Re: [sniffer] Bagle J others

2004-03-03 Thread Madscientist
At 01:33 PM 3/3/2004, you wrote: On Mar 3, 2004, at 12:44 PM, Madscientist wrote: We have adopted the current policy at least for the short term: 1 ) We block all potentially hazardous extensions including .zip. Can these virus rules be bypassed? We have real virus checking and don't want our

[sniffer] Rules Question

2004-03-03 Thread Keith Johnson
I am using Declude and have indiv. Sniffer Tests and lets say the following gets tripped in an email SNIFFER-WHTLIST result code 000 SNIFFER-PORNresult code 054 Which would take precedence over the other, as far as which would be the final code passed to Declude? Thanks, Keith This

Re: [sniffer] Rules Question

2004-03-03 Thread Madscientist
At 04:55 PM 3/3/2004, you wrote: I am using Declude and have indiv. Sniffer Tests and lets say the following gets tripped in an email SNIFFER-WHTLIST result code 000 SNIFFER-PORNresult code 054 Which would take precedence over the other, as far as which would be the final code passed to

RE: [sniffer] Rules Question

2004-03-03 Thread Keith Johnson
Thanks for the aid. One last question, you mentioned: In a case where a white rule is present and a black rule is present the white rule will always win So if the White Rule fired 000, it would override a Porn Rule of 54? If so, how are these White Rules entered? Thanks, Keith

RE: [sniffer] Rules Question

2004-03-03 Thread Madscientist
White rules are entered either upon request or in response to a false positive report with your permission. In some cases we will enter a white rule based on our own research or in response to a false positive report if we feel a core white rule would be more appropriate. We add core white