[Esd-l] Double-zipped virus

John D. Hardin jhardin at impsec.org
Thu Sep 2 15:25:32 PDT 2004

On Thu, 2 Sep 2004, Simon Matthews wrote:

> I have just received an email that bypassed the scanner, because
> it contains a double-zipped file (I assume). It is an executable
> (masquerading as a screen-saver), inside a zipfile, which is
> inside another zipfile (or the same name).

If you don't wish to accept double-zipped files, then create a
separate poisoned-zipped-files list and put *.zip in that list.

The recommended poisoned-zipped-files list on the website does this.

I do not intend to make the sanitizer recursively scan zip files.

