Vulnerability Development mailing list archives

Re: Virus Scan Notices in eMail


From: ctibbs () EAGLE YCP EDU (Colleen Tibbs)
Date: Wed, 28 Jun 2000 08:40:45 -0400


If the virus slipped through the system undetected the 'no virus
message' would be appended to the e-mail.  By adding it to your e-mail
wouldn't it then result in

 ****** Message from InterScan E-Mail VirusWall NT ******

 ** No virus found in attached file noname.htm

 *****************     End of message     ***************
 ****** Message from InterScan E-Mail VirusWall NT ******

 ** No virus found in attached file noname.htm

 *****************     End of message     ***************

Brian Kifiak wrote:

Hi,

Could someone enlighten me as to why many server-side eMail virus
scanners add this information to eMails they scan?

   ****** Message from InterScan E-Mail VirusWall NT ******

   ** No virus found in attached file noname.htm

   *****************     End of message     ***************

Is there something I'm missing, or isn't this actually a BAD thing?
If users get comfort from seeing messages like this, what's to stop
someone from adding this to an eMail containing a virus they want to
spread?  Wouldn't the user be more likely to open it?  (Assuming
your virus slipped through their detection mechanism undetected.)


Current thread: