[Esd-l] ZIP scanning, take two (repost)

John D. Hardin jhardin at impsec.org
Mon Feb 23 13:14:22 PST 2004


On Mon, 23 Feb 2004, Mike Dini wrote:

> Have we updates our sanitizer in the last few months?  Should we?

You should be on 1.140 for the improvement in forged-Received-header
hardening. Earlier versions will generate a *lot* of mydoom (et. al.)
backscatter.

The zipfile stuff is still in development/beta and won't be released
earlier than this coming weekend.

--
 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org                        pgpk -a jhardin at impsec.org
 key: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  "Bother," said Pooh as he struggled with /etc/sendmail.cf, "it never
  does quite what I want. I wish Christopher Robin was here."
				-- Peter da Silva in a.s.r
-----------------------------------------------------------------------
   40 days until the Slovakian Presidential Election


More information about the esd-l mailing list