> From: Fred [mailto:[EMAIL PROTECTED]
> Lucas Albers wrote:
> '(ade|adp|app|asd|asf|asx|bas|bat|chm|cmd|com|cpl|crt|dll|exe|
> fxp|hlp|hta|ht
> o|inf|ini|ins|isp|jse?|lib|lnk|mdb|mde|msc|msi|msp|mst|ocx|pcd
> |pif|prg|reg|s
> cr|sct|sh|shb|shs|sys|url|vb|vbe|vbs|vcs|vxd|wmd|wms|wmz|wsc|w
> sf|wsh|\{[^\}]
> +\})';
> 
> 
> This looks like the default list which comes with MIMEDefang, just a word
of
> caution, some of you might want to remove a few of those, especially:
> 
> .MDB  = Access Database - many people really do send these in e-mail.
> .INF = Not really sent, but not harmful either.
> .INI = same as above.
> .HLP = I send people help files often, this is not harmful is it?
> .INS = This is awful to block, it's used by ISPs to sign up 
> customers, it's
> an Internet Setup File, same as .ISP
> .REG = I send these to customers, also people who need help 
> fixing problems
> with software I've made.  It's not uncommon for techies to 
> send these files.
> .URL = This is sent when you use Internet Explorer, Send -> 
> Link By E-mail
> feature, don't want to block those, people send those a lot.

Just a word of caution in the opposite direction - some of you may want to
*add* a few of those, especially
.htm/.html (.html? for regex gurus) - there are actual viruses that spread
through these
.zip - encrypted only, if you can distinguish encrypted .zip's from regular
.zip's
.doc - (to get really extreme) lotsa macro viruses still out there

More needs to be said about .url - it's true IE's Send Link By Email
attaches a .url link.  But Microsoft's flagship email reader, Microsoft
Outlook, won't let you access .url attachments in email you receive!!!  They
consider it too dangerous!
Most versions of IE will also include the link in the body of the email by
default.  XP's vanilla install does not - Microsoft now considers this a
bug!

See
http://support.microsoft.com/default.aspx?kbid=327010
http://support.microsoft.com/default.aspx?kbid=291506

It all depends on how difficult it is to unquarantine things vs. how hard it
is to clean up after an infection.

[EMAIL PROTECTED]                      805.964.4554 x902
Hispanic Business Inc./HireDiversity.com         Software Engineer
perl -e"map{y/a-z/l-za-k/;print}shift" "Jjhi pcdiwtg Ptga wprztg,"

Reply via email to