RE: [ADMIN] Just testing the attachment stripping...

Author: Ted Roche

Posted: 2003-02-27 at 08:04:00

Ed:

Is it possible it is slipping through because of the type of encoding? On

the suspicious message, I saw this in the header:

Content-Transfer-Encoding: base64

Content-Type: application/octet-stream;name=picacu.exe

McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a flaw in

Microsoft's MIME handling, allowing the EXE to run when the message is

viewed. Details at:

http://vil.mcafee.com/dispVirus.asp?virus_k=99273

-----Original Message-----

From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of

Ed Leafe

Sent: Thursday, 27 February, 2003 08:17

To: ProFox@leafe.com

Subject: Re: [ADMIN] Just testing the attachment stripping...

On Thursday, February 27, 2003, at 08:13 AM, Ed Leafe wrote:

> Hmm... another attachment with a virus made it through earlier. I'm

> sending an innocuous zip file to see if that makes it through.

Well, that was OK. Let's try with a simple EXE.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

--- StripMime Report -- processed MIME parts ---

multipart/mixed

text/plain (text body -- kept)

application/zip

---

[excessive quoting removed by server]

©2003 Ted Roche