That is exactly why I suggested scanning for file types instead of
extension.  I think Scott mentioned that they need to include full MIME
decoding before something like that would be possible.

Scott, how feasible is this idea for inclusion?

Darin.


----- Original Message ----- 
From: "Todd Ryan" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, March 05, 2004 7:14 AM
Subject: Re: [Declude.Virus] Bagle.J / news.com article on AV software
opening zipped files.


This is a good segway into something that I see as an even bigger
problem coming.  The virus writers are passing on "easy to invoke, easy
to catch" attachments and preying on social vulnerabilities.  Until now,
we've been focusing on blocking things that are very easy for a user to
launch by accident.  But what's next?

We've seen that they can circumvent our virus scanners by password
protecting zip files.  I see the next one coming around something like this:

Rename the attached "superduperpatch.txt" file to "superduperpatch.exe"
and install it immediately or we (your ISP) will shut down your internet
access.  ....blah blah blah...

In such a case, many of us do not scan .txt files, assuming they're
safe.  I just looked and sure enough, I have SKIPEXT TXT in my virus.cfg
file.

In other words, any techniques we, the good guys are currently offering
our customers/clients so they can get around banned file extention
policies, are fair game to the virus writers.  And what if  they decide
to rename  password protected zip file "ZI_" or any number of other
combinations that would keep us from being able to catch it?  We now
know that users WILL jump through hoops to open something that they
think is very important.

It seems to me that anything is fair game and they've proven they'll
stoop to any level to get around the safegaurds we have in place.  It
also seems to me that what we've been doing up to now is no longer good
enough.

So what do we do to proactively thwart the next "we hadn't even thought
of that" idea they come up with?  Do we make sure to scan EVERY file
regardless of extension?  How would we know if the contents of any
particular file are encrypted or protected if we can't determine the
true file type from the extension?

Does this worry anyone else as much as it does me?

--Todd.



R. Scott Perry wrote:

>
>> that is going to be a chalenge for scott to incorporate in declude :)
>
>
> It's unlikely that we will do this.  It makes for a great marketing
> gimmick, but won't work in the long term.  All it will take is for a
> virus to say "The password is  1 2 3 4 5" or "The password is 12344
> plus 1", and those AV programs will quickly leave the spotlight.
>
>> We are an isp, and for us blocking zips is out of the question.
>
>
> Remember that all AV programs can catch viruses in standard .ZIP
> files.  It's only the encrypted .ZIP files that pose a problem, and it
> is recommended that people block all encrypted .ZIP files (but allow
> standard .ZIP files through).  That way, extremely few people are
> inconvenienced, but it would be very hard for a virus to get through.
>
>                                                    -Scott
> ---
> Declude JunkMail: The advanced anti-spam solution for IMail
> mailservers since 2000.
> Declude Virus: Catches known viruses and is the leader in mailserver
> vulnerability detection.
> Find out what you've been missing: Ask for a free 30-day evaluation.
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

_____________________________________
[This E-mail virus scanned by 4C Web]


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to