[Esd-l] Got a message that the cat dragged in, now what ?

John D. Hardin jhardin at impsec.org
Fri Sep 19 05:30:28 PDT 2003

On Fri, 19 Sep 2003, Tommy Lindqvist wrote:

> I can gzip a copy of the message after editing out a suitable
> portion of the virii ( swen ) in it, but I do not know where to
> send it.

Don't worry about disabling the content, I don't use Windows.

Please gzip the original raw message with all headers and mail it to


> I do not even know if anyone besides me is interested in
> figuring out how the virii managed to get past the scanner.

I am.

> My first laymans guess would be that:
> Content-Type: application/x-msdownload; name="Q179632.exe"
> Content-Disposition: attachment
> Content-Transfer-Encoding: base64
> Is not recognized as a file.

That looks like an unremarkable MIME header. It should be detected.

> Any clues now what to do next ?

I'd have to see the message.

