Re: Nessus DOS attack against Sophie

Mark Martinec <[email protected]> Thu, 16 Sep 2004 14:54:54 +0200
Newsgroups gmane.comp.security.virus.vtools
Message-ID <[email protected]>
| We use Sophie from mimedefang and are verify satisfied with
| it. However, one of my collegaues ran the Nessus security scanner
| enabling 'dangerous' tests. As part of the test, it sent a
| mail through our mailserver. It caused severe overloading of 
| the filter machine. A zip file which was part of the mail contained zip
| files containing zip files which untimately ended up in some verfy large
| .dll files. I've searched the web for info about how to configuere
| Sophos/Sophos to cope with such DOS attacks but have found no
| solution.

I don't think Sophos offers a solution for this.

| I'll be glad to hear if there's a solution our there so that
| we are prepared the day somebody decides to launch a real attack
| against us.

If Sophie is called via amavisd-new, the mail bomb protection is
provided by its decoding. In case of a mail bomb the virus scanners
are not called, and depending on the settings the mail either
arrives to the recipient with ***UNCHECKED** in the subject and
a MIME part with a warning prepended to a MIME-wrapped original mail,
or MTA (Postfix) can be configured to place it on hold.

  Mark