[33424] in bugtraq
Re: RFC: virus handling
daemon@ATHENA.MIT.EDU (Casper Dik)
Wed Feb 4 16:21:48 2004
Message-Id: <200402032257.i13Mv6w21439@sunnl.Holland.Sun.COM>
To: David Brodbeck <DavidB@mail.interclean.com>
Cc: "'Daniele Orlandi'" <daniele@orlandi.com>, bugtraq@securityfocus.com
In-Reply-To: <C823AC1DB499D511BB7C00B0D0F0574C58467A@serverdell2200.interclean.com>
Date: Tue, 03 Feb 2004 23:57:06 +0100
From: Casper Dik <casper@holland.sun.com>
>
>
>> -----Original Message-----
>> From: Daniele Orlandi [mailto:daniele@orlandi.com]
>
>> I use amavisd-new which has support for listing viruses/worms
>> that fake
>> the sender's email address. Unfortunatelly the list is external to the
>> actual virus scanner and has to be updated manually.
>
>Given that the majority of new viruses forge the sender's email address, I
>think the reverse would make more sense -- have a list of viruses that
>*don't* forge, and only send notifications for those.
Considering that virus scanners still operate using signatures,
it seems logical to include a flag for each specific virus so that
when it is recognized the virus software knows that they shouldn't
bother me.
(A, and yes, it is a lot of fun that those virus scanner vendors sell
*localized* versions of their software so I've now had them tell me in
more languages and character sets than I care to remember how bloody
incompetent they are.)
Casper