Exactly why I use the /COLLECT /DUMB switches in f-prot. I did a little more
testing, and it appears to catch more than I thought it did. It seems to miss
"forwarded" messages much more often(almost always). Have a copy of emanuel
it missed under all "winmail.dat" circumstances though.
Jerry
----- Original Message -----
From: "Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, January 18, 2001 12:04 PM
Subject: Re: [IMail Forum] Virus scanning in TNEF format
> > I've had f-prot detect a couple of winmail.dat problems. Testing
> > show it's hit or miss though. Probably just enough of the
> > signature f-prot's looking for left un-molested to be picked up.
>
> It may have something to do with the number of attachments, or their order.
When Declude decodes the TNEF segment, the file that it creates contains the
attachments intact... but, they are hidden among other Microsoft properties
and such. If the virus scanner simply scans the whole file for virus
signatures, it will find them. But, if it uses time-saving algorithms to only
check pieces of the file, then it may not see them.
>
> TNEF is apparently only used when using RTF in Outlook. We will definitely
be adding support for TNEF. Maybe someday Microsoft will take my advice and
eschew obfuscation.
> -Scott
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/