|
|
This issue sponsored by: Sherpa Software ♦
Sperry Software
Today's highlights:
Regular features:
Exchange 2007 Service Pack 1 - Update Rollup 3 (UR3)
by Michael B. Smith, MCSE/Exchange MVP
This week, Microsoft unleashed update rollup 3 for Exchange
Server 2007 service pack 1 onto the world - on Patch Tuesday,
along with a number of other 'important' security patches. This
timing is no coincidence. Included in UR3 is a fix for an OWA
security hole that can cause an elevation of privilege
(MS08-039). This was also not a unique problem to SP1 -
Microsoft also released UR7 for Exchange Server 2007 RTM (that
is, the version without a service pack) and a hotfix for
Exchange Server 2003 service pack 2 (earlier versions of
Exchange 2003 are no longer supported) to correct the same
issues.
The OWA fix actually addresses two security vulnerabilities -
both of which are Cross Site Scripting (XSS) vulnerabilities. A
XSS vulnerability is one where a bad-guy talks a user into
visiting a web-page that contains a payload. This payload is
generally some kind of programming - like javascript - that can
do something nasty to the user's machine. It does this by
finding a way to impersonate the user. Once that code
impersonates the user, it basically has free reign to mess up a
user's computer (well, as much as that particular user does -
this is why Vista's UAC is a good thing!). If you want to know
more about XSS, see the Wikipedia entry on it. Well, some smart
guy (or security researcher, take your pick), found two problems
in OWA where it was vulnerable to XSS payloads. UR3 closes those
holes.
Of course, this is far from the only fix in UR3. A correction
that is near-and-dear to me is a fix for the Import-Mailbox
Exchange Management Shell cmdlets. Ever since the initial
release of Exchange Server 2007, the IncludeFolders parameter
for Import-Mailbox has been broken - specifying it would cause
the cmdlets to crash. This has now been corrected. YAY! (This
particular fix is described in KB 949549.)
There are also fixes for three common problems that I've seen
discussed on various mailing lists and newsgroups:
- If a delegate uses OWA to modify an appointment,
the wrong time may be sent to meeting attendees.
- The Exchange 2007 Application Pool crashes and on
restart causes all OWA sessions to reauthenticate.
- After an Authentication Timeout, OWA will generate a 404
on refresh (or if any buttons on the OWA window are
clicked).
Because of the way Exchange 2007 does Update Rollups now -
this is a big patch. As I examined the patch manifest, I was
astounded - there are hundreds of files contained within the
patch. At 34 MB in size, it's about 10 percent of the size of
the full Exchange (English) release. Then I remembered that it's
fully cumulative - all of the changes to everything since
Service Pack 1 are included in UR3.
Obviously, this is a pretty important roll-up to roll-out.
However, I encourage you to keep a couple of things in mind:
If you have ANY OWA customizations, they will require rework.
There is still a problem with Exchange servers (such as mailbox
servers behind a firewall) that cannot connect to the Internet
experiencing a timeout when some services try to start the first
time (see KB 944752 for a description of how to fix this)
Ensure that you install the roll-up with an account that has
enough permission to do the install!
I have already seen a number of reports on the newsgroups where
folks have tried to install UR3, and it SAID it installed, but
because of permission issues it didn't actually install. This
can cause any number of difficult to analyze problems.
So go on! Happy patching!
_____________________________________________________________________________________
Wikipedia - Cross-Site Scripting
http://en.wikipedia.org/wiki/Cross-site_scripting
MS08-039: Vulnerabilities in Outlook Web Access for Exchange
Server could allow elevation of privilege
http://support.microsoft.com/kb/953747/
Update Rollup 3 for Exchange Server 2007 Service Pack 1
(KB949870)
http://www.microsoft.com/downloads/details.aspx?FamilyId=63E7F26C-92A8-4264-882D-F96B348C96AB&displaylang=en&displaylang=en
Error message when you import a .pst file by running the
Import-Mailbox cmdlet in Exchange Server 2007: "Unable to make
connection to the server"
http://support.microsoft.com/default.aspx/kb/949549/
Exchange 2007 managed code services do not start after you
install an update rollup for Exchange 2007
http://support.microsoft.com/kb/944752/
Webmail via Outlook
It seems like a lot of Exchange sites support only OWA and a
lot for those users would like to use Outlook instead but won't
ask the administrator or don't believe him when the answer is
"No", so they ask me if its possible.
My answer: It depends on how the server is configured.
If the web address you use to access OWA begins with HTTPS, you
can use Outlook only if Outlook Anywhere (RPC over HTTP) is
enabled. While you could try to find out on your own by using
the OWA URL in the proxy settings, you should ask the Exchange
administrator if its enabled and if so, what proxy address and
authentication settings to use. It's much faster and less
frustrating than experimenting with different settings.
When the web address is not secure (URL begins with HTTP://) you
can configure it in Outlook 2003 and 2007 as an HTTP account
type. However you will be limited to email as Calendar,
Contacts, and Tasks are unusable.
