Re: MyDoom.o: Time to move to MIME ACL

Steven Dickenson <[email protected]>
Newsgroups gmane.mail.exim.exiscan.user
Message-ID <[email protected]>
Rich, WhidbeyNET NOC wrote:
> ClamAV catches all known variants of MyDoom, and we haven't had many 
> slip by while using it. The only exception is the brief time between an 
> outbreak and definition update, but blocking common executable file 
> types and password-protected zips helps.

I am checking and bouncing for MIME errors (> 2), however this message 
still got through.  And I know that ClamAV is catching most other MyDoom 
messages, from the logs.  I'm wondering if the old demime condition 
can't properly decode the attachment for scanning, which is why I wanted 
to use the new MIME ACL code, hoping it can get around these errors.

The log lines I mentioned correspond to the message that came through 
(which was then caught by GroupShield).  However, no file was scanned 
anywhere near that time, according to the ClamAV logs (thank goodness 
for low mail volume).  Thus, I'm wondering if these base64 errors 
resulting in the demime condition not being able to unpack the 
attachment.  I've only seen these errors twice, and both correspond to a 
MyDoom.O caught by GroupShield.

We currently block most MS executable formats at the gateway, but we 
leave ZIP files to be quarantined by Groupshield, so I can pull them out 
for users.  If the ZIP is a known virus, exiscan is set to reject it, 
however.

I will explore the examples mentioned by all.  Many thanks.

 > Anyone else long for the days of pure-text email..

<raises hand>

Steven
-- 
Steven Dickenson <[email protected]>
http://www.mrchuckles.net
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.