Are popular anti-spam filters putting systems at risk for infection?
Lack of secure quarantined message management in many popular spam filter applications, puts systems at risk for virus and exploit infection.

Many of today's popular anti-spam servers do not offer a secure quarantined message processor. These applications have instead chosen to simply route "quarantined" messages into a user's Outlook folder designated as suspected spam. Although this can ostensibly appear as "simpler" or more "integrated", this approach can't really be considered quarantining by any reasonable definition and poses a rather substantial organization wide security threat.

There is an important reason more sophisticated anti-spam servers include a server-side quarantined message area, coupled with a secure quarantined message processing application. It is critical that a safe environment be created to evaluate potentially dangerous content. Spam messages often contain viruses and other exploits that require containment, so they are not inadvertently auto-executed and the system infected.

The rather substantial risk associated with using Microsoft Outlook to view and process "quarantined" messages, is that there is little, if any protection against the execution of dangerous exploits contained within the "quarantined" message. A prime example is that Outlook actually uses Internet Explorer to view messages containing HTML. The ever increasing number of security holes in Internet Explorer is well documented and poses great concern.

On the other hand, spam filters which have a real quarantined message facility, use a custom application to safely process suspect messages. These applications are specifically designed with security in mind and are not vulnerable to the exploits that plague Outlook-based "quarantine" solutions.

The alternative to exposing the organization to viruses, phishing attacks and various mal-ware, is to deploy an anti-spam server that has true message quarantining. One of the leading anti-spam server products on the market, which includes true quarantined message processing, is Extensible Messaging Platform ( EMP 6 ).

EMP is endorsed by tier-one mail server vendors; Microsoft, IBM/Lotus and Novell. It is operating system independent and deployed around the world, protecting a diverse array of mail server products, including Microsoft Exchange Server, Lotus Domino, Novell GroupWise and UNIX Sendmail.

J.A. Korsmeyer, Inc. is a privately held Illinois corporation, Incorporated in 1988, it provides enterprise email security products to organizations of all sizes, from the Fortune 50, to the small business community.

Login

SSL Certificate Authority