Only Exchange server supports HTTP access through Outlook. Other
web mail sources, such as Yahoo, do not support WebDAV and
cannot be used in Outlook. You'll need POP3 or IMAP access to
use them with Outlook.
Searching for Attachments
An Outlook user asked me if its possible to define a search that
will only show those messages that have a specific attachment
type (file extension).
Outlook 2007's search capabilities are better than in previous
versions, but not yet perfect, as a search like this shows.
Instant search will narrow the field for you, but it will find
all messages with the extension in the message body too. You can
use the Instant search criteria of "Has Attachments" to show
only messages with attachments, making it easier to browse the
results for the correct message.
When you use an older version of Outlook, you'll need to be
creative or use a third-party search tool. If the attachment
name is in the email header (many are) you can use a rule to set
a flag or category based on words in the header and use Run
Rules Now to run it on the messages already downloaded. Then use
a custom view or Advanced Find to show only that flag or
category that meet the flag or category criteria. This is not
100% foolproof as it may miss attachments that are embedded in
the message as the attachment name may not be included in the
Internet header.
Search Tools
http://www.slipstick.com/addins/search.asp
Windows Update KB951748 and Internet Connection Problems
If you use Zone Alarm and lost Internet connectivity after a
recent Windows update, you'll need to download the new version
of ZoneAlarm.
A link to the new version is at
http://download.zonealarm.com/bin/free/pressReleases/2008/LossOfInternetAccessIssue.html
For a temporary fix you can move the ZoneAlarm Internet Security
zone slider to Medium or uninstall the Windows update.
Update Rollup Numbering
If you're unfamiliar with how Exchange Server 2007 updates
are numbered, KB articles referring to different rollup updates
may leave you confused, such as the two released this week.
Exchange RTM and SP1 are considered different versions when it
comes to updates and SP1 isn't a requirement or forced upgrade,
yet. The rollup updates allow those sites who haven't yet
installed SP1 to install the more critical updates and fixes
without upgrading to SP1.
In either case, the rollup terminology means the updates
installed with previous rollups are rolled into the latest one.
This means if you need to install Exchange 2007 in the future
you'll need only the last rollup released.
|
 |
|
New Utilities
|
KiGoo
http://www.getkigoo.com/
Use KiGoo to manage Exchange and Google Calendars in only one
program. Check free/busy availability of all Google Contacts who
shared their information. View, browse, update, email and invite
your Google Contacts from Outlook. Real-time access. Supports
Outlook 2007. Free for non commercial use. |
 |
|
Updated Utilities
|
Open Relay Filter Enterprise Edition (ORFEE)
http://www.slipstick.com/redirect.asp?id=vamsoft
ORFEE has SURBL blacklist support, greylisting, tarpit delay, and
automatic sender whitelist for improved spam filtering. ORFEE
supports filtering emails on arrival, which allows delivery path
analysis, keyword and attachment filtering and Attachment and
keyword filtering so you can drop emails with malicious attachments
or replace the attachments with a customizable warning text. Both
the keyword and the attachment filtering support using
Perl-compatible regular expressions and are Unicode-aware. E-mails
caught by the On Arrival filtering point can be dropped, redirected
or tagged (header or subject). ORFEE includes a built-in log viewer
which allows easy browsing, searching and filtering the logs.
Version 4.2
Salesplus.net
http://www.salesplus.net/
Contact management and customer relationship system based on
Outlook, Exchange Server and SQL, and is compatible with other
SFA's/CRM's and databases. Hosting is offered for companies without
Exchange Server. A Lotus version is also available.
