[Esd-l] My party...

Marcus Williams marcus at quintic.co.uk
Tue Jan 29 04:28:02 PST 2002


[snip]
> > http://www.sophos.com/virusinfo/analyses/w32mypartya.html
> >
> > The filter, set to block *.COM, trapped two already.
> [snip]
>
> I've caught a few since yesterday (trapping was already set
> to *.com).
> However, I've just received one through a mail list I'm on which
> appears to have got through the sanitizer. I send a copy of the
> message headers to the list once I've extracted it.
[snip]

Mmmm.. false alarm I think. My filters are somehow at version 131 and
I think the message was a nested mime attachment so fell over the bug
in v131 with these sort of mime attachments. Needless to say I've
upgraded up to v133 now.

Now I've gotta work out how come I was running at v131 without
realising it.... Feature suggestion - a version number in the security
alert emails? I know its in the headers of the copied message, but it
would be nice to have a line at the end of the warning text that said
"sanitised by blah version xyz (http://www.sanitiser.address)" or
something.

Marcus

--
Marcus Williams - http://www.onq2.com
Quintic Ltd, 39 Newnham Rd, Cambridge, CB3 9EY



More information about the esd-l mailing list