I hate to say it, because it sucks, but I had mentioned it before... A
challenge/response system for attachments.  It could cause a bunch of crap,
but since all these viruses forge the return address a user is likely to say
"no, I didn't send that" and that could reduce the number of viruses
exponentially.

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Todd Ryan
Sent: Friday, March 05, 2004 7:15 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Bagle.J / news.com article on AV software
opening zipped files.

This is a good segway into something that I see as an even bigger 
problem coming.  The virus writers are passing on "easy to invoke, easy 
to catch" attachments and preying on social vulnerabilities.  Until now, 
we've been focusing on blocking things that are very easy for a user to 
launch by accident.  But what's next?

We've seen that they can circumvent our virus scanners by password 
protecting zip files.  I see the next one coming around something like this:

Rename the attached "superduperpatch.txt" file to "superduperpatch.exe" 
and install it immediately or we (your ISP) will shut down your internet 
access.  ....blah blah blah...

In such a case, many of us do not scan .txt files, assuming they're 
safe.  I just looked and sure enough, I have SKIPEXT TXT in my virus.cfg 
file. 

In other words, any techniques we, the good guys are currently offering 
our customers/clients so they can get around banned file extention 
policies, are fair game to the virus writers.  And what if  they decide 
to rename  password protected zip file "ZI_" or any number of other 
combinations that would keep us from being able to catch it?  We now 
know that users WILL jump through hoops to open something that they 
think is very important.

It seems to me that anything is fair game and they've proven they'll 
stoop to any level to get around the safegaurds we have in place.  It 
also seems to me that what we've been doing up to now is no longer good 
enough.

So what do we do to proactively thwart the next "we hadn't even thought 
of that" idea they come up with?  Do we make sure to scan EVERY file 
regardless of extension?  How would we know if the contents of any 
particular file are encrypted or protected if we can't determine the 
true file type from the extension? 

Does this worry anyone else as much as it does me?

--Todd.



R. Scott Perry wrote:

>
>> that is going to be a chalenge for scott to incorporate in declude :)
>
>
> It's unlikely that we will do this.  It makes for a great marketing 
> gimmick, but won't work in the long term.  All it will take is for a 
> virus to say "The password is  1 2 3 4 5" or "The password is 12344 
> plus 1", and those AV programs will quickly leave the spotlight.
>
>> We are an isp, and for us blocking zips is out of the question.
>
>
> Remember that all AV programs can catch viruses in standard .ZIP 
> files.  It's only the encrypted .ZIP files that pose a problem, and it 
> is recommended that people block all encrypted .ZIP files (but allow 
> standard .ZIP files through).  That way, extremely few people are 
> inconvenienced, but it would be very hard for a virus to get through.
>
>                                                    -Scott
> ---
> Declude JunkMail: The advanced anti-spam solution for IMail 
> mailservers since 2000.
> Declude Virus: Catches known viruses and is the leader in mailserver 
> vulnerability detection.
> Find out what you've been missing: Ask for a free 30-day evaluation.
>
> ---
> [This E-mail was scanned for viruses by Declude Virus 
> (http://www.declude.com)]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
---
[This E-mail scanned for viruses by Declude Virus]




---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to