Re: [Full-Disclosure] MyDoom-M evades attachment filters

2004-07-29 Thread lsi
Err, Pegasus Mail :) (a free POP3 client) Seriously..! When I get some time I plan to add the exe and zip filters to SpamPal, which is a free Windows-based anti-spam POP3 proxy that supports multiline regular expressions. It has some virus- specific base-64 sigs, but does not currently have

Re: [Full-Disclosure] MyDoom-M evades attachment filters

2004-07-28 Thread William Warren
what are you using for attachment filters? my astaro attachment filter is killing mydoom without one getting through. lsi wrote: Since the first MyDoom (which appeared almost six months ago, to the day) I have been nice and snug behind my executable attachment filter. And my zipfile

[Full-Disclosure] MyDoom-M evades attachment filters

2004-07-27 Thread lsi
Since the first MyDoom (which appeared almost six months ago, to the day) I have been nice and snug behind my executable attachment filter. And my zipfile attachment filter. But then MyDoom-M slips past The reason is because it puts spaces or newlines into its MIME. Very smart.

Re: [Full-Disclosure] MyDoom-M evades attachment filters

2004-07-27 Thread Marek Isalski
lsi [EMAIL PROTECTED] 27/07/2004 11:14:20 My current thoughts are something like this: U.*E.*s.*D.*B.*A.*o.*A.*A.* Still got newline prob though. Careful -- that (corrected) regexp will overoptimistically match strings like: 'United Arab Emirates branch seeks Data Base Administrator to work