KAM wrote:
>> Disable the RAR engine?
> 
> Don't know how to do that.  Can you give any more hints?

Well, for ClamAV it's as simple as editing /etc/clamd.conf; change this line
ScanRAR
... to this:
#ScanRAR

Hopefully your decompression-scanners have a similar configurability.

I suppose there's still the worry that someone will slip a virus into a .rar, 
then rename it to .zip, and rely on the client's unzipper "helpfully" 
recognizing the RAR format despite the wrong extension.

-- 
Matthew.van.Eerde (at) hbinc.com               805.964.4554 x902
Hispanic Business Inc./HireDiversity.com       Software Engineer

_______________________________________________
NOTE: If there is a disclaimer or other legal boilerplate in the above
message, it is NULL AND VOID.  You may ignore it.

Visit http://www.mimedefang.org and http://www.roaringpenguin.com
MIMEDefang mailing list [email protected]
http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Reply via email to