[MAILSCANNER] Latest Bagel varients

Glenn Steen glenn.steen at GMAIL.COM
Fri Sep 23 12:11:24 IST 2005


    [ The following text is in the "ISO-8859-1" character set. ]
    [ Your display is set for the "US-ASCII" character set.  ]
    [ Some characters may be displayed incorrectly. ]

On 21/09/05, Rick Cooper <rcooper at dwford.com> wrote:
> I noticed this morning that the latest couple bagel varients are not being
> caught by bit defender and f-prot (clam gets them as of early this morning).
>
> bdc will catch them if the --nohed (unknown virus detection) switch is used
> but that switch is not in the default CommonOptions setting of
> SweepViruses.pm. Should it be, or does someone know of a reason it isn't at
> this time?
>
>
>  Rick Cooper
>

I *think* it's because that will generate a fair bit of FPs. Might be
wrong though.
My experience was that bdc got some of the variants fairly early and
clamav and mcafee got some others, so in total none slipped by
(would've triggered the file name/type thingies)... And after a few
hours they we're pretty much on par (all getting everything)... Until
the next "spamming of bagels" round:).

--
-- Glenn
email: glenn < dot > steen < at > gmail < dot > com
work: glenn < dot > steen < at > ap1 < dot > se

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the Wiki (http://wiki.mailscanner.info/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!



More information about the MailScanner mailing list