Educause Security Discussion mailing list archives

Re: blocking .ZIP attachments


From: Michael_Maloney <Michael_Maloney () MIDDLESEXCC EDU>
Date: Fri, 20 Aug 2004 13:33:02 -0400

We don't block ZIP's persay, but if the zip file includes a file that is
included on our blocked attachment list, then both the zip file, and the
file inside are blocked, as well as the message is deleted. This was due to
the massive amount of spam-viruses that users were receiving.

So far the user community has been very accepting of this, I've only
received 1 complaint about this, and when I informed the user to have the
attachment renamed it would go thru they were agreeable to this.

Mike

********************************************
Mike Maloney
Sr. System Engineer
Middlesex County College
2600 Woodbridge Avenue
Edison, NJ 08818
Phone: 732-906-7754
Cell: 908-217-2086
Fax: 732-906-4266
Email: Michael_Maloney () middlesexcc edu
********************************************


-----Original Message-----
From: John C Borne [mailto:jcb () LSU EDU]
Sent: Thursday, August 19, 2004 5:53 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] blocking .ZIP attachments

I apologize if this topic has been discussed before, but I couldn't find
any direct mention of this specific issue recently.

We have a problem with viruses penetrating the campus "under the radar" so
to speak. Before a new virus is detected and the anti-virus update is
written, received, and distributed, we have a window of vulnerability. In
the past we have lost a considerable amount of time repairing these
outbreaks. The vector for many of these infections has been through
attachments especially .ZIP's. At first we were intermittently blocking
.zip and other attachments; going back and forth between blocking and
accepting as each new virus appeared. We found that keeping the zip's
blocked had a big impact on minimizing the impact of new virii.

We've gotten to the point where we cringe at the thought of unblocking
.zip's and would like to make it permanent. Before I propose this to the
administration, I wanted to see if anyone could comment on whether they
are, or are not, blocking zip's and other attachments and if not, what
other solutions they have considered.

Thanks.

John Borne
Asst Dir for System Support
Computing Services
Louisiana State University

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at http://www.educause.edu/cg/.

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: