Bugtraq mailing list archives
Procmail scanning for hostile macros in Microsoft document e-mail
From: jhardin () wolfenet com (John D. Hardin)
Date: Wed, 31 Mar 1999 11:01:37 -0800
I have added some rudimentary scanning for possibly hostile macros in Microsoft Word and Excel attachments to my Procmail-based email sanitizer. This scanning is for code fragments that do things that shouldn't be in document macros rather than any particular variant of an existing virus or worm, so it should be generally effective. I'd like to have some third-party comment and beta testing before I release it. Anyone interested should send me some email at <jhardin () wolfenet com> and I'll send the html-trap.procmail filter with the added attachment scanning code. I hope to publicly release this modification tomorrow or Friday. For further information on the Procmail e-mail sanitizer, visit ftp://ftp.rubyriver.com/pub/jhardin/antispam/procmail-security.html -- John Hardin KA7OHZ jhardin () wolfenet com pgpk -a finger://gonzo.wolfenet.com/jhardin PGP key ID: 0x41EA94F5 PGP key fingerprint: A3 0C 5B C2 EF 0D 2C E5 E9 BF C8 33 A7 A9 CE 76 ----------------------------------------------------------------------- In the Lion the Mighty Lion the Zebra sleeps tonight... Dee de-ee-ee-ee-ee de de de we um umma way! ----------------------------------------------------------------------- 48 days until Star Wars episode I
Current thread:
- Re: Melissa Macro Virus, (continued)
- Re: Melissa Macro Virus Nick FitzGerald (Mar 29)
- Re: Melissa Macro Virus Kuo, Jimmy (Mar 26)
- Re: Melissa Macro Virus Jim Reavis (Mar 26)
- Re: Melissa Macro Virus Doug Granzow (Mar 29)
- Re: Melissa Macro Virus Brett Glass (Mar 28)
- Bug in xfs Lukasz Trabinski (Mar 29)
- ICQ Webserver bug Kerb (Mar 29)
- IE 5.0 allows reading and sending local files to a remote server Georgi Guninski (Mar 30)
- Excel Virus Seree Visitseelwat (Mar 30)
- Re: IE 5.0 allows reading and sending local files to a remote Andrew Tulloch (Mar 31)
- Procmail scanning for hostile macros in Microsoft document e-mail John D. Hardin (Mar 31)
- Excel variant of Melissa Marcel de Haas (Mar 30)
- Re: Excel variant of Melissa Ken Pfeil (Mar 31)
- Bug in xfs Lukasz Trabinski (Mar 29)
- Re: Bug in xfs Roman Drahtmueller (Mar 30)
- Re: Bug in xfs Matthieu Herrb (Mar 30)
- Re: Bug in xfs Juha Virtanen (Mar 30)
- Re: Bug in xfs Alan Cox (Mar 31)
- [support_feedback () us-support external hp com: Security Bulletins Patrick Oonk (Mar 31)
- Re: Melissa Macro Virus Brett Glass (Mar 30)
- Re: Melissa Macro Virus Dimitry Andric (Mar 31)