senji suggested ratelimiting email based on the MD5 checksum of any attachments, with the goal of slowing down an email virus attack. I think this might be feasible so I'm noting it here as a sort of public to-do list entry...
I would completely agree with that for the most part viren modify their vector and not the payload but some of the more successful viren certainly do use techniques such as word etc it would be interesting to see the statistics from a large mail host
the fuzzy part
Date: 2008-07-26 14:06 (UTC)