Link to home
Start Free TrialLog in
Avatar of mrmut
mrmutFlag for Croatia

asked on

Locking down email client

Client recently had Cryptolocker breach. The delivery was the usual path, attachment -> word macro -> shell script -> trojan -> cryptolocker -> crap.

So, they asked me to lock some email clients on POS machines.

How to do it? And what to do?

To just disable attachments?

What do you do?

Thanks
Avatar of regmigrant
regmigrant
Flag of United Kingdom of Great Britain and Northern Ireland image

I'm not aware of any settings on an email client to prevent download of attachments, this is more likely a server side setting. though you can set outlook (and probably others) to not download attachments automatically the user can still force the download

addictive tips

Which mail server do your clients connect to?
Does your ISP offer email scanning?
Have you looked at enterprise email handling which allows both scanning and flexibility about what can be downloaded?
Do the clients machines have appropriate malware/virus scanner?
Avatar of mrmut

ASKER

Thanks.

I would like to lock out Thunderbird.

Here are answers to your Qs:

Which mail server do your clients connect to?

SSL servers

Does your ISP offer email scanning?

Yes, and compromised emails are deleted automatically. However, that is not enough, as sometimes Viruses pass.

Have you looked at enterprise email handling which allows both scanning and flexibility about what can be downloaded?

Unfortunately, too expensive.

Do the clients machines have appropriate malware/virus scanner?

Yes. BitDefender Endpoint Protection, cloud based. It is a solid solution.


However, we got a CryptoLocker breach with all of the protection we utilize.
ASKER CERTIFIED SOLUTION
Avatar of Imal Upalakshitha
Imal Upalakshitha
Flag of Sri Lanka image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
use this MX record level spam filtering https://www.openprovider.co.uk/spam-filter/ it is not expensive & very effecctive
SEP with the correct settings, IPX, SONAR, etc will do it and Malwarebytes Anti-Ransomware  (MBARW) although still in Beta,  is a proven solution.
You amy also want to look at create a local or group policy that prevents programs from executing from the %appdata% folder.  This is a bit of a pita, as some OutLook plugins, and GoToMeeting run from there, but it can be a useful weapon in this battle.