Re: [icon-users] Microsoft Office file validation

  • From: Mike Hobbs <mike.hobbs@xxxxxxxxxx>
  • To: Icon users <icon-users@xxxxxxxxxxxxx>
  • Date: Mon, 19 Mar 2012 18:35:22 +0000

In message <52729a4a94john@xxxxxxxxxxxxxxxx>
          John Harrison <john@xxxxxxxxxxxxxxxx> wrote:

> Has anyone else had this problem?  I've had it from several people in
> recent months.

This _may_ not not have anything to do with EW/TW/MS Office.
I've discovered that a number of internet service providers are
getting very aggressive about spam. It seems some spam filters
delve into every part of an email looking for spam-like material.
That can be as innocuous as mentioning low cost jewellery or
including a URL of a site that uses a domain and IP address that
does not tally with its location of registration (e.g. using
.co.uk if the IP address is not registered in the UK).
Simply including the email address of someone using such a domain
can cause the mail to be marked as spam.
In my opinion this this unacceptably intrusive but that is what is
happening, like it or not.  Could this be your problem?
Try compressing and perhaps even encrypting the content.

> When sending documents to non-RO users I convert them to PDF if they are
> not for editing, or Word if they are (eg contributions to a newsletter).
> Several people have come back asking me to re-save and re-send, because the
> file has been detected as suspicious.

> There can't be any malware in a file generated by EW, and I can't believe
> that EW would add any content that wasn't necessary.  My suspicion is that
> the file is being scanned to find out what version of Word created it, and
> then checked to make sure it contains nothing inconsistent with that
> version.  Since an EW file doesn't contain such an identifier, it is
> failing the first part of the test.

> If I am right, I consider it arrogant of MS to assume that anything not
> created by MS is probably malicious.  I wonder whether it would reject
> files created by Open Office, or Apple's 'Pages'.

> The latest frightened recipient sent me this URL:

> http://technet.microsoft.com/en-us/security/advisory/2501584

> Regards



-- 
Mike Hobbs
------------------------------------------------------------
    To change, suspend or cancel your subscription go to
          //www.freelists.org/list/icon-users
------------------------------------------------------------


Other related posts: