RE: [Declude.Virus] Vulnerabilities explained

2003-03-06 Thread Markus Gufler
> As you have discovered when multiple recipients are in place, > if one of then sends the request, the message is released for > all of them. In my opinion I consider it as a minor glitch. ..until there is spreading a real virus using such a vulnerability. The worst case: A Worm that uses the

RE: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread Adolfo Justiniano
g what mistakes the user could have done %imailpath%\imail1 -f %imailpath%\unblock_email_error.txt -s "Error while unblocking E-mail:%subject%" -t "%sender%" -u [EMAIL PROTECTED] :end endlocal <<< End >>> -Original Message- From: [EMAIL PROTECTED] [mail

RE: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread Markus Gufler
BTW: I've attached to this mail a short ASP-Script that requeues a spoolfile from the virus folder. Simply set a link in your vulnerability.eml file to http://www.yourdomain.com/requeue.asp?id=%QUEUENAME% The recipient of the vuln.warning can simply click on this link to requeue the hold message

RE: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread Markus Gufler
> Yes -- http://www.declude.com/virus/manual.htm has a section on > vulnerabilities, that has a brief description of each one. Thanks. It's exaclty what we need. > The information in the manual should be enough for the programmers to > figure out the problem (if they can't, they shouldn't be

RE: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread R. Scott Perry
>Outlook 'CR' Vulnerability "It is possible to send attachments to Outlook Express users using non-standard attachment techniques. This can be accomplished by encapsulating the data in Carriage Return () specifiers in the Subject line of an email. Upon receiving an email with a subject line conta

Re: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread R. Scott Perry
Is there a information page where you explain the different vulnerabilities and what are tipical causes of this? Yes -- http://www.declude.com/virus/manual.htm has a section on vulnerabilities, that has a brief description of each one. We have here a lot of hold messages with: Outlook '

RE: [Declude.Virus] Vulnerabilities explained

2003-03-05 Thread David Lewis-Waller
In my recent experience... >Outlook 'CR' Vulnerability "It is possible to send attachments to Outlook Express users using non-standard attachment techniques. This can be accomplished by encapsulating the data in Carriage Return () specifiers in the Subject line of an email. Upon receiving an emai