On Mar 18, 2004, at 09:35, Nigel Metheringham wrote:
> I'd be interested if anyone has a exiscan acl rule that kills this off
> with a high degree of certainty since theres bound to be a pile of
> these
> around soon.
Well, I get zero viruses with the following snippet:
# Unpack MIME containers and reject file extensions used by worms.
# Note that the extension list may be incomplete.
# For reference, see:
# http://support.microsoft.com/default.aspx?scid=kb;EN-US;290497
deny message = We do not accept ".$found_extension" attachments
here.
demime =
bat:btm:cmd:com:cpl:dll:exe:lnk:msi:pif:prf:reg:scr:vbs:url:zip
-tor