Re: [ADMIN] Just testing the attachment stripping...

Author: Ed Leafe

Posted: 2003-02-27 at 08:18:00

On Thursday, February 27, 2003, at 08:38 AM, Ted Roche wrote:

> Is it possible it is slipping through because of the type of encoding?

> On

> the suspicious message, I saw this in the header:

>

> Content-Transfer-Encoding: base64

> Content-Type: application/octet-stream;name=picacu.exe

>

> McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a

> flaw in

> Microsoft's MIME handling, allowing the EXE to run when the message is

> viewed. Details at:

StripMime doesn't try to be too smart. It will strip all attachments

without consideration of their content. The only 'thinking' it does is

when there is an HTML attachment. In that case, if there is no plain

text available, it removes all HTML markup and reformats the message to

be plain text. So I can't see why this is happening.

___/

/

__/

/

____/

Ed Leafe

http://leafe.com/

http://opentech.leafe.com

©2003 Ed Leafe