Exchange Messaging Outlook
Volume 10, Number 14

   
Greetings! Welcome to Vol. 10, No. 14, Oct 13, 2005, of Exchange Messaging Outlook, a biweekly newsletter about Microsoft Exchange and Microsoft Outlook.

Today's highlights:

Regular features:

 

Outlook 2003 SP2 Anti-Phishing Support

Service pack 2 for Outlook 2003 added two new security features: all mail is displayed in plain text only and hyperlinks are disabled in the Junk email folder, additionally all hyperlinks in messages which are identified as potential phishing attempts are disabled in any folder. While you can change a junk email option and enable hyperlinks globally, HTML rendering in the junk email folder was removed completely and it can't be enabled globally. You either need to move the messages to another folder or click on the Infobar to enable HTML for that message only.

The newest junk mail filter does a very good job and has a low false positive rate so there should be little need to look in the junk mail folder, once you have your Safe lists configured. While viewing junk mail as plain text is less important if you keep the download external content setting on and only download content for individual messages as needed, many users and administrators requested this feature because many users allow all external content.

The reaction to this new security feature surprised me. Many users are upset that they can't turn HTML on in the junk email folder and ask "how dare Microsoft tell me what to do?" and "I can protect myself, I don't need big brother telling me what to do". While Microsoft should have made plain text in the Junk mail folder optional, there should be few false positives in the Junk email folder, and if you can't read the plain text portion, move them to the Inbox. If the message is not junk, mark it Not Junk and add the sender's address or domain to the Safe senders list. If Outlook's junk email filter has a high false positive rate for you, then you need a different anti-spam scanner, one you can train for the types of messages you receive.

To enable hyperlinks on messages in the junk email folder, as well as on messages not classified as junk but which exhibits phishing characteristics, go to Tools, Options, Preferences tab, Junk Email button. Remove the check from 'Don't turn on links in messages than might connect to unsafe sites... ' at the bottom of the dialog. Microsoft recommends you leave this checked, and I agree. It's not about being smart enough to know it's probably a phishing or spam email, it's about accidentally clicking on a link. This feature is added security and it takes just one click in the Infobar to enable hyperlinks on messages that are legitimate.

To learn more about Service Pack 2 and the anti-phishing features, view the

Support WebCast: Overview of Outlook 2003 Service Pack 2
http://support.microsoft.com/?kbid=908366

Blocked External Content Revisited

Outlook 2003's release version included a 'web bug' blocking feature which prevents automatic downloading of external content, usually images, but other content, such as style sheets are also blocked. This feature is good for users in several ways: users can avoid prompts from Windows dialer as they read messages offline, users with slow connections can reduce the bandwidth they use, and everyone can prevent companies or spammers from learning if they viewed their messages.

I purposely choose not to download any external content and enable it per message, as necessary, because I don't want someone to know if, where or from what IP, I read their messages. Unfortunately, too many users do enable external content for all messages because they don't want to be bothered with enabling external content as needed..

An incident from last week illustrates why blocking external content is good for users, bad for newsletters and advertisers and why many people are opposed to 'web bugs'. I received a message which began with the following sentence. "It appears from our records that you are not getting our messages." All I can say is "Oh, really?" I'm most certainly getting their newsletters and I sometimes even read them, when the titles are interesting, but I value my privacy and don't want them to know when I read their messages, so I do what I can to prevent this information from getting back to them, which is to leave external content blocked in Outlook 2003. 

Autocomplete Cache and User Logons

An interesting question about Outlook's autocomplete cache and security came up this week:

"We are experiencing an issue with the autocomplete naming in Outlook 2003. The AutoComplete name displays with the name followed by a UniqueID. The issue is the UniqueID is the user logon name which presents a security issue. After all, we remove the "last logon name" from the logon dialog box for the same security reason. Is there a way to remove the <UniqueID> portion of the AutoComplete name?

While Microsoft allows a way to NOT see a user ID in the logon dialog box, it allows it in the autocomplete section using an .NK2 file? This is a huge security issue so I guess my next question would be is there a way to turn Autocomplete off?"

I'm not sure this problem qualifies as a security issue. What they are seeing in the autocomplete cache is the Exchange mailbox alias, which just happens to be the user logon account at their site. Many sites use the account name as the default SMTP alias, but even if you create a different default SMTP alias, it's visible in the GAL, and anyone with access to the GAL can open the contact record and view it. It can be removed from the GAL, but then users can't log on to OWA using an email address.

