lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <F028B146DACD54419D564A00090F66AD96BDAF@comail1.corp.idanalytics.com>
From: smacdougall at idanalytics.com (MacDougall, Shane)
Subject: Re: E-Mail viruses

Curt's idea could be more effective in a client/server environment that used extensions that changed periodically (fast enough to thwart virus attacks, etc). The extension transformations could be length/format. How this updated extension exchange would be implemented would be another kettle of fish...

Just a thought.
Shane

 -----Original Message-----
From: 	docco
Sent:	Sat Mar 06 00:58:09 2004
To:	full-disclosure@...ts.netsys.com
Subject:	Re: [Full-Disclosure] Re: E-Mail viruses

 Hi all,

>>"The nice thing about this approach is that it completely
>>eliminates the need for any anti-virus on the mail server
>>since all virus attachments are automatically dropped
>>without the need for scanning [...]"

What Curt Purdy is saying looks to me like a great_pain_in_the_ass_solution.
In case the "supersecret" extension would get leaked or compromised, which I
beleive would be absolutely not hard to achieve (by means of social
engineering, sniffing or just brute force - combinations of three letters,
wow, that IS hard to guess) you should:

- Change your whole statregy. As the extension is been compromised you could
not trust ANY attatchment anymore from that moment on, loosing probably good
and valid attachments.

- Inform all users about the "supersecret" extension been compromised and
ask them to use the new "supersecret" extension.

Then, and I'm playing Devil's Advocate, suppose the new "supersecret"
extension gets again compromised in the time users are getting used to this
new second one, and that you, again, have to inform everybody to change once
more the way they send attachments ...

Well I'm guessing, but I'm almost sure some of your users would just quit
their jobs and go insane.

You Can't Judge a Book By Looking At The Cover
(Willie Dixon)
You Can't Judge a File By Looking At The Extension
(Common Sense)

Just my two cents.
Regards,
Nacho Pobes

PS.- I follow the list for a while with great interest and it's a good
learning experience. Thanx to everybody who participate.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Powered by blists - more mailing lists