|
|||||||||||
|
RE: Anti-vrus auto-replies
From: Pete Herzog <lists(at)isecom.org>
Date: Mon Jun 30 2003 - 16:29:45 EDT
Since the security tester is looking for any response from the security presence of an organization, the ideal situation is no responses to anything which is not expressly permitted under business justification. Running a test, I do look in the headers of bounced mails, out of office mails, bounced mailing list mails, direct sent mails, read receipts, receive receipts, and AV response mails for network path information. I also use this to find live e-mail addresses, systems and applications in use, containment measures either server side or desktop, etc. Again, no response is proper for various reasons but most of all if business justification does not expressly permit a community service for sending responses to all virus-attached mails which offsets the risk of the profiling that it may be used for and possible legal action for causing a third-party DoS. The proper action is strip the virus and allow the recipient to receive the mail with a warning that the attachment was removed because of XYZ virus. The recipient may then decide if the person is known and worth contacting (key client perhaps). All mails which have no proper recipient do not bounce either- they forward to a common account that a designated person reviews for legitimate traffic.
Sincerely,
www.osstmm.org > -----Original Message-----
Received on Mon Jun 30 23:03:26 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:39 EDT |
||||||||||
|
|||||||||||