On Nov 27, 2004, at 0:42, Justin Erenkrantz wrote:
This does include exe_filter, but as Ask said, "Why aren't we including that?"
I don't if anyone's approached the author of that plugin about bundling it.
Matt and I talked to Gavin about it and I think we stalled on Gavin and Matt wanting to improve the MIME handling (in a general way) first.
And make sure before it gets added to the Qpsmtpd project that any additional executable signatures get added, too. I know of only one additional:
TVoAAAEAAA
which is used by some .SCR files. It might be worthwhile to take the full list of M$loth executable extensions and write a program to search and encode all files on a Win32 installation and extract the signatures. Then, have people run that program on as many different releases of Winblows as possible and make sure that there aren't any executable headers that we are missing. It's been more than a few years since Russ's original virusscan patch, so the odds are there are at least a couple of newer M$loth executable headers which we are missing.
John
