Mike,

About a month ago, we made a proactive decision to automatically BLOCK all
ZIP and any other file that might contain an executable type of file.

We notified all of our clients and all of their users in a single mass
e-mail, repeated 2 days later.  Since then, we have trapped more than 15,000
attachment containing e-mails, more than half of which contain ZIPPED
attachments.  Of these only ONE ZIP file has been a legitimate file.  ONE in
15,000 is not a bad false positive rate.  (We currently send those files to
a special account called "SPAM" for manual review, but will begin
auto-refusing them on the 31st of March.)

We notified the intended recipient of the one legitimate file who then
notified the original sender of the file that they could no longer send
ZIPPED files to their e-mail account and they resent the message with the
file sent, as an ACROBAT file without, zipping it.

They can still send e-mail attachments in the form of ACROBAT, WORD, EXCELL,
ACCESS, PUBLISHER, PROJECT, VISIO, POWERPOINT, GIF, JPG, and any other kinds
of file, that are not either executable or zipped.  If they password protect
those files, we strongly urge them to send the password via a SEPERATE
e-mail so the password cannot be intercepted and sniffed with the e-mail
containing the attachment.

It may be a little inconvenient, but it makes for far fewer viruses and
attacks.  Once the clients got used to not receiving regular notifications
of virus laden attachments they actually started sending thank-you notes for
the fact that we are now blocking all executable attachments.

My suggestion to you is that you simply BLOCK both ZIP files and all other
executable attachments.  It will save a world of headaches for your and your
clients, and eliminate one of the largest gateways currently used by
infections, viruses and worms.

Bruce Barnes,
ChicagoNetTech Inc.

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Mike Nice
Sent: Monday, March 01, 2004 06:36
To: [EMAIL PROTECTED]
Subject: [IMail Forum] Bagle.F Passworded zip files



Well, you knew it had to happen:  A password protected archive with the
virus including the password in the body of the {RANDOM} message.  E-mail
virus scanners can't scan inside password-protected files.  Now the user
gets it, and enters the password of course and promptly infects himself.

 We're also trapping conventional unzipped Bagle.F viruses.

 As an ISP, it will be hard to block all ZIP files or even just
password-protected ZIP files.   We now need to be able to detect
password-protected zip files, hold them, notify the recipient, and allow
them to release the message.


Sample below without virus Bagle.F ---
-------------------------------------------
Sent: Sunday, February 29, 2004 7:04 PM
Subject: Bad girl


I am from Taiwan but I study in Camden, New Jersey now. I like to know
people from different places .
 password for archive: 87326





To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to