On Wed, 8 Sep 2004 22:07:53 -0700, you wrote:

>I have currently tuned my SARE spam filters, and am humming right along, I get 
>one or 2 uncaught spams a day which is no big deal. But I would like to catch 
>the virus emails that have Win exe, scr, bat, and the like for attachments, 
>but I can't find a rule for them. 
>
>Is there one? How can I catch them otherwise?
>
>Rob

Rob, I don't pretend this is the best way to solve your problem (what
you ideally want to do is look at amavisd-new), but assuming you have
a good reason for doing it this way, here's a half-assed approach.
Below are uuencoded translations for a few common windows executable
markers.  Set up rules looking for them and any others you can find.


This program cannot be run in DOS mode

VGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGU

This program must be run under Win32

VGhpcyBwcm9ncmFtIG11c3QgYmUgcnVuIHVuZGVyIFdpbjMy


Good luck!

Mike-

--
If you can keep your head while those around you are losing theirs...
You may have a great career as a network administrator ahead!
--
Please note - Due to the intense volume of spam, we have installed 
site-wide spam filters at catherders.com.  If email from you bounces,
try non-HTML, non-encoded, non-attachments,

Reply via email to