William,

I understand your opinion and that is certainly your right.

Most of our clients are medical clients and surgery centers.  If we infect
them with a virus and it creates a security risk in their server environment
that makes patient data available to a hacker, it's an automatic $150,000
fine to US from HIPPA.

Other clients are accounting firms, doctor's offices and other professional
organizations.

Many of our other clients have expressed an interest in having us screen
their e-mail for viruses.  Our written agreement  allows us to take every
available action possible to protect both their and our networks.

Screening for executable attachments is the most effective thing we can do
right now.

We have an investment of more than $150,000 in hardware and software in our
data centers alone.  Protecting that investment comes FIRST.  If a client
objects to that, then let them go get an account elsewhere - we don't want
them.  Many other large ISPs have taken the same approach.

Security is NOT something we take lightly.

Bruce Barnes
ChicagoNetTech

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of William
Lefkovics
Sent: Monday, March 01, 2004 08:10
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] Bagle.F Passworded zip files


Wow.  Clearly that works for your environment.

Of course, I'd change ISPs if they started messing with my email like that.


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Bruce Barnes
Sent: Monday, March 01, 2004 5:56 AM
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] Bagle.F Passworded zip files

Mike,

About a month ago, we made a proactive decision to automatically BLOCK all
ZIP and any other file that might contain an executable type of file.

We notified all of our clients and all of their users in a single mass
e-mail, repeated 2 days later.  Since then, we have trapped more than 15,000
attachment containing e-mails, more than half of which contain ZIPPED
attachments.  Of these only ONE ZIP file has been a legitimate file.  ONE in
15,000 is not a bad false positive rate.  (We currently send those files to
a special account called "SPAM" for manual review, but will begin
auto-refusing them on the 31st of March.)

We notified the intended recipient of the one legitimate file who then
notified the original sender of the file that they could no longer send
ZIPPED files to their e-mail account and they resent the message with the
file sent, as an ACROBAT file without, zipping it.

They can still send e-mail attachments in the form of ACROBAT, WORD, EXCELL,
ACCESS, PUBLISHER, PROJECT, VISIO, POWERPOINT, GIF, JPG, and any other kinds
of file, that are not either executable or zipped.  If they password protect
those files, we strongly urge them to send the password via a SEPERATE
e-mail so the password cannot be intercepted and sniffed with the e-mail
containing the attachment.

It may be a little inconvenient, but it makes for far fewer viruses and
attacks.  Once the clients got used to not receiving regular notifications
of virus laden attachments they actually started sending thank-you notes for
the fact that we are now blocking all executable attachments.

My suggestion to you is that you simply BLOCK both ZIP files and all other
executable attachments.  It will save a world of headaches for your and your
clients, and eliminate one of the largest gateways currently used by
infections, viruses and worms.

Bruce Barnes,
ChicagoNetTech Inc.

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Mike Nice
Sent: Monday, March 01, 2004 06:36
To: [EMAIL PROTECTED]
Subject: [IMail Forum] Bagle.F Passworded zip files



Well, you knew it had to happen:  A password protected archive with the
virus including the password in the body of the {RANDOM} message.  E-mail
virus scanners can't scan inside password-protected files.  Now the user
gets it, and enters the password of course and promptly infects himself.

 We're also trapping conventional unzipped Bagle.F viruses.

 As an ISP, it will be hard to block all ZIP files or even just
password-protected ZIP files.   We now need to be able to detect
password-protected zip files, hold them, notify the recipient, and allow
them to release the message.



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to