[Esd-l] NovArg Email Got To Inbox

John D. Hardin jhardin at impsec.org
Tue Jan 27 05:53:40 PST 2004

On Tue, 27 Jan 2004, Mike McCandless wrote:

> I am using the Sanitizer w/ Postfix.  I have included email
> headers from an email that showed up in our inbox.  I have applied
> the NovArg local rules that John posted very recently.  Do I need
> to do something so that these never hit the inbox?

> Content-Disposition: attachment; filename="body.zip"

The sanitizer does not, by default, treat .ZIP attachments as hostile.

I have posted a local rule that detects some of them, I am working on
refining it. Unfortunately it appears that the .ZIP attachments may be
randomly named part of the time, so checking for filenames may not be
long term successful. I will see if the payloads have common strings
that can be keyed against as signatures.

You are, of course, free to add "zip" extensions to your local mangle
and poison lists if you wish. It may be wise to mangle non-whitelist
zip attachments for the next week or so while this runs its course.

