Author: Ed Leafe
Posted: 2003-02-27 at 08:18:00
On Thursday, February 27, 2003, at 08:38 AM, Ted Roche wrote:
> Is it possible it is slipping through because of the type of encoding?
> On
> the suspicious message, I saw this in the header:
>
> Content-Transfer-Encoding: base64
> Content-Type: application/octet-stream;name=picacu.exe
>
> McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a
> flaw in
> Microsoft's MIME handling, allowing the EXE to run when the message is
> viewed. Details at:
StripMime doesn't try to be too smart. It will strip all attachments
without consideration of their content. The only 'thinking' it does is
when there is an HTML attachment. In that case, if there is no plain
text available, it removes all HTML markup and reformats the message to
be plain text. So I can't see why this is happening.
___/
/
__/
/
____/
Ed Leafe