[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Yet Another Virus was Re: [cobalt-users] Spam



On Wednesday, Aug 20, 2003, at 01:21 US/Eastern, René Mølsted wrote:
What we did, was blocking all mails with the stated subjects, so "nobody" accually got the virusthrough our servers.

I've been using the Procmail Sanitizer <http://www.impsec.org/email-tools/procmail-security.html> on our Qube3 since Badtrans and Goner. It has been stopping the latest round quite effectively without need of an update; it simply stops any message with a "Windows Executable" attachment. (Among other things, it strips any attachment with a .pif or .scr extension.)

That's pretty crude, but more accurate than simply subject-blocking; someday, by accident, someone will use that subject on an innocent email and not know why their message didn't get through.

The Sanitizer stopped 160 last night, when it usually finds fewer than 10 with fewer than 30 users on the system.

pjm