For some reason we've been getting hit with new virii just ahead of their inclusion in the scanner databases recently. Has anyone come up with a clever way to parse the logs or another way to quickly notice if the first IP in the received headers belongs to your own ranges so that after the scanner detects the virus you can quickly find internal boxes already infected?
--- Les Mikesell [EMAIL PROTECTED] _______________________________________________ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

