fanf: (Default)
[personal profile] fanf
[livejournal.com profile] senji suggested ratelimiting email based on the MD5 checksum of any attachments, with the goal of slowing down an email virus attack. I think this might be feasible so I'm noting it here as a sort of public to-do list entry...

Date: 2008-07-23 23:11 (UTC)
nameandnature: Giles from Buffy (Default)
From: [personal profile] nameandnature
Sort of DCC in reverse (assuming you're talking outbound mail). The DCC does reasonably well on inbound viruses not by looking at the attachments, but at the body that the virus encloses to try to get you to open them (that is, the hash-based checksums are not catching inbound viruses for me, but the "fuzzy" ones are).

the fuzzy part

Date: 2008-07-26 14:06 (UTC)
From: [identity profile] john.jones.name (from livejournal.com)
I would completely agree with that for the most part viren modify their vector and not the payload but some of the more successful viren certainly do use techniques such as word etc it would be interesting to see the statistics from a large mail host

January 2026

S M T W T F S
    123
45678910
1112 13 14151617
18192021222324
25262728293031

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated 2026-01-25 07:58
Powered by Dreamwidth Studios