Re: [Exim] LoveBug as HTML attachment

Top Page
Delete this message
Reply to this message
Author: Vadim Vygonets
Date:  
To: exim-users
Subject: Re: [Exim] LoveBug as HTML attachment
Quoth Paul Golds on Fri, May 05, 2000:
> Guess it's time to start work on something to filter for .htm/.html
> attachments and then, if there, check for any VBS inside of it?


No. It's time to filter for .htm/.html attachments and then, if
there, throw the message away. Same goes for GIFs, JPEGs, Word
documents, Excel spreadsheets, and messages larger than 50K.

As Yann said, looking into the message body is expensive. Any
filtering (except maybe filtering by envelope and headers) takes
lots of resources. If you have a couple of thousands of users,
it may not be a problem, but if you really deliver lots of mail,
then you've got a problem. One solution to the virus problem may
be to ban Outloop and other mailers that are known to execute
code they receive (for security reasons), and to forbid people to
send and receive Word documents, executable binaries, and other
dangerous stuff (for security reasons). HTH.

Vadik.

--
Rex is to Regina as Vax is to...