Re: Nessus DOS attack against Sophie
Mark Martinec <[email protected]> Thu, 16 Sep 2004 14:54:54 +0200
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
| We use Sophie from mimedefang and are verify satisfied with | it. However, one of my collegaues ran the Nessus security scanner | enabling 'dangerous' tests. As part of the test, it sent a | mail through our mailserver. It caused severe overloading of | the filter machine. A zip file which was part of the mail contained zip | files containing zip files which untimately ended up in some verfy large | .dll files. I've searched the web for info about how to configuere | Sophos/Sophos to cope with such DOS attacks but have found no | solution. I don't think Sophos offers a solution for this. | I'll be glad to hear if there's a solution our there so that | we are prepared the day somebody decides to launch a real attack | against us. If Sophie is called via amavisd-new, the mail bomb protection is provided by its decoding. In case of a mail bomb the virus scanners are not called, and depending on the settings the mail either arrives to the recipient with ***UNCHECKED** in the subject and a MIME part with a warning prepended to a MIME-wrapped original mail, or MTA (Postfix) can be configured to place it on hold. Mark