[Linux-aus] procmail rule for the latest virus nonsense?
Arjen Lentz
arjen at mysql.com
Wed Jan 28 19:08:01 UTC 2004
Hi all,
The following ruleset should capture the latest virus nonsense, but
doesnt:
:0 B
* ^Content-Type: text/plain; charset="Windows-1252"
* ^Content-Type: application/octet-stream;
name=.*\.(bat|cmd|exe|pif|scr|zip)
* ^UEsDBAoAAAAAA....zDKJx\+eAFgAAABYAA
The lines work when I do them manually with egrep, so it must be some
quirkyness inside procmail (which uses the egrep code!). I've been
messing with lots of escaping, and I just can't find it.
Thoughts anyone?
Regards,
Arjen.
--
Arjen Lentz, Technical Writer, Trainer
Brisbane, QLD Australia
MySQL AB, www.mysql.com
Sydney 1 Mar 2004 (5 days): Using & Managing MySQL Training
Training,Support,Licenses,T-shirts @ https://order.mysql.com/?marl
More information about the linux-aus
mailing list