Virus Vulnerability

Alex Neuman alex at nkpanama.com
Thu Jun 3 23:44:10 IST 2004


It's a non-issue. Look at the archives, the message is mangled in such an
obscure way that it doesn't pose a threat - just proves there are holes in
the way messages are processed by servers and clients.

-----Original Message-----
From: MailScanner mailing list [mailto:MAILSCANNER at JISCMAIL.AC.UK] On Behalf
Of Karl Bailey
Sent: Thursday, June 03, 2004 4:55 PM
To: MAILSCANNER at JISCMAIL.AC.UK
Subject: Virus Vulnerability

Been looking at a site:
www.testvirus.org

Which will fire a number of tests at a mail account. Among these are:

Test #21: Eicar virus within zip file hidden using the "Long MIME
Boundary Vulnerability"
And
Test #23: Eicar virus within zip file hidden using the "Empty MIME
Boundary Vulnerability"

Both of these tests seemed to get through the MailScanner system I am
running, one of which got picked up by the mcaffee groupshield solution
on an exchange server (number 23). The other (21) wasn't picked up by
anything & made it to the mail client...

Is this a problem with my config (which I suspect), or is this actually
a problem & if so can the hole be plugged?

I'm running latest version of Mailscanner, kaspersky AVP, Mcaffee uvscan
& f-prot.

Regards
Karl Bailey
Systems Administrator

=====================================
This email and any files transmitted
with it are confidential and intended
solely for the use of the individual
or entity to whom they are addressed.

If you have received this email in error
please notify Landmark Information Group
on +44(0) 1392 441700.

For more information about the Landmark
Information Group visit
www.landmark-information.co.uk

This email and any attachments have
been scanned for viruses and to the
best of our knowledge are clean.
====================================

-------------------------- MailScanner list ----------------------
To leave, send    leave mailscanner    to jiscmail at jiscmail.ac.uk
Before posting, please see the Most Asked Questions at
http://www.mailscanner.biz/maq/     and the archives at
http://www.jiscmail.ac.uk/lists/mailscanner.html

-------------------------- MailScanner list ----------------------
To leave, send    leave mailscanner    to jiscmail at jiscmail.ac.uk
Before posting, please see the Most Asked Questions at
http://www.mailscanner.biz/maq/     and the archives at
http://www.jiscmail.ac.uk/lists/mailscanner.html



More information about the MailScanner mailing list