No matter how often you check for new sigs, you'll always have at least several hours between a new worm hits the Net and a signature comes to your local antivirus installation.


IMHO to the question : "What do I do ?" the most logical answer is : "explain to your users what a new virus is and how it is impossible to protect against them in the early hours no matter how much effort the antivirus guys put to the task". Then advise them to use more secure e-mail clients...

And we are only talking here about the SMTP transport which can mostly be handled by banning/quarantining attachments and content filtering for script and iframe exploits. A virus can enter through many more methods - P2P - IM - HTTP - FTP etc. which requires realtime scanning of all traffic at the perimeter. My worst problem is people who install MSN Messenger and don't configure it for virus scanning. Email is only the beginning.

In addition to banning all the usual executable attachments I
bounce/quarantine .zip files now too.

_________________________________________________________________
Is your PC infected? Get a FREE online computer virus scan from McAfeeŽ Security. http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963




-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to