Vulnerability Development mailing list archives

Sendmail vs *.vbs


From: tgarris () FRAMELOSS ORG (Todd Garrison)
Date: Sun, 7 May 2000 23:18:21 -0600


I was really bummed when I saw how they did it... I want to be able to
block all *attachments* that have the string .vbs in the name - I don't
want to rely on subject headers alone, but I haven't quite figured out
how yet.  I played with my .mc/.cf configs in sendmail for about six
hours trying to get it to play nice, but the problem seems to be that
all the different mailers describe their attachments differently.  I
must be pretty thick in the head, but the fact that I know others want
to do the same thing and I have yet to see a filter that does it (in
sendmail that is) bums me out.

I could just use procmail, but that only seems to work for local
delivery and is not any good for a relay server (for example - reducing
the risks of running MS-Exchange as the front-line mail exchanger on the
internet by relaying through sendmail).  Maybe I am wrong on this though
- can procmail be configured to process mail that isn't delivered locally?

Any sendmail gurus out there that can help enlighten us lesser beings?

Thanks,
Todd

Sendmail.com has released a procedure to block the Love letter virus
that's been nailing a lot of people today.  This works for the
Unix and NT versions of Sendmail.

http://www2.sendmail.com/loveletter/


Current thread: