[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Block .pif files



On Thursday, Aug 21, 2003, at 18:34 US/Eastern, Santiago Montalvan wrote:
We have a Qube3 at work and we keep getting e-mails w/ attachments w/ .pif and .scr extensions. Is there any way that I can modify Sendmail and block
any e-mail w/ these attachments?

I strongly recommend use of The Procmail Sanitizer. You can find more information about it at <http://www.impsec.org/email-tools/procmail-security.html>, and I describe my installation on our Qube3 at <http://bluebird.sinauer.com/~morse/cobalt/procmail.html> (scroll down past the SpamAssassin instructions.)

It is a drop-in script which uses Procmail and Perl to monitor incoming email. I installed ours about five hours before Goner hit (nearly 18 months ago?) and we haven't been bothered by a virus outbreak since. It has picked up BadTrans, Klez and SoBig variants without needing specific updates.

Of course, people can't send you Windows executables by email, but WTF would you want a Windows executable in your email anyway?

pjm