Re: MyDoom.o: Time to move to MIME ACL
Steven Dickenson <[email protected]>
| Newsgroups | gmane.mail.exim.exiscan.user |
|---|---|
| Message-ID | <[email protected]> |
Rich, WhidbeyNET NOC wrote: > ClamAV catches all known variants of MyDoom, and we haven't had many > slip by while using it. The only exception is the brief time between an > outbreak and definition update, but blocking common executable file > types and password-protected zips helps. I am checking and bouncing for MIME errors (> 2), however this message still got through. And I know that ClamAV is catching most other MyDoom messages, from the logs. I'm wondering if the old demime condition can't properly decode the attachment for scanning, which is why I wanted to use the new MIME ACL code, hoping it can get around these errors. The log lines I mentioned correspond to the message that came through (which was then caught by GroupShield). However, no file was scanned anywhere near that time, according to the ClamAV logs (thank goodness for low mail volume). Thus, I'm wondering if these base64 errors resulting in the demime condition not being able to unpack the attachment. I've only seen these errors twice, and both correspond to a MyDoom.O caught by GroupShield. We currently block most MS executable formats at the gateway, but we leave ZIP files to be quarantined by Groupshield, so I can pull them out for users. If the ZIP is a known virus, exiscan is set to reject it, however. I will explore the examples mentioned by all. Many thanks. > Anyone else long for the days of pure-text email.. <raises hand> Steven -- Steven Dickenson <[email protected]> http://www.mrchuckles.net