Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: e-mail virus scanning through f/w
From: Nick Simicich <njs @ scifi . emi . net>
Date: Wed, 19 Jul 1995 09:15:22 -29900
To: Kari Laine <buster @ klaine . pp . fi>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199507191047 . AA27045 @ personal . eunet . fi>

On Wed, 19 Jul 1995, Kari Laine wrote:

> 
> > Does anyone know if a utility or application exists that will, transparent 
> > tot he user, scan incoming and outgoing e-mail for executables and report 
> > viruses to the user and/or system administrator?  I have a client that uses 
> > the i-net for e-mail only but users often send and receive executables as 
> > par of their e-mail.  Any leads would be appreciated.
> 
> We have implemented a utility to check all the attachment
> files on MS-mail when messages are stored in the mail
> server. This solution uses Dr. Solomon's AVTK but it
> is possible to use other scanners.
> 
> Now if you system uses some other mail-system the
> question is - how it stores messages and atttachements?
> If it is possible to access them from dos-level (emulator
> or a machine connected to post server) we probably
> could implement something. Problem is those million
> different encoding systems. Let me know more of your
> setup. 
> 

Um, what do you do about:

zip files
tar files
gnu zipped files
lzh files?

compressed disk images, in about three formats I can think of offhand....

About 20 other compression formats?

Most files are transmitted compressed, and sometimes the unpacking method 
is not obvious.  If your goal is to allow your users not to have to think 
about viruses when getting mail, I suspect that you will never quite 
achieve it.

Your best bet is to educate your users, and if you do scan, don't let 
them know, so that they continue to run their own virus checkers and 
don't become dependent on yours.  The primary responsibility has to be 
theirs.

Nick Simicich - njs @
 scifi .
 emi .
 net - (last choice) njs @
 bcrvm1 .
 vnet .
 ibm .
 com
http://scifi.emi.net/njs.html -- Stop by and Light Up The World!



References:
Indexed By Date Previous: Barriers to entry of firewall software
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Next: Re: Changing a (cisco) firewall setup.
From: Greg Nenych <gnenych @ ncrcan . canada . ATTGIS . COM>
Indexed By Thread Previous: Re: e-mail virus scanning through f/w
From: "Kari Laine" <buster @ klaine . pp . fi>
Next: Re: e-mail virus scanning through f/w
From: njb @ knoware . nl (Niels Bjergstrom)

Google
 
Search Internet Search www.greatcircle.com