Author: Ted Roche
Posted: 2003-02-27 08:04:00 Link
Ed:
Is it possible it is slipping through because of the type of encoding? On
the suspicious message, I saw this in the header:
Content-Transfer-Encoding: base64
Content-Type: application/octet-stream;name=picacu.exe
McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a flaw in
Microsoft's MIME handling, allowing the EXE to run when the message is
viewed. Details at:
http://vil.mcafee.com/dispVirus.asp?virus_k=99273
-----Original Message-----
From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of
Ed Leafe
Sent: Thursday, 27 February, 2003 08:17
To: ProFox@leafe.com
Subject: Re: [ADMIN] Just testing the attachment stripping...
On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:
> Hmm... another attachment with a virus made it through earlier. I'm
> sending an innocuous zip file to see if that makes it through.
Well, that was OK. Let's try with a simple EXE.
___/
/
__/
/
____/
Ed Leafe
--- StripMime Report -- processed MIME parts ---
multipart/mixed
text/plain (text body -- kept)
application/zip
---
[excessive quoting removed by server]
Author: Ed Leafe
Posted: 2003-02-27 08:13:00 Link
On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:
> Hmm... another attachment with a virus made it through earlier. I'm
> sending an innocuous zip file to see if that makes it through.
Well, that was OK. Let's try with a simple EXE.
___/
/
__/
/
____/
Ed Leafe
--- StripMime Report -- processed MIME parts ---
multipart/mixed
text/plain (text body -- kept)
application/zip
---
Author: Ed Leafe
Posted: 2003-02-27 08:18:00 Link
On Thursday, February 27, 2003, at 08:38 AM, Ted Roche wrote:
> Is it possible it is slipping through because of the type of encoding?
> On
> the suspicious message, I saw this in the header:
>
> Content-Transfer-Encoding: base64
> Content-Type: application/octet-stream;name=picacu.exe
>
> McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a
> flaw in
> Microsoft's MIME handling, allowing the EXE to run when the message is
> viewed. Details at:
StripMime doesn't try to be too smart. It will strip all attachments
without consideration of their content. The only 'thinking' it does is
when there is an HTML attachment. In that case, if there is no plain
text available, it removes all HTML markup and reformats the message to
be plain text. So I can't see why this is happening.
___/
/
__/
/
____/
Ed Leafe
Hmm... another attachment with a virus made it through earlier. I'm
sending an innocuous zip file to see if that makes it through.
___/
/
__/
/
____/
Ed Leafe
--- StripMime Report -- processed MIME parts ---
multipart/mixed
text/plain (text body -- kept)
application/zip
---
Author: Gary Sutherland
Posted: 2003-02-27 09:23:00 Link
Given that I'm running IE6 presumably I'm not at risk?
Cheers
Gary
-----Original Message-----
From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of
Ted Roche
Sent: Thursday, February 27, 2003 1:58 PM
To: profox@leafe.com
Subject: RE: [ADMIN] Just testing the attachment stripping...
Ed:
Is it possible it is slipping through because of the type of encoding?
On
the suspicious message, I saw this in the header:
Content-Transfer-Encoding: base64
Content-Type: application/octet-stream;name=picacu.exe
McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a
flaw in
Microsoft's MIME handling, allowing the EXE to run when the message is
viewed. Details at:
Author: Stuart Dunkeld
Posted: 2003-02-27 11:56:00 Link
> Given that I'm running IE6 presumably I'm not at risk?
>
> Cheers
> Gary
Correct.
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-020.asp
Stuart
-----------------------------------------------------------------------
This message is intended for the use of the addressee
only and may contain confidential or privileged information. If you
have received it in error please notify the sender and destroy it.
You may not use it or copy it to anyone else.
E-mail is not a secure communications medium.
Please be aware of this when replying.
Although East Sussex County Council has taken steps to ensure
that this e-mail and any attachments are virus free, we can take
no responsibility if a virus is actually present and you are advised to
ensure that the appropriate checks are made.
I never got it here. Not that I want it.
Allen
-----Original Message-----
From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of
Ed Leafe
Hmm... another attachment with a virus made it through earlier. I'm
sending an innocuous zip file to see if that makes it through.
Author: Paul McNett
Posted: 2003-02-27 12:29:00 Link
On Thursday 27 February 2003 06:05 am, Gary Sutherland wrote:
> Given that I'm running IE6 presumably I'm not at risk?
LOL!!!
--=20
Paul McNett - p@ulmcnett.com
Hollister, California, USA