Email from Microsoft (?)

Email from Microsoft (?)

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Email from Microsoft (?) Mick Jennings 05-17-2007
Posted by =?Utf-8?B?TWljayBKZW5uaW5ncw== on May 17, 2007, 3:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,

I've recently signed up to receive the MS newsletters and alerts so that I
can start to learn more about security issues in depth. Once I'm past my SBS
exam I intend to take courses in the security side, but for now I'm no expert
and relatively new to the "MS way" ...

I received an email this morning claiming to be from Microsoft with the
subject "Microsoft Security Bulletin Minor Revisions". It doesn't look
professional, beginning with text ...

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Minor Revisions
Issued: May 16, 2007
********************************************************************

Summary
=======
The following bulletins have undergone a minor revision increment.
Please see the appropriate bulletin for more details.

* MS07-027
* MS07-025
* MS07-023

Bulletin Information:
=====================

* MS07-027

- http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx
- Reason for Revision: Bulletin revised due to an incorrect file
name in Arbitrary File Rewrite Vulnerability - CVE-2007-2221
killbit table; A new issue discovered with the security
update: 937409 The "File Download - Security Warning" dialog
box opens when you try to open Internet Explorer 7; Updated
file names for Internet Explorer 7
- Originally posted: May 8, 2007
- Updated: May 16, 2007
- Bulletin Severity Rating: Critical
- Version: 1.2

Anyway - I wondered 2 things ...

1. How do I check that it's actually from Microsoft and not a spoofed send
address (I have SBS2003 R2 SP2 installed but I haven't yet configured the IMF
to check the Sender ID - how do I check that manually ?)

2. How do I check that the links in the email actually point to where they
say they point to (ok I have IE7 which SHOULD prevent phishing attacks right?
but again I'm interested to know how to assure myself manually)

Thanks all. Sorry if these are dumb questions or posted in the wrong place.

Posted by =?Utf-8?B?TmV3ZWxsIFdoaXRl?= on May 17, 2007, 3:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
1) Can't help

2) Configure e-mail client to show all messages as text, not html. Copy and
paste text version of link into web browser address bar. This is known as a
WYSIWYG hyperlink, and is preferable to a blind jump into hyperspace!
--
Newell White


"Mick Jennings" wrote:

> Hi all,
>
> I've recently signed up to receive the MS newsletters and alerts so that I
> can start to learn more about security issues in depth. Once I'm past my SBS
> exam I intend to take courses in the security side, but for now I'm no expert
> and relatively new to the "MS way" ...
>
> I received an email this morning claiming to be from Microsoft with the
> subject "Microsoft Security Bulletin Minor Revisions". It doesn't look
> professional, beginning with text ...
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> ********************************************************************
> Title: Microsoft Security Bulletin Minor Revisions
> Issued: May 16, 2007
> ********************************************************************
>
> Summary
> =======
> The following bulletins have undergone a minor revision increment.
> Please see the appropriate bulletin for more details.
>
> * MS07-027
> * MS07-025
> * MS07-023
>
> Bulletin Information:
> =====================
>
> * MS07-027
>
> - http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx
> - Reason for Revision: Bulletin revised due to an incorrect file
> name in Arbitrary File Rewrite Vulnerability - CVE-2007-2221
> killbit table; A new issue discovered with the security
> update: 937409 The "File Download - Security Warning" dialog
> box opens when you try to open Internet Explorer 7; Updated
> file names for Internet Explorer 7
> - Originally posted: May 8, 2007
> - Updated: May 16, 2007
> - Bulletin Severity Rating: Critical
> - Version: 1.2
>
> Anyway - I wondered 2 things ...
>
> 1. How do I check that it's actually from Microsoft and not a spoofed send
> address (I have SBS2003 R2 SP2 installed but I haven't yet configured the IMF
> to check the Sender ID - how do I check that manually ?)
>
> 2. How do I check that the links in the email actually point to where they
> say they point to (ok I have IE7 which SHOULD prevent phishing attacks right?
> but again I'm interested to know how to assure myself manually)
>
> Thanks all. Sorry if these are dumb questions or posted in the wrong place.

Posted by =?Utf-8?B?TWljayBKZW5uaW5ncw== on May 17, 2007, 4:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
:-) Thanks

"Newell White" wrote:

> 1) Can't help
>
> 2) Configure e-mail client to show all messages as text, not html. Copy and
> paste text version of link into web browser address bar. This is known as a
> WYSIWYG hyperlink, and is preferable to a blind jump into hyperspace!
> --
> Newell White
>
>
> "Mick Jennings" wrote:
>
> > Hi all,
> >
> > I've recently signed up to receive the MS newsletters and alerts so that I
> > can start to learn more about security issues in depth. Once I'm past my SBS
> > exam I intend to take courses in the security side, but for now I'm no
expert
> > and relatively new to the "MS way" ...
> >
> > I received an email this morning claiming to be from Microsoft with the
> > subject "Microsoft Security Bulletin Minor Revisions". It doesn't look
> > professional, beginning with text ...
> >
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > ********************************************************************
> > Title: Microsoft Security Bulletin Minor Revisions
> > Issued: May 16, 2007
> > ********************************************************************
> >
> > Summary
> > =======
> > The following bulletins have undergone a minor revision increment.
> > Please see the appropriate bulletin for more details.
> >
> > * MS07-027
> > * MS07-025
> > * MS07-023
> >
> > Bulletin Information:
> > =====================
> >
> > * MS07-027
> >
> > - http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx
> > - Reason for Revision: Bulletin revised due to an incorrect file
> > name in Arbitrary File Rewrite Vulnerability - CVE-2007-2221
> > killbit table; A new issue discovered with the security
> > update: 937409 The "File Download - Security Warning" dialog
> > box opens when you try to open Internet Explorer 7; Updated
> > file names for Internet Explorer 7
> > - Originally posted: May 8, 2007
> > - Updated: May 16, 2007
> > - Bulletin Severity Rating: Critical
> > - Version: 1.2
> >
> > Anyway - I wondered 2 things ...
> >
> > 1. How do I check that it's actually from Microsoft and not a spoofed send
> > address (I have SBS2003 R2 SP2 installed but I haven't yet configured the
IMF
> > to check the Sender ID - how do I check that manually ?)
> >
> > 2. How do I check that the links in the email actually point to where they
> > say they point to (ok I have IE7 which SHOULD prevent phishing attacks
right?
> > but again I'm interested to know how to assure myself manually)
> >
> > Thanks all. Sorry if these are dumb questions or posted in the wrong place.

