I'm consistently stopping viruses from two systems that show up in the logs as NULL senders. Without an address I can't add them to the KILL file. Their IP addresses change, but stay in the same general ranges -- they use different ISP's. So I'm looking to a global rule that checks the header for host names of "oemcomputer" and "bigired" (w/o quotes), my two bad boys. Going to drop it in NUL. I would like the opinion of others. Will this do it? Is there a better way? Thanks. John Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
