# Anyone else see this supposed "security" e-mail?

**URL:** https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837
**Category:** Factual Questions
**Created:** [April 10, 2003, 6:16pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837 "2003-04-10T18:16:10Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [April 10, 2003, 6:16pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837/1 "2003-04-10T18:16:10Z")

</div>

One of our users got the following e-mail today:

> [@](#):
>
> Dear ladies and gentlemen,  
> As discovered recently, the microsoft windows software  
> is still not protected against attacks from the internet.  
> For preventing any damage to your own system, your own  
> software and for shielding it against any unauthorized  
> attacks from the internet, we advice you to install the  
> new “Microsoft Baseline Security Analyzer”.  
> Please follow the attached instructions for downloading  
> and setting up of the “Microsoft Baseline Security Analyzer”.  
> Or click the following link:

I didn’t include the link. It goes to a web page that immediately tries to download software onto your computer.

There is a “Microsoft Baseline Security Analyzer,” but I can’t think of any legitimate reason why a third-party site would be contacting you, and making you download it from their site and not Microsoft’s.

A search through Google and Symantec didn’t help. It’s obviously fishy, but does anyone know what it is?

---

<div class="post-metadata">

### Author: ![zev\_steinhardt](https://avatars.discourse-cdn.com/v4/letter/z/97f17d/32.png) [@zev\_steinhardt](https://boards.straightdope.com/u/zev_steinhardt)
#### Post date: [April 10, 2003, 6:19pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837/2 "2003-04-10T18:19:32Z")

</div>

I got it too, but disregarded it.

When Microsoft has any updates, you should go to [www.windowsupdate.com](http://www.windowsupdate.com) for authorized patches.

Zev Steinhardt

---

<div class="post-metadata">

### Author: ![Number](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/number/32/242_2.png) [@Number](https://boards.straightdope.com/u/Number)
#### Post date: [April 10, 2003, 6:43pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837/3 "2003-04-10T18:43:37Z")

</div>

This sounds similar to a scam that Snopes [posted](http://66.165.133.65/computer/virus/security.htm) last week.

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [April 10, 2003, 6:49pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837/4 "2003-04-10T18:49:46Z")

</div>

Bingo! A search for the website name shows it come from [Aconti.net](http://Aconti.net), which is listed as spyware by both AdAware and Spybot.

**Zev** – I ignored it, too, but we have a lot of users who may not, and then I have to clean up after them. ☹

---

<div class="post-metadata">

### Author: ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)
#### Post date: [April 11, 2003, 5:57pm UTC](https://boards.straightdope.com/t/anyone-else-see-this-supposed-security-e-mail/167837/5 "2003-04-11T17:57:56Z")

</div>

The standing rule: Microsoft does not send out emails to users advising them to make any updates unless the user has subscribed to the [Microsoft Security Notification Service.](http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-007.asp)

These alerts are exceedingly technical in nature, and while they’re obtuse, the grammar and spelling is perfect. (No “we advice you to install” goofs!) They’re also sent out with a PGP signature. Here’s just a tiny sample from a recent alert:

\*Summary  
Who should read this bulletin: Systems administrators running Microsoft ® Windows ® 2000  
Impact of vulnerability: Run code of attacker’s choice  
Maximum Severity Rating: Critical  
Recommendation: Systems administrators should apply the patch immediately  
Affected Software: Microsoft Windows 2000

Technical details

Technical description:  
Microsoft Windows 2000 supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. WebDAV, defined in RFC 2518, is a set of extensions to the Hyper Text Transfer Protocol (HTTP) that provide a standard for editing and file management between computers on the Internet. A security vulnerability is present in a Windows component used by WebDAV, and results because the component contains an unchecked buffer.

yada, yada, yada…  
\*