Posted by Roger Abell [MVP] on May 17, 2007, 4:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options

verify the PGP signing


> Hi all,
>
> I've recently signed up to receive the MS newsletters and alerts so that I
> can start to learn more about security issues in depth. Once I'm past my
> SBS
> exam I intend to take courses in the security side, but for now I'm no
> expert
> and relatively new to the "MS way" ...
>
> I received an email this morning claiming to be from Microsoft with the
> subject "Microsoft Security Bulletin Minor Revisions". It doesn't look
> professional, beginning with text ...
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> ********************************************************************
> Title: Microsoft Security Bulletin Minor Revisions
> Issued: May 16, 2007
> ********************************************************************
>
> Summary
> =======
> The following bulletins have undergone a minor revision increment.
> Please see the appropriate bulletin for more details.
>
> * MS07-027
> * MS07-025
> * MS07-023
>
> Bulletin Information:
> =====================
>
> * MS07-027
>
> - http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx
> - Reason for Revision: Bulletin revised due to an incorrect file
> name in Arbitrary File Rewrite Vulnerability - CVE-2007-2221
> killbit table; A new issue discovered with the security
> update: 937409 The "File Download - Security Warning" dialog
> box opens when you try to open Internet Explorer 7; Updated
> file names for Internet Explorer 7
> - Originally posted: May 8, 2007
> - Updated: May 16, 2007
> - Bulletin Severity Rating: Critical
> - Version: 1.2
>
> Anyway - I wondered 2 things ...
>
> 1. How do I check that it's actually from Microsoft and not a spoofed send
> address (I have SBS2003 R2 SP2 installed but I haven't yet configured the
> IMF
> to check the Sender ID - how do I check that manually ?)
>
> 2. How do I check that the links in the email actually point to where they
> say they point to (ok I have IE7 which SHOULD prevent phishing attacks
> right?
> but again I'm interested to know how to assure myself manually)
>
> Thanks all. Sorry if these are dumb questions or posted in the wrong
> place.



Posted by Alex Krawarik [MSFT] on May 17, 2007, 2:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> but for now I'm no expert and relatively new to the "MS way" ...

Actually, as a general rule Microsoft does not send out random e-mail
(especially about patches and updates and stuff). So if you ever see a mail
purporting to contain a critical patch coming from "Microsoft" you can
pretty much bet money its malware, just like you can bet money a mail from
"paypal" is a scam.

> 1. How do I check that it's actually from Microsoft and not a spoofed send
> address (I have SBS2003 R2 SP2 installed but I haven't yet configured the
> IMF
> to check the Sender ID - how do I check that manually ?)

These days its best to start your morning knowing that any unsolicited mail
is untrusted and treated with utmost caution, period.

> 2. How do I check that the links in the email actually point to where they
> say they point to (ok I have IE7 which SHOULD prevent phishing attacks
> right?
> but again I'm interested to know how to assure myself manually)

Read all mail as plain text. Email "thick" clients allow you to do this.
I've been using Outlook 2007 and its actually pretty nice. My default view
is plain text, but if for some reason I want to see "pretty" HTML formatting
for particularly involved mails, or images, I can turn on HTML viewing in
one click. If you are using a web-based client (hotmail, gmail, whatevah),
you may get to view only in HTML. Today, Hotmail (Live Classic) doesnt allow
a default view as text, which is a bit lame, but you can either hover over a
suspicious link, and the address will be displayed in bottom left (IE) or
cut and paste into a test editor and the meta data for the link should be
displayed.

> Thanks all. Sorry if these are dumb questions or posted in the wrong
> place.

Not dumb, welcome.

Alex



Similar ThreadsPosted
Microsoft Award Email March 30, 2008, 5:16 pm
I got this fake/scam email from Microsoft January 1, 2008, 1:52 am
Re: I receive the same email from "Microsoft Customer Support" ev November 17, 2007, 8:16 pm
I receive the same email from "Microsoft Customer Support" every day! November 7, 2007, 5:04 am
Microsoft Help staff asking for home address, phone, etc. by email March 9, 2006, 2:05 pm
I receive the same email reminding reset password from "microsoft" every day! November 7, 2007, 5:11 am
MS Outlook automatically change email pop server email January 14, 2006, 9:13 pm
Uploading an email from email client to web based host September 22, 2006, 9:46 am
Re: Forum software email security: email obfuscation October 14, 2006, 12:46 pm
Re: Confidentiality of email June 23, 2005, 9:26 am

The site map in XML format XML site map

Contact Us | Privacy Policy