Index
2003-02-27 08:04Ted Roche : RE: [ADMIN] Just testing the attachment stripping...
2003-02-27 08:13Ed Leafe : Re: [ADMIN] Just testing the attachment stripping...
2003-02-27 08:18Ed Leafe : Re: [ADMIN] Just testing the attachment stripping...
2003-02-27 08:25Ed Leafe : [ADMIN] Just testing the attachment stripping...
2003-02-27 09:23Gary Sutherland : RE: [ADMIN] Just testing the attachment stripping...
2003-02-27 11:56Stuart Dunkeld : RE: [ADMIN] Just testing the attachment stripping...
2003-02-27 12:01allen : RE: [ADMIN] Just testing the attachment stripping...
2003-02-27 12:29Paul McNett : Re: [ADMIN] Just testing the attachment stripping...
Back to top
RE: [ADMIN] Just testing the attachment stripping...

Author: Ted Roche

Posted: 2003-02-27 08:04:00   Link

Ed:

Is it possible it is slipping through because of the type of encoding? On

the suspicious message, I saw this in the header:

Content-Transfer-Encoding: base64

Content-Type: application/octet-stream;name=picacu.exe

McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a flaw in

Microsoft's MIME handling, allowing the EXE to run when the message is

viewed. Details at:

http://vil.mcafee.com/dispVirus.asp?virus_k=99273

-----Original Message-----

From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of

Ed Leafe

Sent: Thursday, 27 February, 2003 08:17

To: ProFox@leafe.com

Subject: Re: [ADMIN] Just testing the attachment stripping...

On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:

> Hmm... another attachment with a virus made it through earlier. I'm

> sending an innocuous zip file to see if that makes it through.

Well, that was OK. Let's try with a simple EXE.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

--- StripMime Report -- processed MIME parts ---

multipart/mixed

text/plain (text body -- kept)

application/zip

---

[excessive quoting removed by server]

©2003 Ted Roche
Back to top
Re: [ADMIN] Just testing the attachment stripping...

Author: Ed Leafe

Posted: 2003-02-27 08:13:00   Link

On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:

> Hmm... another attachment with a virus made it through earlier. I'm

> sending an innocuous zip file to see if that makes it through.

Well, that was OK. Let's try with a simple EXE.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

--- StripMime Report -- processed MIME parts ---

multipart/mixed

text/plain (text body -- kept)

application/zip

---

©2003 Ed Leafe
Back to top
Re: [ADMIN] Just testing the attachment stripping...

Author: Ed Leafe

Posted: 2003-02-27 08:18:00   Link

On Thursday, February 27, 2003, at 08:38 AM, Ted Roche wrote:

> Is it possible it is slipping through because of the type of encoding?

> On

> the suspicious message, I saw this in the header:

>

> Content-Transfer-Encoding: base64

> Content-Type: application/octet-stream;name=picacu.exe

>

> McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a

> flaw in

> Microsoft's MIME handling, allowing the EXE to run when the message is

> viewed. Details at:

StripMime doesn't try to be too smart. It will strip all attachments

without consideration of their content. The only 'thinking' it does is

when there is an HTML attachment. In that case, if there is no plain

text available, it removes all HTML markup and reformats the message to

be plain text. So I can't see why this is happening.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

©2003 Ed Leafe
Back to top
[ADMIN] Just testing the attachment stripping...

Author: Ed Leafe

Posted: 2003-02-27 08:25:00   Link

Hmm... another attachment with a virus made it through earlier. I'm

sending an innocuous zip file to see if that makes it through.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

--- StripMime Report -- processed MIME parts ---

multipart/mixed

text/plain (text body -- kept)

application/zip

---

©2003 Ed Leafe
Back to top
RE: [ADMIN] Just testing the attachment stripping...

Author: Gary Sutherland

Posted: 2003-02-27 09:23:00   Link

Given that I'm running IE6 presumably I'm not at risk?

Cheers

Gary

-----Original Message-----

From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of

Ted Roche

Sent: Thursday, February 27, 2003 1:58 PM

To: profox@leafe.com

Subject: RE: [ADMIN] Just testing the attachment stripping...

Ed:

Is it possible it is slipping through because of the type of encoding?

On

the suspicious message, I saw this in the header:

Content-Transfer-Encoding: base64

Content-Type: application/octet-stream;name=picacu.exe

McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a

flaw in

Microsoft's MIME handling, allowing the EXE to run when the message is

viewed. Details at:

http://vil.mcafee.com/dispVirus.asp?virus_k=99273

©2003 Gary Sutherland
Back to top
RE: [ADMIN] Just testing the attachment stripping...

Author: Stuart Dunkeld

Posted: 2003-02-27 11:56:00   Link

> Given that I'm running IE6 presumably I'm not at risk?

>

> Cheers

> Gary

Correct.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-020.asp

Stuart

-----------------------------------------------------------------------

This message is intended for the use of the addressee

only and may contain confidential or privileged information. If you

have received it in error please notify the sender and destroy it.

You may not use it or copy it to anyone else.

E-mail is not a secure communications medium.

Please be aware of this when replying.

Although East Sussex County Council has taken steps to ensure

that this e-mail and any attachments are virus free, we can take

no responsibility if a virus is actually present and you are advised to

ensure that the appropriate checks are made.

©2003 Stuart Dunkeld
Back to top
RE: [ADMIN] Just testing the attachment stripping...

Author: allen

Posted: 2003-02-27 12:01:00   Link

I never got it here. Not that I want it.

Allen

-----Original Message-----

From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of

Ed Leafe

Hmm... another attachment with a virus made it through earlier. I'm

sending an innocuous zip file to see if that makes it through.

©2003 allen
Back to top
Re: [ADMIN] Just testing the attachment stripping...

Author: Paul McNett

Posted: 2003-02-27 12:29:00   Link

On Thursday 27 February 2003 06:05 am, Gary Sutherland wrote:

> Given that I'm running IE6 presumably I'm not at risk?

LOL!!!

--=20

Paul McNett - p@ulmcnett.com

Hollister, California, USA

©2003 Paul McNett