[Esd-l] Procmail Sanitizer local rule for SoBig .ZIP worm

John D. Hardin jhardin at impsec.org
Thu Jun 26 06:23:26 PDT 2003

On Thu, 26 Jun 2003, Pierre Etchemaite wrote:

> Some rules quarantine, others discard; Somes rules notify, that one
> doesn't...
> Is there a logic behind those differences, or only historical reasons ?
> Just wondering...

Some of it does have a reason, some is sloppiness. :)

Where the identification is reliable, the default is to discard. Where
it's iffy (like with SoBig) you should quarantine.

The "NONOTIFY" was my failure to clean up a cut-and-paste from my
local rulesets: I'm discarding notifications on known attacks. I have
changed SoBig to NOTIFY in the sample ruleset file - thanks for
mentioning this.

