[Linux-aus] procmail rule for the latest virus nonsense?

Arjen Lentz arjen at mysql.com
Wed Jan 28 19:08:01 UTC 2004


Hi all,

The following ruleset should capture the latest virus nonsense, but
doesnt:

:0 B
* ^Content-Type: text/plain; charset="Windows-1252"
* ^Content-Type: application/octet-stream;
name=.*\.(bat|cmd|exe|pif|scr|zip)
* ^UEsDBAoAAAAAA....zDKJx\+eAFgAAABYAA

The lines work when I do them manually with egrep, so it must be some
quirkyness inside procmail (which uses the egrep code!). I've been
messing with lots of escaping, and I just can't find it.
Thoughts anyone?


Regards,
Arjen.
-- 
Arjen Lentz, Technical Writer, Trainer
Brisbane, QLD Australia
MySQL AB, www.mysql.com

Sydney 1 Mar 2004 (5 days): Using & Managing MySQL Training
Training,Support,Licenses,T-shirts @ https://order.mysql.com/?marl





More information about the linux-aus mailing list