[Esd-l] How do I display Virus Names

John D. Hardin jhardin at impsec.org
Mon Jan 14 06:40:14 PST 2002

On Mon, 14 Jan 2002, Herbert Nkhoma wrote:

> I am new to the forum and I am writing from Malawi.


> I want sanitizer to say what virus it has caught as opposed to the
> poisoned file name. Is this possible? What configurations do I do?

To do that, there has to be a unique signature for the file attachment
or email that will identify the worm. We have collected such
information for a few of the common worms and made some rules that do
identify the worm - see the discussion of the local-rules scripts near
the bottom of the Configuration page.

Please note that the sanitizer is not signature-based (even though
we've made a few signature-based traps) - it does not try to identify
specific attacks; rather, it enforces a policy decision that
"bare executable file attachments are too dangerous to accept".

