|
Auto-Replies and Security - 2/10/2003 |
|
| Huh? What's that got to do with the price of fish? Well, more than you might think. It's not as harmless as you expect. The people at Panda Software sent us this hint which makes sense: Information in auto-replies usually deals with one's absence from their workplace. However, in many cases, they contain additional data such as return date, alternative contact persons and even phone numbers. All this data can become very handy in order to launch an attack using 'social engineering' techniques, as an attacker could use that information to call the contact person in the message and, taking advantage of the other user's absence, try to obtain information that could be used to prepare more advanced attacks. A basic measure to prevent this type of attack is to avoid giving much information on your absence, as when you ask a neighbor to collect your mail so that it does not pile up in your mailbox and nobody knows you are not at home. Another solution is to redirect messages to a workmate's mailbox. It also prevents your email from getting bounced up & down from automated list servers. |
|
|
Goto the 1USA Home Page at least once per week. The new features will be in the What's New section. |