Re: Anti Virus Mailscanners DOS

From: David F. Skoll (dfsat_private)
Date: Mon Feb 25 2002 - 15:52:51 PST

  • Next message: Menashe Eliezer: "RE: Windows Media Player executes WMF content in .MP3 files."

    On Mon, 25 Feb 2002, Eduardo R. Maciel wrote:
    
    > An antivirus mailscanner should check the filesizes inside a
    > compressed file like .tar.gz, .zip, .bz2, etc, BEFORE open the file
    > for scanning.
    
    MIMEDefang, in its normal configuration, does not look inside compressed
    files or archives.
    
    In general, I believe it is unwise for any virus scanner to look
    inside compressed files or archives unless explicitly told to do so in
    an interactive invocation.  The extra steps required to open such
    files and extract and execute the viral payload make it highly
    unlikely that viruses would propagate in this way.
    
    Viruses rely heavily on social engineering for propagation.  Archives
    and compression make such social engineering difficult.
    
    --
    David.
    



    This archive was generated by hypermail 2b30 : Thu Feb 28 2002 - 22:45:32 PST