When you send a message internally, the display name and exchange alias are stored in the autocomplete cache. This is normal - on my server it's "Diane Poremsky <dianep>". In their case, it looks like Bill Smith <123456>, displaying the same logon id they don't want stored in the logon screen for security reasons. Had they configured the account differently, it could show "Bill Smith <bsmith>" in autocomplete and the user account name would not be seen, even in the GAL.

When many sites create a user account in the AD, they enter the user account logon name and OK their way thru the screens, accepting the defaults for the exchange alias, which by default, just happens to be the same as the user account logon.

If you want to keep the logon separate from the exchange alias, you should create the user account in the AD and enter the user logon name as usual, but once you get to the Create Exchange mailbox screen, enter a different name for the Exchange alias. When the user logs on to Windows using his user account, he'll be logged into the mailbox as usual, even though the user account and mailbox name are different, unless Outlook was configured to require the username and password when accessing the mailbox.

If this is a problem for your company and changing the Exchange mailbox name is not a workable solution, you can disable autocomplete in Tools, Options, Preferences, Email options button, Advanced Email options. Remove the checkmark from Suggest names while completing TO, CC, and BCC fields near the bottom of the dialog.  

Back to Top  
New Utilities

FREEBUSY FOR OUTLOOK
http://freebusy.4team.biz/?pcode=508260136ovkjc2
MS Outlook add-on automatically creates and sends e-mail auto reply from your custom templates based on your Status (Away, Out of Office, Vacation, custom Status or Calendar Free/Busy time). Allow response to selected Contacts or Distribution lists. Version 1.20.0049

LBE FIND & REPLACE FOR MS OUTLOOK
http://www.outlook-find-replace.com
LBE Find & Replace for MS Outlook lets you Search and replace in Outlook Contacts, Emails, Appointments, Notes and Tasks. Free trial available.

OUTLOOKPRINTER
http://www.outlookprinter.com/
Use OutlookPrinter to customize your look of your emails easily and print just the part of the email you need. It also allows you to list the attachments or print them out directly.

PSTSYNC
http://www.pstsync.com
Use PSTSync to perform Outlook synchronizations, helping you synchronize every Outlook folder, even custom created ones. PSTSync provides bi-directional folder synchronization as well as a number of other tools to help you manage your pst files with ease, PSTSync offers SmartMove and SmartCopy functionality as well as Encryption, Password Protection, Online Backup as well as the popular built in PST file viewer.

SPAMFIGHTER EXCHANGE MODULE
http://www.spamfighter.com/product_sem.asp
SPAMfighter Exchange module (SEM), is an easy-to-use anti-spam solution for Microsoft Exchange Servers. SEM delivers instant spam protection with no configuration or maintenance, to help small and medium businesses filtering time consuming spam.

Back to Top  

Updated Utilitiesties

EXCHANGE GROUPCALENDAR
http://www.exchangegroupcalendar.com/
This Active Directory integrated tool for Exchange server 2000/2003 monitors user & resource calendars and collates the appointments in Public Folders. You can configure what type of content every individual public calendar will contain based on the properties of the original item. It can also change the appointment-copy in the public calendar to obscure, convert or enhance the original appointment properties. New features include improved administration, import of existing calendars, additional interface languages, reporting and a utility to export public folder calendar data to Excel/html. Version 1.30 works with Exchange 2000/2003.

IMI GAL EXPORTER
http://www.imibo.com/imidev/Exchange/imige.htm
IMI GAL Exporter for Microsoft Exchange Server is small utility for Exchange Admin to export GAL (Global Access List) to a Microsoft Access 2000 table. Also available is IMI Distribution List Content Exporter, a small add-in used to export the contents of Distribution Lists to an Access 2000 table. Now supports custom attributes and multi-value entries for phone entries. Version 3.

