Full Disclosure mailing list archives

RE: Fwd: YOUR PAYPAL.COM ACCOUNT EXPIRES


From: "Brown, Nicholas" <Nicholas_Brown () stercomm com>
Date: Thu, 20 Nov 2003 09:48:04 -0500

Bojan Zdrnja Wrote:
...
That is why you should implement content blocking at your e-mail server.
There is absolutely no reason to allow .scr files to go around. If you had
this blocked, it would stop MiMail-I without AV updates.
Also, note that this attachment has double extension, which should also be
automatically blocked.
...

It should be pointed out that blocking files with multiple extensions is
not good idea, as this would interfere with lots of legitimate,
non-executeable file types, such as .tar.gz.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: