[Esd-l] Re: [Esa-l] Sanitizer rule for Novarg .ZIP attack

John D. Hardin jhardin at impsec.org
Thu Jan 29 14:38:09 PST 2004

On Thu, 29 Jan 2004, Simon Matthews wrote:

> John, and others,
> I've seen a few copies of a variant that has no subject, no text (to be 
> more accurate, it claims to have to have a section that uses Windows-1252 
> charset, but it's empty), just a zip file attachment.
> Any suggestions on filtering? Anyone want to see a copy?

That's why I took out the subject test. The current local rule should
catch such variants.

