[Fwd: Anti Virus Mailscanners DOS]
rabellino at DI.UNITO.IT
Tue Feb 26 09:28:17 GMT 2002
Julian Field wrote:
> At 08:48 26/02/2002, you wrote:
> >Does MailScanner check for this DOS ?
> Yes, it will handle this (I've tried it a long time ago). The process of
> expanding (and scanning) the compressed archive will take a very long time
> in an attempt to stop the virus scanning returning to its calling program.
> This will trigger the timeout code in MailScanner, causing it to abort the
> scan. This is precisely the reason that MailScanner has timeout code, just
> to cope with DoS attacks like this.
> I've got a copy of the "Zip of Death", which expands from 42,374 bytes to
> 49,000 Tbytes. MailScanner handles this fine.
thanks... very fine.
Dott. Sergio Rabellino
Department of Computer Science
University of Torino (Italy)
Member of the Internet Society
More information about the MailScanner