[Esd-l] ZIP scanning, take two (repost)

John D. Hardin jhardin at impsec.org
Mon Feb 23 10:26:10 PST 2004

On Mon, 23 Feb 2004, Mark Wendt (Contractor) wrote:

> Okay, maybe I misundertook sumthin' here.  Is the Sanitizer going
> to actually unzip the file, read the contents, determine whether
> or not it's one of the bad boys, and if so, quarantine (strip) the
> zip?

The sanitizer will look for the ZIP archive's filename in the standard
poison and strip lists (the same as for DOC and XLS and other Office
files) and will quarantine the message or strip the zip attachment
based on the standard rules. In other words, the sanitizer now
recognizes the extension ".ZIP".

The sanitizer will then scan the first-level filenames within the ZIP
(e.g. zipping a zip will still bypass the scan) and quarantine *the
message* based on whether any filenames it finds match the filespecs
in your ZIPPED_FILES policy list.

> IF so, thatn turn it on by default.  If not, and we're going to
> base the quarantine on the type of extension, I would rather see
> it turned off as the default.

The default is what will be used if you do not provide an explicit
policy for the content of ZIP archive attachments. Providing no
default will duplicate the way things are presently (e.g. zipped
*anything* will bypass the sanitizer). Providing a default will force
you to override it with an explicit local policy if you do not want to
automatically quarantine (or in your case, discard) a lot of ZIPs.

I take it you vote "no default ZIP policy"?

> We're extremely happy with the Sanitizer John, and look forward 
> to the new releases.

Thanks! "nrl.navy.mil" - *that* is gratifying! :)

