Re: 543.rar attachment

From: Steven DeFord (security.willworker_at_gmail.com)
Date: 03/14/05

  • Next message: Steve: "Re: ICQ Corporate Security Risks"
    Date: Mon, 14 Mar 2005 10:54:53 -0800
    To: security-basics@securityfocus.com
    
    

    On Mon, 14 Mar 2005 09:13:03 -0600, Kinnell <kinnell.t@gmail.com> wrote:
    > On the network I'm a member of we block all exe files sent inside the
    > rar or zip, so even if it is sent the file will be 0byted. Wouldn't
    > that be a better method? otherwise if you block all bz2, zip, rar,
    > etc... then you will block a lot of useful communication
    >
    > -Kinnell

    What about password-protected (encrypted) .zip archives? Some common
    virus propagation methods avoid detection by encrypting the virus in a
    .zip archive and giving the user the password, telling the user to
    decrypt the archive and run the virus (couched in persuasive terms).
    Because of this, it can be hard to determine what's in a .zip file.
    (I don't know anything about .rars.)

    -- 
    Steven DeFord
    steve@singingtree.com
    (925) 596-0426
    

  • Next message: Steve: "Re: ICQ Corporate Security Risks"

    Relevant Pages

    • Re: 3 questions
      ... I for one do not care for "RAR" files of this type as I have no clues as to ... In which case, you'd not only lose your posting account, but your ... anyone worth their salt would virus scan a RAR file ...
      (misc.transport.road)
    • How to create multipart rar archive in linux?
      ... multipart rar archive of a video file for Usenet posting. ... Once it is on the Linux ... not how to create multipart rar archives. ... kilobyte chunks, meaning 15Mb. ...
      (alt.os.linux)
    • Re: Good backup software for Linux
      ... My suggestion is to use rar. ... Rar also allows you to put "recovery data" in with the archives. ... -m5 Maximum compression. ...
      (Debian-User)
    • Re: RAR under linux: any alternative?
      ... > whether it's a RAR archive or any other type of archive. ... You create the archives and ... Later when you ask it to check the validity of the archive it can reference ... to reconstruct missing files in a volume set. ...
      (Debian-User)
    • Re: RAR under linux: any alternative?
      ... >> whether it's a RAR archive or any other type of archive. ... You create the archives and ... Added support of so called recovery volumes, ... It's ALREADY corrupt, so what makes you ...
      (Debian-User)