RE: VIRUS WARNING

From: Jon (jon@dakota-truck.net)
Date: Thu Sep 21 2000 - 11:25:33 EDT


On Wed, 20 Sep 2000, Bernd D. Ratsch wrote:

> Uhhhh...good point. John?
>
> - Bernd

  
  Yep, I have several filters set up to catch attachments. However, there
are different types of attachments; since the body of the message is ASCII,
the only way to know if it is an attachment or not is by looking at the
e-mail headers (except for uuencoded stuff). Anyway, the filters work by
looking at the content type; usually it is text/plain, but it checks for
text/html and multipart/mixed, as those are both attachments. The type on
this attachment on this virus was application/octet-stream; haven't seen
that one before.

  But, the good news is that a new filter has been set up, so there's one
less type of attachment that'll make it though in the future. :-P

                                              -Jon-

  .---- Jon Steiger ----- jon@dakota-truck.net or jon@twistedbits.net ------.
  | Affiliations: AOPA, DoD, EAA, NMA, NRA, SPA, USUA; Rec & UL Pilot - SEL |
  | '92 Ram 150 4x4 V8, '96 Dakota V8, '96 Intruder 1400, '96 FireFly 447 |
  `------------------------------ http://www.cs.fredonia.edu/~stei0302/ ----'



This archive was generated by hypermail 2b29 : Fri Jun 20 2003 - 11:54:42 EDT