LUCATEC MASK
http://www.lucatec.net/mask/maskoverview-en.htm
The Lucatec Mask Add-in for Outlook is used with Exchange server accounts which allows you to reply from a shared mailbox or public folder, automatically entering the folder or mailbox's email address in the From field. Lucatec Mask will automatically determine the correct sender address to use based on the mailbox or public folder the user is currently using in Outlook. It also offers the option to move or copy the sent message to the relevant account's Sent Items folder (or Public Folder) and define sender addresses and target locations for sent items for individual folders or even globally for all sent messages. It supports shared Exchange Server mailbox accounts and Public Folders with email addresses and was tested with Exchange Server 5.5 and 2000, Microsoft Outlook 2000 and XP. Version 1.2.2

PROFILER
http://www.dirwiz.com/products/index.shtml?profiler.html
Profiler gives the typical end user the ability to update their directory information (telephone number, office location etc) using their browser. Because the software is web based, deploying the solution is as easy as giving your users the correct URL or adding a link to your intranet. Supports Exchange 5.5/2000/2003 and OpenLDAP, LDAP v3 (including SSL) for directory updates. Updating membership of Groups and Distribution lists are now supported. Version 4.5

SHAREO FOR OUTLOOK
http://shareo.4team.biz/?pcode=409220071fmbb2r
Share your Outlook calendar, contacts, journal, mail, tasks and notes folders with other Outlook users, without a server, with this utility. Version 2.15.0034

Back to Top  

Other Resources

CHANGES TO CUSTOM PROPERTIES IN OUTLOOK 2003 SERVICE PACK 2
http://support.microsoft.com/default.aspx?scid=KB;EN-US;907985
To guarantee consistent use of custom properties, or fields, Microsoft Office Outlook 2003 Service Pack 2 (SP2) and later versions of Outlook limit some of the ways that custom properties can be introduced into Outlook data stores. For example, custom properties can be introduced in specific ways in Outlook personal folders (.pst) files.

OFFICE 2003 SP2
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=57e27a97-2db6-4654-9db6-ec7d5b4dd867
SP2 contains a number of fixes, including one for SMTP problems, and a new phishing protection feature that's works with the Outlook Junk Email Filter to warn you of potential phishing attempts.

OUTLOOK LIVE 2003 SERVICE PACK 2
http://support.microsoft.com/?kbid=902848
Outlook Live subscribers who use the subscription service version of Outlook need to download and install this service pack. The general Office 2003 SP2 will not install with the downloaded version of Outlook supplied by Outlook Live.

SUPPORT WEBCAST: NEW FEATURES IN THE BUSINESS CONTACT MANAGER UPDATE FOR OFFICE 2003
http://support.microsoft.com/?kbid=908467
This Support WebCast describes new features in the Business Contact Manager Update for Microsoft Office 2003. Some of the topics will include: System requirements, a brief technical overview of BCM and the Microsoft SQL Server 2000 Desktop Engine (MSDE), database sharing, accounting integration, Pocket PC synchronization support, and a brief introduction to troubleshooting

SUPPORT WEBCAST: OVERVIEW OF OUTLOOK 2003 SERVICE PACK 2
http://support.microsoft.com/?kbid=908366
This WebCast discusses some of the new Microsoft Outlook features that are included in Microsoft Office 2003 Service Pack 2 (SP2). New features that will be discussed include updated junk e-mail functionality, changes to Calendar meeting processing, and support for Microsoft Exchange Server 2003 SP2 Offline Address Book, version 4.

Back to Top  

New Exchange Knowledge Base Articles

The IMailBox.BaseFolder, IMailBox.RootFolder, and IMailBox.Inbox CDOEX properties may return blank values when you use script code to access a hierarchy of folders that belongs to a person
http://support.microsoft.com/?kbid=899351

The event sink does not fire as expected on a computer that has both Exchange 2000 SP2 and ScanMail for Exchange version 6 installed
http://support.microsoft.com/?kbid=810150

Back to Top  

New Outlook Knowledge Base Articles

You receive an "Unable to update Public free/busy data" error message when you quit Outlook 2002 after you add a new appointment to a delegate's calendar
http://support.microsoft.com/?kbid=905814

Description of the Outlook 2002 post-Service Pack 3 hotfix package: August 30, 2005
http://support.microsoft.com/?kbid=905864

Description of the Outlook 2003 Junk E-Mail Filter update: September 2005
http://support.microsoft.com/?kbid=904631

Issues that are fixed in Outlook 2003 by Office 2003 Service Pack 2
http://support.microsoft.com/?kbid=906451

Description of Outlook Live 2003 Service Pack 2
http://support.microsoft.com/?kbid=902848

Back to Top  

More Information

ISSN 1523-7990
Copyright 1996-2006, Slipstick Systems and CDOLive LLC. All rights reserved.