RE: CRIME WORM_Sobig.A blocked but dealing with the residual address...

From: alan (alan@private)
Date: Mon Jan 20 2003 - 07:56:32 PST

  • Next message: Todd Ellner: "CRIME Hope this isn't too spammish"

    On Mon, 20 Jan 2003, Andrew Plato wrote:
    > Well, if the from address was consistently big@private you could filter
    > it out via a mail proxy or anti-spam system. However, since the address
    > may change that probably isn't possible. Basically you would need some
    > kind of reactive and dynamic filtering product that sits before your
    > mail server. Trend Micro has a virus wall product that can drop emails
    > that contain known intrusions. Other in-line prevention systems like
    > attack mittigator from Top Layer would have that capability as well. 
    Any reasonably up to date virus mail scanner should be able to find that 
    one.  It is only one of many exploiting the worm propagation device that 
    is Outlook.

    This archive was generated by hypermail 2b30 : Mon Jan 20 2003 - 16:46:58 PST