William, I understand your opinion and that is certainly your right.
Most of our clients are medical clients and surgery centers. If we infect them with a virus and it creates a security risk in their server environment that makes patient data available to a hacker, it's an automatic $150,000 fine to US from HIPPA. Other clients are accounting firms, doctor's offices and other professional organizations. Many of our other clients have expressed an interest in having us screen their e-mail for viruses. Our written agreement allows us to take every available action possible to protect both their and our networks. Screening for executable attachments is the most effective thing we can do right now. We have an investment of more than $150,000 in hardware and software in our data centers alone. Protecting that investment comes FIRST. If a client objects to that, then let them go get an account elsewhere - we don't want them. Many other large ISPs have taken the same approach. Security is NOT something we take lightly. Bruce Barnes ChicagoNetTech -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of William Lefkovics Sent: Monday, March 01, 2004 08:10 To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] Bagle.F Passworded zip files Wow. Clearly that works for your environment. Of course, I'd change ISPs if they started messing with my email like that. -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bruce Barnes Sent: Monday, March 01, 2004 5:56 AM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] Bagle.F Passworded zip files Mike, About a month ago, we made a proactive decision to automatically BLOCK all ZIP and any other file that might contain an executable type of file. We notified all of our clients and all of their users in a single mass e-mail, repeated 2 days later. Since then, we have trapped more than 15,000 attachment containing e-mails, more than half of which contain ZIPPED attachments. Of these only ONE ZIP file has been a legitimate file. ONE in 15,000 is not a bad false positive rate. (We currently send those files to a special account called "SPAM" for manual review, but will begin auto-refusing them on the 31st of March.) We notified the intended recipient of the one legitimate file who then notified the original sender of the file that they could no longer send ZIPPED files to their e-mail account and they resent the message with the file sent, as an ACROBAT file without, zipping it. They can still send e-mail attachments in the form of ACROBAT, WORD, EXCELL, ACCESS, PUBLISHER, PROJECT, VISIO, POWERPOINT, GIF, JPG, and any other kinds of file, that are not either executable or zipped. If they password protect those files, we strongly urge them to send the password via a SEPERATE e-mail so the password cannot be intercepted and sniffed with the e-mail containing the attachment. It may be a little inconvenient, but it makes for far fewer viruses and attacks. Once the clients got used to not receiving regular notifications of virus laden attachments they actually started sending thank-you notes for the fact that we are now blocking all executable attachments. My suggestion to you is that you simply BLOCK both ZIP files and all other executable attachments. It will save a world of headaches for your and your clients, and eliminate one of the largest gateways currently used by infections, viruses and worms. Bruce Barnes, ChicagoNetTech Inc. -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Mike Nice Sent: Monday, March 01, 2004 06:36 To: [EMAIL PROTECTED] Subject: [IMail Forum] Bagle.F Passworded zip files Well, you knew it had to happen: A password protected archive with the virus including the password in the body of the {RANDOM} message. E-mail virus scanners can't scan inside password-protected files. Now the user gets it, and enters the password of course and promptly infects himself. We're also trapping conventional unzipped Bagle.F viruses. As an ISP, it will be hard to block all ZIP files or even just password-protected ZIP files. We now need to be able to detect password-protected zip files, hold them, notify the recipient, and allow them to release the message. To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
