While the PayPal messages apparently aren't properly formatted via the
RFC's, they clearly aren't "vulnerabilities."

That's kind of like saying "That package that says 'bomb inside' doesn't really have a bomb in it, and so even though it says it does, it isn't dangerous." That's very true. But are you going to open such a package? I certainly would not.


I have always considered this
one of Declude's most questionable "features."  For marketing purposes, this
is touted as something that Declude stops while other programs don't.  It
isn't well explained and would lead people to believe that anything it traps
is something nasty.  The truth is that most things it traps are legitimate
emails that are the product of badly-coded email programs.  A more accurate
method of detecting *real* exploits of the blank folding problem would
certainly be very appreciated.

The E-mail PayPal is sending out does indeed contain a vulnerability (or exploit, hole, whatever you want to call it).


Specifically, if it has a virus in it that caused that vulnerability to appear there, it is not believe that there is any mailserver virus scanner on the planet that will block the virus, *unless* it is caught as a vulnerability.

The only reason that it is considered a questionable feature is because of all the irresponsible AV companies out there (Ipswitch included!) that takes the "No viruses use the vulnerability yet, it will cost us too much to detect them, it's easier to apologize to customers for taking 3 weeks to release a new version than apologize to our shareholders for reduced profits..." attitude. If they were all blocking them (as they should), nobody would be complaining to us or to other AV companies.

Yes, many people see mailserver AV vulnerabilities as a non-serious issue -- but that's only because no virus has used them yet, and all they see are the handful of legitimate E-mails that have the vulnerability in them. People get very upset when it takes an AV company 24 hours to get new virus definitions -- imagine how they are going to feel when they have an AV product that takes weeks to release a new version. Remember, mailserver AV programs that do not detect these vulnerabilities are going to require a new release (.exe file), not just new virus definitions.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to