minor isse with sophos-autoupdate script

David Sullivan David.Sullivan at BARNET.AC.UK
Mon Jun 2 13:25:25 IST 2003

On 2 Jun 2003 at 13:14, Ron Campbell wrote:

> We had a few instance of Sobig-C which got through this morning !
> Sophos sent out an alert at 3:54 am. I have this arranged (via a mail
> alias) to run sophos-autoupdate immediately. However, we did not
> detect any Sobig-C viruses until after 8 am (when MS was automatically
> restarted, as happens every 4 hours).
> Perhaps sophos-autoupdate should restart MS ?
If you're running sophos in the "normal" mode this shouldn't be necessary at all since
it executes sweep each time it scans a batch of messages (picking up on whatever
ides are present at the time when it is executed).

This is probably not the case if you're running sophossavi if my understanding of how
it works is cirrect but I couldn't say for sure since we don't use this yet.

Incidentally Sophos seem to have taken longer than usual on getting this virus
update out (which also occurred with another e-mail worm several weeks back)
Symantec had an update and advisory for Sobig-C yesterday and we were certainly
blocking pif attachments of this all of yesterday.



This communication may contain privileged or confidential information which
is for the exclusive use of the intended recipient.  If you are not the
intended recipient, please note that you may not distribute or use this
communication or the information it contains.  If this e-mail has reached you
in error, please delete it and any attachment.

Internet communications are not secure and Barnet College does not accept
legal responsibility for the content of this message.  Any views or opinions
expressed are those of the author and not necessarily those of Barnet College.

Please note that Barnet College reserves the right to monitor the
source/destinations of all incoming or outgoing e-mail communications.

More information about the MailScanner mailing list