procmail
[Top] [All Lists]

Re: puzzled about a regexp

2003-01-12 21:40:01
NKK> xe xe.. I have two av soft in my win-box. The linux mail server is at
my
NKK> university and I work remotely. I began writing the script for a
friend that
NKK> receives about 8 MB of Klez in 4 days...!!

:0hB
*
^135AAItEjhyJRI8ci0SOGIlEjxiLRI4UiUSPFItEjhCJRI8Qi0SODIlEjwyLRI4IiUSPCItE$
        klez

nope... :-)
please let me be the bad guy when it comes to viruses.

what you wrote is a 72-length base64 encoded string.. Do you know what
happes when the virus comes encoded in a 60-length string or even a
76-lentght (which is the standrard maximum of base64) ? Klez passes!

I've spent hours reading old recipes about viruses and even the ones from
impsec don't have a correct signature policy on that matter (and yes I know
that the filter from impsec is really good).
So I extract my own signatures. :-)



_______________________________________________
procmail mailing list
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail

<Prev in Thread] Current Thread [Next in Thread>