|
Declude Virus will *not* detect abuse of MS05-16 with the Declude CLSID
vulnerability detector.
They
are entirely different animals, which happen to have CLSID at their
heart.
The
only way to attack MS05-16 abuse with Declude Virus is with a) keep your virus
scanner up to date, and/or b) to watch for virus news and ban extensions that
are deliberately crafted as bogus, e.g. .d0c or .doc_ instead of
.doc
The
only way to attack MS05-16 abuse with Declude JunkMail is to dream up ways to
tell apart MIME filename lines that are valid from the ones that are
bogus. Given that Macintoshes will send files to PC users without a file
extenstion, and given the lack of regular expressions and fine control over
substring matching, I think this is a fool's errand. Leave it up to your
antivirus scanner.
Ok,
John, get back to fixing that mirrored drive set.
Andrew
8)
|
Title: Message
- [Declude.Virus] MS05-16 Exploit Andy Schmidt
- RE: [Declude.Virus] MS05-16 Exploit John Tolmachoff \(Lists\)
- Re: [Declude.Virus] MS05-16 Exploit Matt
- Re: [Declude.Virus] MS05-16 Expl... Darrell \([EMAIL PROTECTED])
- RE: [Declude.Virus] MS05-16 Exploit Dave Marchette
- Re: [Declude.Virus] MS05-16 Exploit Colbeck, Andrew
- Re: [Declude.Virus] MS05-16 Exploit NIck Hayer
- RE: [Declude.Virus] MS05-16 Exploit John Tolmachoff \(Lists\)
- Re: [Declude.Virus] MS05-16 Expl... Darin Cox
- RE: [Declude.Virus] MS05-16 Exploit Dave Marchette
