Author: Ted Roche
Posted: 2003-02-27 at 08:04:00
Ed:
Is it possible it is slipping through because of the type of encoding? On
the suspicious message, I saw this in the header:
Content-Transfer-Encoding: base64
Content-Type: application/octet-stream;name=picacu.exe
McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a flaw in
Microsoft's MIME handling, allowing the EXE to run when the message is
viewed. Details at:
http://vil.mcafee.com/dispVirus.asp?virus_k=99273
-----Original Message-----
From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of
Ed Leafe
Sent: Thursday, 27 February, 2003 08:17
To: ProFox@leafe.com
Subject: Re: [ADMIN] Just testing the attachment stripping...
On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:
> Hmm... another attachment with a virus made it through earlier. I'm
> sending an innocuous zip file to see if that makes it through.
Well, that was OK. Let's try with a simple EXE.
___/
/
__/
/
____/
Ed Leafe
--- StripMime Report -- processed MIME parts ---
multipart/mixed
text/plain (text body -- kept)
application/zip
---
[excessive quoting removed by server]