damned if I know. I know the folks that wrote my news program, though.
Nice guys.
>Could they have written it so that it automatically follows
>the urls and executes activex and java scripts? Sure, why not. It's
>easy.
There's a difference between _could_ and _would_. There isn't a need for
an e-mail program to surf the web for you - it's not really in the
parameters of an e-mail program. Once again, you're speculating without
providing evidence.
Hiya George.
Umm, this can be somewhat misleading. I have a few programs that can take a
binary file (netrun being an excellent example) and turn it into plain ascii
text. Looks sort of like viewing RIP without a RIP viewer. This "harmless"
text however is very much executable. The user would of couse have to
execute the text to infect him/herself.. However, you might want to alter
the plain text part just a tad.
>In article <Pine.A32.3.94.961206...@umabnet.ab.umd.edu>,
> Thomas Connolly <tcon...@umabnet.ab.umd.edu> wrote:
>> Hello All!
>> Simple question... is is possible to get a virus from reading an email
>> message?
> Mail messages WERE text code that were harmless.
> As I read your mail, I have 3 or 4 html hotspots on almost every email
>message I see. Those hot spots can send me packing OR they can reformat
>my hard disk. I'm still safe since I can choose NOT to click on them,
>right? Wrong!. I have been to home pages that checked my clock against
>wwv time and offered to update my clock. All without me doing anything.
>You say, well thats the web and this is email. Remember those
>hotspots(urls) I talked of earlier. Many of them take me to homepages
>which check my clock which
> ......
This clock changing is not a virus, but a trojan. It doesn't reproduce
and spread. It is also an executable program that probably could not
run on your PC or Mac, but only on the server. . . e.g. the "virus"
cannot leave the server. Sure, it could cause problems for your PC or
Mac, but these problems would be solved by rebooting your PC and
undoing the changes made. Problem solved.
> And what about attachments. Do you always have to click on something
>to get the attachments. Not on my machine. I have an option in Eudora
>to automatically download so I expect there are dozens of readers that
>automate the whole process.
The user has still made the choice to download indescriminately.
Precisely why it is a bad idea to set your PC up this way.
> Finally, and this is most important. Who wrote the email program you
>are using? Could they have written it so that it automatically follows
>the urls and executes activex and java scripts? Sure, why not.
You are possibly right about active-x making things more dangerous,
but still 1) this is not a virus, but a trojan, it cannot spread to
other PCs, and 2) I would say your examples are not a part of email,
but email attachments. You COULD click on a link to download a Word
document, open up Word and get a Word virus. Word is not email.
Ditto HTML pages.
______________________________
karl & julie pulledmints
mi...@mnsinc.com
You are cordially invited to visit the Pulled Mints website!!
http://www.mnsinc.com/minty/index.html
Pulled Mints is a zine about Don Knotts, Windows 95, and sex
toys you can make with household items.
Hello!
>
>Umm, this can be somewhat misleading. I have a few programs that can take a
>binary file (netrun being an excellent example) and turn it into plain ascii
>text.
Yes, I'm aware of this. Regardless, it's quite difficult for an e-mail
program to do anything with the text to make it dangerous.
>Looks sort of like viewing RIP without a RIP viewer. This "harmless"
>text however is very much executable. The user would of couse have to
>execute the text to infect him/herself.. However, you might want to alter
>the plain text part just a tad.
The above statement is still quite valid. Text, in whatever form, sent
to somebody via e-mail, is harmless in its current state. It takes
effort on the user's part to turn the text into something dangerous, so
it's not a concern. Harmless.
> A file downloaded to your machine is harmless unless you execute it.
> Considering most people don't go about execuring files in their
> attachments directory, this is not a big deal.
This is true in general. However there are some interesting bugs in a
number of
popular Win95 Email readers that can be exploited that make Email messages
themselves
be "malware". Here are a few real world examples:
If the hot link "file:///aux" appears in an Email message and it is clicked
on in the Windows 95 version of Netscape Navigator, Navigator will go into
an infinite loop. Attempting to shutdown Navigator with CTl-ALT-DEL
can crash Windows 95. This bug is present in Navigator 2.0 and 3.0 and
fixed in 3.01.
If "file:///aux" is used in an HTML tag (ie., <img src="file:///aux">) and
sent
in an HTML attachment to an Email message, Navigator will die when the
Email message
is read.
The Windows 95 version of Eudora 3.0 has a more serious problem. If an
attachment
named AUX is sent from a Macintosh, Eudora 3.0 for WIn95 can get all
confused
and can't read mail again until the offending message is deleted.
Richard
> > Finally, and this is most important. Who wrote the email program you
> >are using? Could they have written it so that it automatically follows
> >the urls and executes activex and java scripts? Sure, why not. It's
> >easy.
>
> Easy ? Please write an e-mail program with all those nifty features,
> with real agents, build in search engine. I'd like a JIT compiler too
> BTW.
The Email reader in Netscape Navigator automatically shows HTML attachments
when an Email message is read. This feature is on by default, but can be
turned off from a menu option.
Here a number of implications:
1). Javascript programs are executed simply by reading an Email message.
Javascript is notorious buggy. A denial service attack is possible simply
by going into an inifite loop in a Javascript program that puts up an alert
box. There is no way in Navigator to break out of the infinite loop except
to shutdown Navigator with a CTL-ALT-DEL. If an attacker has a sense of
humor, they can put a message in the alert box saying that the "Good Times"
virus has been detected on the system and would the user like to
disinfect......
2). Java programs are executed if an Internet connection is active at the
time
the Email message is read. No problem right? All of the Java security
leaks
have been fixed.........
3). Including the HTML tag <img src="file:///aux"> in an HTML attachment
will
crash the Windows 95 version of Navigator. Attempting to shudown
Navigator can also takedown Windows 95.
Richard
In <01bbf024$63d4cd00$a781...@tiac.net.tiac.net>, "Richard M. Smith" <r...@pharlap.com> writes:
>Here a number of implications:
What you describe can mostly happen when you access
a web page. Aren't we supposed to talk about viruses in e-mail ?
Some mail readers have browser features, so what ?
(has anyone figured out how to send an e-mail that shows the
content of a local hard disk ? ;-) ;-))
Is browsing so dangerous that we should worry when e-mail
links to it ?
You could also have the mailto: send hundreds of 100 kb
messages or thousands of 1MB message. You could also
compress a 250 MB empty file in a 10 kb attachment.
Etc... Etc...
But malware, denial of service or misbehaviour isn't
equivalent to "virus".
Pierre Vandevenne, http://www.datarescue.com