We are using the Imail antivirus system in addition to filtering for
executables.  Just trying to layer my defenses a bit here. 

-----Original Message-----
From: R. Scott Perry [mailto:[EMAIL PROTECTED] 
Sent: Tuesday, January 20, 2004 11:08 AM
To: [EMAIL PROTECTED]
Subject: RE: Filtering executables (was: RE: [IMail Forum] New "BAGLE"
virus in the wild!!)


>I'll give it a whirl and see what happens. We get falses every few days

>right now so I'll know within a week or so if it helped.

Just so you are aware:

>B~Content-Disposition\:\sattachment;\s*filename=".{0,100}\dot-com"\s{1,
>10}:[EMAIL PROTECTED]

This one will miss some viruses (if the MIME headers do not appear in
the assumed order), or if the MIME headers are malformed (as is expected
to be the case with future viruses).  It also will only detect MIME
encoded attachments, not some of the lesser used formats (such as
uuencoded, BinHex or TNEF).  However, it should catch a significant
percentage of viruses while catching few legitimate HTML E-mails.

                                                    -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver
vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to