[THIN] Re: OT: Security response to BAGLE virus (password protected .zips)

  • From: Euan Cooper <Euan.Cooper@xxxxxxxxxxxx>
  • To: "'thin@xxxxxxxxxxxxx'" <thin@xxxxxxxxxxxxx>
  • Date: Fri, 5 Mar 2004 10:25:03 +1300

We have never allowed password protected Zip files into our system because
of the very reason that our AV products cannot virus scan the files
contained within the zip file.

Nor do we allow pass worded Word or Excel files - for the same reason.

Some users both external and internal have complained about this - but
management have supported this stand   The reality is none of the stuff they
were sending actually justified password protection anyway - most turned out
to be non-work relegated anyway.

We do have full encryption from and to out e-mail gateway enabled with some
other government organisations we deal with.  At this stage it is more of a
trail/proof on concept - but I expect this may become more common over the
next few years.

-Ec

 

-----Original Message-----
From: Claus, Brian [mailto:BClaus@xxxxxxxxxxxxx]
Sent: Friday, 5 March 2004 2:28 a.m.
To: thin@xxxxxxxxxxxxx
Subject: [THIN] OT: Security response to BAGLE virus (password protected
.zips)


Just wondering what others are doing to combat the latest BAGLE worm.  =
It's password protected so standard AV won't scan into it.  How is =
everyone else handling delivery of .zip files now?

We're using the Trend Micro AV suite.

Do you think the latest password protected BAGLE worm has caused the =
demise of password protected .zip files?

My immediate opinion in the matter is that password protected .zip files =
will now be treated with the same delivery restrictions that the .exe, =
.scr, .pif, .vbs have come under but I'm not aware of any AV software or =
other means to differentiate scanning options between p\w protected .zip =
files and non p\w protected .zip files.


Thanks,
=20

  _____ =20

=20
Brian Claus, A+, Network+, MCP
Network Administrator
WESCO Distribution, Inc.
225 West Station Square Drive, Suite 700
Pittsburgh, PA 15219-1122
Phone:  412-454-2412
Fax:  412-454-2540
bclaus@xxxxxxxxxxxxx <mailto:bclaus@xxxxxxxxxxxxx>=20
  _____ =20

********************************************************
This weeks sponsor triCerat Inc.
triCerat makes your job easier by offering essential
applications to eliminate your printing, policy and profile,
and your application management problems.
http://www.triCerat.com 
**********************************************************
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
***********************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm
********************************************************
This weeks sponsor triCerat Inc.
triCerat makes your job easier by offering essential
applications to eliminate your printing, policy and profile,
and your application management problems.
http://www.triCerat.com 
**********************************************************
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
***********************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm

Other related posts: