25.06.2013 Views

Guide to the Secure Configuration and Administration of Microsoft ...

Guide to the Secure Configuration and Administration of Microsoft ...

Guide to the Secure Configuration and Administration of Microsoft ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter<br />

7<br />

Client Security <strong>and</strong> “Advanced Security”<br />

Introduction<br />

Chapter 2 described issues related <strong>to</strong> <strong>the</strong> installation <strong>of</strong> <strong>the</strong> Exchange client <strong>and</strong> Outlook<br />

clients. This chapter will address o<strong>the</strong>r issues related <strong>to</strong> <strong>the</strong> clients, specifically<br />

protection against malicious file attachments, <strong>the</strong> use <strong>of</strong> encryption <strong>to</strong> protect messages,<br />

<strong>and</strong> methods that users can apply at <strong>the</strong> client <strong>to</strong> manage access <strong>to</strong> <strong>the</strong>ir mailboxes or<br />

public folders.<br />

File Attachment Security<br />

Executable content is a term that refers <strong>to</strong> files or o<strong>the</strong>r objects that contain an<br />

executable component. This executable component could serve a useful application or it<br />

could be malicious – an example being a Word macro virus.<br />

Both <strong>the</strong> Exchange client <strong>and</strong> <strong>the</strong> Outlook 97/98 client can be set <strong>to</strong> moni<strong>to</strong>r mail<br />

messages for some forms <strong>of</strong> executable content. Upon launching <strong>of</strong> <strong>the</strong>se kinds <strong>of</strong><br />

executable content, <strong>the</strong> client will provide notification that an executable is about <strong>to</strong><br />

launched <strong>and</strong> <strong>of</strong>fer <strong>the</strong> opportunity <strong>to</strong> cancel <strong>the</strong> action. Outlook 98 also <strong>of</strong>fers, via patch<br />

O98secu.exe, <strong>the</strong> ability <strong>to</strong> strip attachments from incoming mail messages as described<br />

in Chapter 2.<br />

Note that <strong>the</strong> option <strong>to</strong> moni<strong>to</strong>r for executables only exists in recent versions <strong>of</strong> <strong>the</strong> clients<br />

-- Outlook 97 version 8.02 or higher, Exchange client version 5.0.1458 or higher, <strong>and</strong><br />

Outlook 98. Attachment blocking is only available in Outlook 98 with <strong>the</strong> O98secu.exe<br />

patch installed.<br />

To enable file attachment security:<br />

Exchange Client Outlook 97 Outlook 98<br />

Verify <strong>the</strong> proper versions <strong>of</strong> Outlook 97 <strong>and</strong>/or <strong>the</strong> Exchange client are being used --<br />

Outlook version 8.02 or higher <strong>and</strong> Exchange client version 5.0.1458 or higher.<br />

Verify <strong>the</strong> option <strong>to</strong> check for executable file attachment is enabled (which is <strong>the</strong><br />

default). From <strong>the</strong> client, select Tools/Options <strong>and</strong> <strong>the</strong> “Attachments” tab. Under<br />

“Security Method,” select <strong>the</strong> option “High.”<br />

Please note that file attachment security, while useful, is limited.<br />

29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!