> At the moment the only secure way is to patch each single GDI-dll on
> your   computer(s)!  Even  if  you're  using  MXGuard,  Declude,  20
> Firewalls, 10 intrusion detection systems and local AV-Scanners!

There  is  one (only one) way to protect unpatched browsers before you
get  to  touch the client (and outside of unplugging your CSU/DSU): an
HTTP  proxy  capable of filtering on MIME type in HTTP responses. This
crisis  has  kicked  our proxy implementations into high gear. You may
want  to look into Squid and WebWasher; I'm sure there are others that
will also do the job.

This  note is only dealing with the browser-based infection vector, of
course, and is thus OT.

--Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]

SpamAssassin plugs into Declude!
  http://www.mailmage.com/products/software/freeutils/SPAMC32/download/release/

Defuse Dictionary Attacks: Turn Exchange or IMail mailboxes into IMail Aliases!
  
http://www.mailmage.com/products/software/freeutils/exchange2aliases/download/release/
  http://www.mailmage.com/products/software/freeutils/ldap2aliases/download/release/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to