GFI
English Deutsch Français Italiano Nederlands Español
GFI SecurityLabs > News 2000 > GFI protects against email security hole c...

GFI protects against email security hole created by HTML mail & IE5

Traditional anti-virus programs provide no defense against this new threat!

London, UK, 21 July 2000 - GFI, a leading developer of email security & anti-virus software, today announced that it offers a solution to the new breed of email viruses that can spread without the user opening an email attachment. GFI's email content checking tool, Mail essentials, can be used to protect against this dangerous new threat at email server level.

"In line with security experts' predictions, each new generation of email viruses becomes more dangerous and harmful, making it necessary for organizations to tighten their email security. Now, a newly discovered vulnerability can be exploited to transmit email viruses that no longer rely on the email attachment to be opened in order to be activated," explained Nick Galea, GFI CEO.

"As a result of this Microsoft vulnerability, PCs running Internet Explorer (IE) version 5.0 and/or Microsoft Office 2000 are vulnerable to virus attacks using most HTML-enabled email systems, even if the email recipient opens no attachments."

This email security problem is caused by a programming bug in an Internet Explorer ActiveX control called scriptlet.typelib. "Unfortunately, as it is simple to exploit, it is ripe for a hugely destructive event - at least as large as the ILOVEYOU virus which struck in May," Mr. Galea added.

Traditional anti-virus programs cannot protect against this type of virus. However, Mail essentials can block emails and attachments containing VB script (such as the LoveLetter virus), Windows Scripting, Java scripts and HTML scripts at email server level. This way, as it is a content checking gateway that installs before the mail server, Mail essentials can detect and remove such emails before they can be distributed to users.

Internet Explorer and Outlook users are advised to check the Microsoft security site for the patch to deal with this hole. Network administrators should install an email content security gateway capable of detecting this virus to ensure that such emails are not passed on to the mail server.

Mail essentials is a powerful email security, content checking & anti-virus gateway that offers the following features:

  • Content checking/filtering.
  • Prevention of confidential info leaks.
  • Virus checking of all email.
  • Advanced anti-spam measures.
  • Disclaimers: Enables you to add a disclaimer to each outgoing mail.
  • Email management: Reports, archiving of all email, POP3 downloading & server-based auto replies.

More information can be found at http://www.gfi.com/me/index.html. The full version of Mail essentials is available from $275.

About GFI
GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging needs. With award-winning technology, an aggressive pricing strategy and a strong focus on small-to-medium sized businesses, GFI is able to satisfy the need for business continuity and productivity encountered by organizations on a global scale. Founded in 1992, GFI has offices in Malta, London, Raleigh, Hong Kong, and Adelaide which support more than 200,000 installations worldwide. GFI is a channel-focused company with over 10,000 partners throughout the world. GFI is also a Microsoft Gold Certified Partner. More information about GFI can be found at http://www.gfi.com.

All product and company names herein may be trademarks of their respective owners.



 Check out GFI's product range
>  GFI MailEssentials for Exchange/SMTP
>  GFI MailSecurity for Exchange/SMTP
>  GFI MailArchiver for Exchange
>  GFI FAXmaker for Exchange/SMTP
>  GFI LANguard Network Security Scanner
>  GFI EventsManager
>  GFI EndPointSecurity
>  GFI Network Server Monitor
>  GFI WebMonitor for ISA Server

   © 2008. All rights reserved. GFI Software Home Products Download trials Support Ordering Site map About us Contact us
GFI solutions: Exchange anti spam filter - exchange anti virus - isa server - network vulnerability scanner - event log management - USB security software - exchange archiving - fax server software