Firewall Wizards mailing list archives

Re:


From: Bill_Royds () pch gc ca
Date: Sat, 20 May 2000 12:59:13 -0400

I have seen most copies of the .vbs vira coming  in as MIME type
application/octet-stream rather than
application/x-unknown.
 This MIME type is also used from many legitimate attachments such as
WordPerfect documents and binary data.
So blocking it can a greater denial of service than the risk of the virus/worm
itself.




Matt Lind <matt_lind () yahoo com> on 05/19/2000 08:22:57

Please respond to Matt Lind <matt_lind () yahoo com>
                                                              
                                                              
                                                              
 To:      firewall-wizards () nfr net                            
                                                              
 cc:      (bcc: Bill Royds/HullOttawa/PCH/CA)                 
                                                              
                                                              
                                                              
 Subject:                                                     
                                                              





Most of you may be aware of a way to strip these new
.vbs viruses at the firewall. However I was not, and
will post what appears to be working for us. I am
using  Firewall-1.

Configure your SMTP resource,
under action,
strip mime of type
add- application/x-unknown

Any feedback is welcome.
Thanks,
Matt Lind




__________________________________________________
Do You Yahoo!?
Send instant messages & get email alerts with Yahoo! Messenger.
http://im.yahoo.com/





Current thread: