|
随着Mydoom/Novarg危害的升级,Ipswitch于昨日(02/02/04) 发布了"IMail - How to protect against the Novarg.A virus"为题的KB,请大家注意,原文全文如下:<br>
<br>
-------------------------------------------------------------------------------<br>
IMail - How to protect against the Novarg.A virus <br>
Product: Version: Platform: <br>
IMail All NT,Win2000,XP,Win2003 <br>
<br>
--------------------------------------------------------------------------------<br><br>
Question/Problem: How do I protect against the Novarg.A virus?<br>
<br>
Answer/Solution: You will want Rules to block attachments. You want to make sure your anti-virus scanner has up to date virus definitions.<br>
<br>
Blocking attachments<br>
<br>
THESE STEPS SHOULD BLOCK ALL FILE ATTACHMENTS.<br>
**YOU WILL WANT TO CREATE RULES TO LOOK AT BOTH THE HEADER AND BODY OF MESSAGES.**<br>
<br>
1. Click on the hostname in IMail Administrator and select the Inbound Rules tab.<br>
2. Click Add<br>
3. From the dropdown box, select "If the Body text". You will also want to create the same rules to say "If the Header text".<br>
4. In the text box, paste the following: name=.*\.scr<br>
5. Click Add Condition<br>
6. Click insert OR<br>
7. In the text box, paste the following: name=.*\.pif<br>
8. Click Add Condition<br>
9. Click insert OR<br>
10. In the text box, paste the following: name=.*\.exe<br>
11. Click Add Condition<br>
12. Click insert OR<br>
13. In the text box, paste the following: name=.*\.zip<br>
14. Click Add Condition<br>
15. Click insert OR<br>
16. In the text box, paste the following: name=.*\.bat<br>
17. Click Add Condition<br>
18. Select the action to be taken.<br>
<br>
For more information on Rules creation see:<br>
IMail - Rules to filter all file attachments<br>
<br>
Use Current Virus Definitions<br>
Verify that your IMail Anti-Virus (or any desktop anti-virus scanner) has the current definitions. They should not be older than 1/28/2004.<br>
<br>
See also:<br>
IMail Anti-Virus - How to automatically update the Virus Definition File<br>
<br>
Disable User Notifications<br>
To stop the influx of notifications being sent to the users and administrator you should add an Inbound Rule to block "Virus Caught" notifications.<br>
<br>
1. Click on the hostname in IMail Administrator and select the Inbound Rules tab.<br>
2. Click Add<br>
3. From the dropdown menu select "If the Subject text"<br>
4. In the text box, enter Virus Detected<br>
5. Click Add Condition<br>
6. Click Insert And<br>
7. From the dropdown menu select "if the Body text" 8. In the text box, enter novarg<br>
8. Click Add Condition<br>
9. Click OK<br>
10. Select the action to be taken.<br>
<br>
Additional Information on Novarg.A<br>
<br>
<a target=_blank href=http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html>http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html</a><br>
<br>
<br>
--------------------------------------------------------------------------------<br>
<br>
A customer suggests: as there is a strain of the novarg virus which forwards itself, but fails to attach itself as a virus. You can add the following line to rules.ima to delete these annoying virus-created spam messages as they come in:<br>
<br>
S~(test|\shi\s|hello|Mail Delivery System|Mail Transaction Failed|Server Report|Status|Error):NUL<br><br>
Document #: Revision Date: <br>
IM-20040130-DM01 02/02/04 <br>
<br>
--------------------------------------------------------------------------------<br><br>
<a target=_blank href=http://support.ipswitch.com/kb/IM-20040130-DM01.htm>http://support.ipswitch.com/kb/IM-20040130-DM01.htm</a> |