home :: technology :: microsoft :: messengerspam.txt

May 05, 2004

Messenger Spam is Evil

Wow, I'm out of touch with every day users. I've been running on properly firewalled network now since the summer of 98' and on Linux for over a year now. Consequently, I completely missed one of the nastyest side effects of having your computer plugged straight into the Internet.

If you've got a WinNT/2k/XP machine and aren't behind a firewall, you'll be barraged by so called "Messenger Spam" which pops up real looking windows message boxes as if they were coming from a system administrator. This is because they use the same exact interface as admins would use inside a private network. Yes, I know this is old news, but I'm just catching now as I work on a friend's PC which is, *gasp*, out on the net without a firewall. (Yes I'll be fixing that too, don't worry.)

The idea is simple, I just can't believe Microsoft left this glaring a hole in their product. You should at least have to be authenticated to the same domain to send a message like this. Ug.

Anyway, the fix is easy - just disable the "messenger" service. (not to be confused with Windows Messenger, which is another ball of wax entirely with it's own bugs and spam). To disable the service, just go into the services console in "Administrative tools" and change the messenger service from "Automatic" to "Disable" and then right click and stop the service.

Oh yeah, while you're at it, you'll probably want to update to keep out nasties like the new sasser worm.