[Mimedefang] MIME type message/partial
David F. Skoll
dfs at roaringpenguin.com
Tue Nov 9 09:33:08 EST 2004
On Tue, 9 Nov 2004, Keith Patton wrote:
> I am getting compaints of email not being delivered. I look in the
> logs and they are being bounced with "MIME type message/partial not
> accepted here". Sure enough the filter blocks this type of message. So
> like any good computer is does exactly what you tell it.
message/partial is a huge, gaping, enormous, cavernous, overwhelming
security risk. (Was I clear about my feelings?)
message/partial lets you slip malware under the radar of scanners. It
lets you evade any kind of sensible filtering policy. The
message/partial MIME type is an abomination that cements in my mind
the belief that MIME was a mistake.
More concretely: message/partial lets you split up a virus so that it
can evade server-side virus scanners. It will then be reconstructed
by the mail reader and do its damage.
> I need something because mgmt is likely to tell me just not to block
> and I would like to have some valid reasons as to why they are being
> blocked.
Tell mgmt that if they permit message/partial, they might as well throw
away server-side scanning and turn off their anti-virus software.
Regards,
David.
More information about the MIMEDefang
mailing list