[Fwd: Anti Virus Mailscanners DOS]

Rabellino Sergio rabellino at DI.UNITO.IT
Tue Feb 26 09:28:17 GMT 2002


Julian Field wrote:
>
> At 08:48 26/02/2002, you wrote:
> >Does MailScanner check for this DOS ?
>
> Yes, it will handle this (I've tried it a long time ago). The process of
> expanding (and scanning) the compressed archive will take a very long time
> in an attempt to stop the virus scanning returning to its calling program.
> This will trigger the timeout code in MailScanner, causing it to abort the
> scan. This is precisely the reason that MailScanner has timeout code, just
> to cope with DoS attacks like this.
>
> I've got a copy of the "Zip of Death", which expands from 42,374 bytes to
> 49,000 Tbytes. MailScanner handles this fine.
>

thanks... very fine.
--
Dott. Sergio Rabellino

 Technical Staff
 Department of Computer Science
 University of Torino (Italy)
 Member of the Internet Society

http://www.di.unito.it/~rabser
Tel. +39-0116706701
Fax. +39-011751603



More information about the MailScanner mailing list