[Esd-l] Can't get Procmail-security to work...

Brett Glass brett at lariat.org
Thu Oct 25 08:27:00 PDT 2001


Here's a "poisoned" file that we have used with John's sanitizer.
Note that it does produce the occasional "false positive," most
often when users naively use an attachment file name such as
"Plan.rev.doc". But the security is well worth it.

--Brett

*.[a-z][a-z][a-z0-9].[a-z0-9]+
*.aip
*.asd
*.asx
*.bat
*.chm
*.dll
*.hlp
*.hta
*.js
*.lnk
*.m3u
*.ocx
*.pif
*.pls
*.scr
*.sh[bs]
*.vb
*.vb[se]
*.w[ps]z
*.wm[szd]
*.ws[cfh]
26705-i386-update.exe
Anna.exe
BiHNet.exe
Common.exe
Disk.exe
IBMls.exe
NakedWife.exe
Posta_Update.exe
Raquel Darian.exe
ReDe.exe
SM.exe
Si.exe
Simpsons Episodes
Suzete.exe
UserConf.exe
Win32_Update.exe
Win_Update.exe
Xena.exe
Xuxa.exe
amateurs.exe
anal.exe
anniv.doc
antivirus.exe
aol4free.com
asian.exe
atchim.exe
baby.exe
babylonia.exe
badass.exe
bboy.exe
black.exe
blancheneige.exe
blonde.exe
boss.exe
boys.exe
buhh.exe
casper.exe
celebrity rape.exe
cheerleader.exe
cheeseburst.exe
chocolate.exe
compu_ma.exe
cooler1.exe
cooler3.exe
copier.exe
creative.exe
cum.exe
cumshot.exe
cupid2.exe
doggy.exe
dwarf4you.exe
emanuel.exe
enanito fisgon.exe
enano porno.exe
enano.exe
eurocalculator.exe
explorer.doc
famous.exe
farter.exe
fborfw.exe
fist-fucking.exe
g-zilla.exe
gadget.exe
gay.exe
girls.exe
goal.exe
goal1.exe
happy[0-9]+.exe
hardcore.exe
hog.exe
horny.exe
hot.exe
hottest.exe
i-watch-u.exe
ie0199.exe
ie[0-9]+.exe
irnglant.exe
jesus.exe
joke.exe
kinky.exe
leather.exe
lesbians.exe
list.doc
lovers.exe
matcher.exe
messy.exe
missworld.exe
misworld.exe
monica.exe
monopoly.vbs
mwld.exe
mwrld.exe
myromeo.exe
nains.exe
navidad.exe
oral.exe
orgy.exe
panther.exe
party.exe
path.xls
photos17.exe
picture.exe
pirate.exe
pleasure.exe
pretty park.exe
prettypark.exe
readme.eml
readme.exe
saddam.exe
sado.exe
serialz.hlp
setup.exe
sex.exe
sexy.exe
slut.exe
sodomized.exe
sslpatch.exe
story.doc
suck.exe
suppl.doc
surprise!.exe
teens.exe
theobbq.exe
video.exe
virgins.exe
wtc.exe
x-mas.exe
y2kcount.exe
yahoo.exe
zipped_files.exe



More information about the esd-l mailing list