Jeffrey Moskot wrote:

> Based on what this article says, it looks like there will 
> soon be problems
> with my config: 
> http://www.sophos.com/virusinfo/articles/bagletwist.html
> 
> I wasn't able to get my version of amavis properly patched to 
> submit the
> body of the message to clam (or at least as far as I can 
> tell, that's not
> what's happening).
> 
> The clam team saved my butt last round by coming up with those generic
> signatures, but does this article mean I'm finally going to 
> beat my old amavis script into shape?
> 
> Jeffrey Moskot
> System Administrator
> [EMAIL PROTECTED]

MailScanner (http://www.mailscanner.info) as of today's version 4.29.2 can
now disable "Object Data" tags.

And ClamAV catches it (of course):

ClamAV databases updated (18-mar-2004 12:02 GMT): daily.cvd, viruses.db2
version: 194

Submission: 2032
Sender: webdigger
Submitted virus name: Unknown Virus
Virus name: Exploit.HTML.Bagle.Q-eml
Notes: Worm.Bagle.Q has the ability to distribute through 
Notes: an e-mail with a HTML exploit (and no binary 
Notes: attachment). This signature will detect these e-mails. 
Added: Yes

Cheers,

Phil
---------------------------------------------
Phil Randal
Network Engineer
Herefordshire Council
Hereford, UK


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to