I like the confirmation idea, but... someone already said that they have a customer that sends automatic updates of some kind in an exe file. That could not be confirmed. Would you have a whitelist of specific files from specific addresses that would not need to be confirmed?
Todd -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry Sent: Wednesday, March 13, 2002 9:05 PM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] Microsoft Spoof [It's a virus] > > FYI, we are working on a system to allow these potentially dangerous > > files to be delivered, while preventing viruses from spreading themselves > > (for our Declude Virus Pro product). >How can you possibly be sure that your detecting unknown virus'? Hence the >need to prohibit attachments that can infect your computer. > >Maybe I need some more explaination of the way your going to detect virus' >vs. the current method of using Declude Virus/F-Prot. Also, how can we be >confident that you will detect the unknown virus'? Well, it's impossible to detect an unknown virus with 100% accuracy. But blocking all file attachments of a specific type is too inconvenient for many people. First, certain safe attachments are allowed to be sent (such as .JPG files, which can't contain a virus). Then, potentially unsafe attachments that aren't what they are supposed to be ("disguised" attachments) will automatically be banned. That will catch quite a few current viruses that use a .PIF extension, even though they are really .EXE files, for example. That will allow you, if you want, to allow all .BAT and .PIF files through, for example, undergoing only standard scanning. A virus could only get through if [1] It was not yet detected by virus scanners, and [2] it was writting in a very unusual and difficult way (writing a virus with a real batch file or real .PIF file would be extremely difficult). That just leaves potentially dangerous files that viruses can really spread in, such as .EXEs and .COMs. In this case, a confirmation system of some sort will be used. If the .EXE was sent intentionally, the sender will simply confirm it. If a virus sent the .EXE, the sender will not confirm it, and it won't reach the recipient. It's not 100% foolproof, but very close. -Scott --- Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for IMail. http://www.declude.com --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/ --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail scanned for viruses by Declude Virus] Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
