[Esd-l] How to mangle contents of a .zip file?

John D. Hardin jhardin at impsec.org
Tue Mar 9 22:14:18 PST 2004

On Wed, 10 Mar 2004, Brian Hampton wrote:

> Yeah, I began writing such policies in procmail and then realized
> that it was going to be difficult to maintain the list of valid
> people/domains that would be allowed to exchange zipped executables.

Well, for internal use that should be a set it and forget it
configuration. Does your list of external contacts vary that much?

One way to simplify it might be to put a "key phrase" into the subject
that would let certain ZIPs be accepted.

> The reason this whole issue came up is because the sanitizer has
> worked so well that people aren't used to getting any kind of
> dangerous attachment (excellent work, btw!).  But the latest batch
> of .zip viruses that look like they come from me (the admin)
> fooled a couple folks.

Oops. Sorry. Mea culpa.


> I may have to put in something like ClamAV in addition to the
> sanitizer.

I've always recommended the sanitizer be part of a multilayer defense.
It is not a replacement for antivirus software on individual Windows
systems. I hope that any leakers got caught...

