OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Blocking PWD Encrypted ZIP Files

From: Alex van den Bogaerdt (alexergens.op.het.net)
Date: Thu Apr 22 2004 - 02:56:18 CDT


On Sat, Mar 20, 2004 at 01:34:43AM +1100, listssbt.net.au wrote:

> Alex,
>
> I didn't notice any follow up on this, is it OK so far ?
>
> Voytek

Hi Voytek,

Late reply, sorry, I am behind on postfix mail.

Is it OK? Well, yes and no. I didn't get false positives but I
got quite some amount of false negatives. The amount of messages
containing this virus at the moment does not justify the amount
of work needed to sort out the messages.

If/when a new wave is coming in, I will most likely place this
regex back (discarding in stead of holding this time) and notify
users there is a 0.000000000001 % chance of FP.

cheers,
Alex