giza: Giza White Mage (Default)
[personal profile] giza
In case anyone wants to do some filtering of SoBig, which is (still) making the rounds, the following procmail filter will delete all incoming e-mails with the worm:

#
# Filter for the SoBig worm
#
:0
* ^X-MailScanner: Found to be clean
* ^Content-Type: multipart/mixed
/dev/null


Share and enjoy! (Mad props go to Laura Atkins of The SpamCon Foundation, who originally sent it to me)

(no subject)

Date: 2003-08-28 06:37 am (UTC)
From: [identity profile] foxmagic.livejournal.com
Y'mean SoBig always adds a header saying "Found to be clean" to its messages?

How devious... how pointlessly devious, though, 'cos I wonder if anyone or anything pays attention to that header?

(no subject)

Date: 2003-08-28 07:06 am (UTC)
From: [identity profile] duncandahusky.livejournal.com
Actually, it's a nasty bit of work since there is in fact an app called MailScanner and this is generating a bogus "clean" message from it. I don't claim to read procmail filters that well, but if I understand right this is an AND condition - if it has the MailScanner header AND that Content-type header THEN send it to /dev/null.

(no subject)

Date: 2003-08-28 07:34 am (UTC)
From: [identity profile] giza.livejournal.com
Yep. And so far, the only thing that has been caught are copies of SoBig.

My next stupid procmail trick is going to be writing some filters that remove all file attachments from e-mails coming in on the server, and replacing them with a note stating why they were removed. (to protect against viruses)

Profile

giza: Giza White Mage (Default)
Douglas Muth

April 2012

S M T W T F S
1234567
891011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags