IDS mailing list archives
Re: Fortinet IDS
From: nick black <dank () qemfd net>
Date: Mon, 26 Jul 2004 21:45:28 +0000 (UTC)
On 2004-07-26, Craig Bumpstead <cbumpste () praxsus dyndns org> wrote:
In regard to a limit of 10MB for AV scanning, in my career I have never seen a 10Mb virus, this is not to say that it isn't possible. By imbedding a virus/Trojan in another file.
But a virus needn't be 10Mb to embed its own mailer, run an SMTP reject code against known AV agents, and generate such a thing on the fly. -- nick black "np: the class of dashed hopes and idle dreams." free hearts, free foreheads -- you and i are old; old age hath yet his honour and his toil; death closes all: but something ere the end, some work of noble note, may yet be done, not unbecoming men that strove with gods. (tennyson) -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
Current thread:
- Fortinet IDS Kyle Maxwell (Jul 25)
- <Possible follow-ups>
- RE: Fortinet IDS Teicher, Mark (Mark) (Jul 25)
- RE: Fortinet IDS JAVIER OTERO (Jul 26)
- RE: Fortinet IDS Craig Bumpstead (Jul 26)
- Re: Fortinet IDS nick black (Jul 27)
- RE: Fortinet IDS travis . alexander (Jul 26)
- RE: Fortinet IDS Jason J. W. Williams (Jul 27)
- RE: Fortinet IDS Ron Gula (Jul 27)