I use Norton Antivirus for Gateways which is configured to filter attachments. .com was in the "delete" list so we didn't get infected even though the antivirus definitions didn't catch it (until yesterday afternoon). I also have all messages with a .com attachment sent to nul using the Imail rules.ima file. I haven't had any problems with embedded links being caught (to my knowledge).
B~name=".*\.com":NUL B~filename=".*\.com":NUL B~Begin 6.*\.com:NUL Scot Rager -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Joseph Marlin Sent: Tuesday, January 29, 2002 11:13 AM To: IMail Forum Subject: [IMail Forum] Who caught the latest virus before it caught their users? Did anyone successfully stop the latest "pictures" worm with rules or Declude or whatever? I have not been able to filter .com's with IMail rules, because it "catches" everyone who puts a .com email address in their signature or puts in a link, etc. Even Watchguard (manufacturer of our Firebox) sent out a message saying that their SMTP proxy service did not always catch this one because it used UU-encoding. Does anyone have a good rule to catch only .com attachments? Or did Declude catch it? Joseph Marlin Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ --------------------------------------------------------------------------------------- This message is for the designated recipient only and may contain privileged or confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the email by you is prohibited. --------------------------------------------------------------------------------------- Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
