[Esd-l] exe

John D. Hardin jhardin at impsec.org
Wed Jun 25 19:18:22 PDT 2003


On 25 Jun 2003, Martin Bourque wrote:

> We are seeing a large number of messages coming in right now (over 150
> today) with an attached file called your_details.zi->details.pif that
> seem to be getting by the sanitizer.  We have *.pif in the poisoned file
> list.  Have you seen this yet?

Yes, I have.

The sanitizer does not unwrap .ZIP files.

I am working on a local rule to trap this one. Check the mailing list
tomorrow morning.

--
 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org                        pgpk -a jhardin at impsec.org
 key: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  The fetters imposed on liberty at home have ever been forged out
  of the weapons provided for defense against real, pretended, or
  imaginary dangers from abroad.
                                            -- James Madison, 1799
-----------------------------------------------------------------------
   496 days until the Presidential Election



More information about the esd-l mailing list