RE: [ADMIN] Just testing the attachment stripping...

Author: Gary Sutherland

Posted: 2003-02-27 at 09:23:00

Given that I'm running IE6 presumably I'm not at risk?

Cheers

Gary

-----Original Message-----

From: profox-admin@leafe.com [mailto:profox-admin@leafe.com]On Behalf Of

Ted Roche

Sent: Thursday, February 27, 2003 1:58 PM

To: profox@leafe.com

Subject: RE: [ADMIN] Just testing the attachment stripping...

Ed:

Is it possible it is slipping through because of the type of encoding?

On

the suspicious message, I saw this in the header:

Content-Transfer-Encoding: base64

Content-Type: application/octet-stream;name=picacu.exe

McAfee does report the EXE was "Exploit-MIME.gen.c" which exploits a

flaw in

Microsoft's MIME handling, allowing the EXE to run when the message is

viewed. Details at:

http://vil.mcafee.com/dispVirus.asp?virus_k=99273

©2003 Gary Sutherland