Autor: Giuliano Gavazzi Data: A: Matt, exim CC: Assumpte: Re: [exim] Emergency!!! Is anyone else getting this virus/worm?
At 1:24 pm +0000 2004/11/14, Matt wrote: >Odhiambo G. Washington wrote:
>
>> I still don't understand why a 1.9MB mail turns out to be 1GB when
>> decompressed for scanning by exiscan+clamd.
>
>
> Are the emails which are causing this legitimate emails?
>
> This is something which ought to be discussed on the ClamAV list, but the
>common name for this type of thing, if there are no problems with exiscan,
>are archive/zip/mail bombs. (Take your pick). That is why you need to make
>sure recursion depths and max compression levels are enabled in
>clamd.conf. Also, make sure you are running version 0.80 of Clam.
>
do you mean that one could compress a 10GB file of "aaaaaaa..." into
a tiny attachment and send it over.. how clever! We should use that
against those servers that send out virus notices for forged sender
emails.