[Mimedefang] sobig virus slipping by mcafee.

Stefano McGhee SMcGhee at ARCweb.com
Fri Sep 5 15:07:01 EDT 2003


Hello,
	As if the issue wasn't dead enough, I added the --mime switch to my
config earlier this week.  Even with that in there, I still get the
occasional message that gets past the uvscan on MD.  The message seems to
simply have the mime encoded text of the pif file in the body.  Keep in
mind that my 3500 message /day server still gets 750 SoBig's daily.  Only
two or so slip by a day.  GroupShield (by NAI) picks it up on Exchange
which sits behind the MD box.  Go figure.  Just reporting my findings.

Cheers,

Stefano
> 
> 
> I added the --mime switch to my mimedefang.pl file last week when I 
> noticed that some Sobig infected messages were getting past, 
> and saw an 
> improvement right away.  I was going to mail the list about it, but I 
> guess someone beat me to it.




More information about the MIMEDefang mailing list