Delete Duplicates for Outlook
http://e-gadgets.freehostia.com/ddo.htm
Delete Duplicates for Outlook is a tool for deleting duplicate
e-mails for Microsoft Outlook. Works with Outlook
2000/2002/2003/2007. Version 4.8 |
 |
|
New Exchange Knowledge Base Articles
|
The Availability service may use lots of memory on an Exchange Server 2007-based
computer
http://support.microsoft.com/?kbid=936747
A meeting reminder is still active when you configure Outlook to send no
reminders to an Exchange Server 2007 user
http://support.microsoft.com/?kbid=945854
A storage group may not mount after you move the resources from the active node
to the passive node while the backup is in progress in Exchange Server 2007
http://support.microsoft.com/?kbid=950153
An attachment incorrectly appears as the body of the e-mail message in an
Exchange Server 2007 environment
http://support.microsoft.com/?kbid=948897
Description of Update Rollup 3 for Exchange Server 2007 Service Pack 1
http://support.microsoft.com/?kbid=949870
Description of Update Rollup 7 for Exchange Server 2007
http://support.microsoft.com/?kbid=953469
Error message when an Exchange 2007-based user sends a meeting request to a
resource that is located in a Lotus Domino resource reservation database: "Error
autoprocessing message"
http://support.microsoft.com/?kbid=937436
Error message when you enter logon credentials after an Outlook Web Access
session times out in Exchange Server 2007: "Server Error in '/ExchWeb/bin'
Application"
http://support.microsoft.com/?kbid=951293
Error message when you import a .pst file by running the Import-Mailbox cmdlet
in Exchange Server 2007: "Unable to make connection to the server"
http://support.microsoft.com/?kbid=949549
External e-mail message senders receive an NDR when you select the Turkish
language setting on a computer that is running Exchange Server 2007 Service Pack
1
http://support.microsoft.com/?kbid=951563
How to disable the "Sent by Microsoft Exchange Server 2007" branding sentence in
an Exchange Server 2007 DSN message
http://support.microsoft.com/?kbid=941770
It takes a long time for the Exchange Management Console to load in an Exchange
Server 2007 organization that was deployed in a multiple-domain environment
http://support.microsoft.com/?kbid=947573
MS08-039: Vulnerabilities in Outlook Web Access for Exchange Server could allow
elevation of privilege
http://support.microsoft.com/?kbid=953747
OVA announces "Unrecognized caller" in an Exchange Server 2007 environment even
though Outlook and Outlook Web Access correctly resolve the caller address
http://support.microsoft.com/?kbid=950758
The e-mail address of a contact does not appear in the Outlook Address Book
after you use Exchange Web Services to edit the contact in Exchange Server 2007
with Service Pack 1
http://support.microsoft.com/?kbid=949206
The heading of the "State" column is translated incorrectly in the German
version of the Exchange Management Console in Exchange Server 2007
http://support.microsoft.com/?kbid=951263
The icons that represent TIFF attachments may not be shown correctly if the
e-mail message is viewed by using Outlook Web Access 2007 in an Exchange Server
2007 environment
http://support.microsoft.com/?kbid=949778
The reminder is triggered earlier than expected when an Exchange Server 2007
server receives an iCalendar meeting request message over an SMTP server
http://support.microsoft.com/?kbid=950409
The W3wp.exe process may intermittently stop responding, and event ID 1000 is
logged in Exchange Server 2007 Service Pack 1
http://support.microsoft.com/?kbid=953539
Web services sends meeting request information that has an incorrect time if a
delegate modifies an appointment in an Exchange Server 2007 environment
http://support.microsoft.com/?kbid=950674
You cannot control the behavior of attachments on mobile devices by using the
ActiveSync policy in Exchange Server 2007 Service Pack 1
http://support.microsoft.com/?kbid=950120
You cannot log on to Outlook Web Access in an Exchange Server 2007 environment,
and you receive an error message: "HTTP Error 403.4"
http://support.microsoft.com/?kbid=945453
You cannot resolve a sender name or a recipient name when the name belongs to an
alternative domain tree in Exchange Server 2007
http://support.microsoft.com/?kbid=950930
You cannot run the New-X400AuthoritativeDomain cmdlet successfully in an
Exchange Server 2007 environment if an X.400 address contains a space character
http://support.microsoft.com/?kbid=951094
|
 |
|
New Outlook Knowledge Base Articles
|
An e-mail message does not appear in a user's mailbox if the e-mail message was
sent on behalf of the user by a delegate in Outlook 2003
http://support.microsoft.com/?kbid=953804
Contains instructions to enable the hotfix described in KB 953803 to fix this
issue.
Description of the Outlook 2003 hotfix package: June 18, 2008
http://support.microsoft.com/?kbid=953803
This hotfix package fixes the issue described in KB 953804
Description of the Outlook 2003 Junk E-mail Filter update: July 8, 2008
http://support.microsoft.com/?kbid=953465
Description of the Outlook 2007 Junk E-mail Filter update: July 8, 2008
http://support.microsoft.com/?kbid=953463
Description of the update for Outlook 2003: July 8, 2008
http://support.microsoft.com/?kbid=953432
This update replaces several previously released updates for Outlook 2003
related to how messages and attachments are rendered.
Description of the update for Outlook 2007: July 8, 2008
http://support.microsoft.com/?kbid=952142
This update addresses a problem with creating a new profile in Outlook 2007
where the creation wizard disappears before the profile is created. If you try
to create a new message, you receive "A dialog box is open. Close it and try
again." error message. Additionally, Outlook stops responding and you cannot
close Outlook, and you have to end the Outlook.exe process by using Task
Manager. If your version of Outlook is 12.0.6316.5000 you do not need to install
this update.
Description of the Outlook 2003 hotfix package: June 18, 2008
http://support.microsoft.com/?kbid=953874
This hotfix package fixes an issue with certain multiple command line switches
returning a 'command not valid' error message.
|
 |
|
More Information
|
Click here
to subscribe to the Exchange Messaging Outlook newsletter.
Exchange Messaging Outlook Newsletter
back issues
ISSN 1523-7990
Copyright 1996-2009, Slipstick Systems and CDOLive LLC. All rights reserved.
|
|
|
|