 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: E-mail filtering service thinks zip file is infected with W32/Bagle virus</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/</link>
	<description></description>
	<lastBuildDate>Tue, 21 May 2013 18:28:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: pineappleman</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48628</link>
		<dc:creator>pineappleman</dc:creator>
		<pubDate>Thu, 03 Nov 2005 10:25:52 +0000</pubDate>
		<guid isPermaLink="false">#comment-48628</guid>
		<description><![CDATA[I would agree with your vendors claims.

You should check with the filtering service to see how to avoid a &quot;false&quot; positive, if it could be done without compromising a procedure or algorithm used to decipher. 


]]></description>
		<content:encoded><![CDATA[<p>I would agree with your vendors claims.</p>
<p>You should check with the filtering service to see how to avoid a &#8220;false&#8221; positive, if it could be done without compromising a procedure or algorithm used to decipher. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sonyfreek</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48629</link>
		<dc:creator>sonyfreek</dc:creator>
		<pubDate>Wed, 02 Nov 2005 19:00:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-48629</guid>
		<description><![CDATA[If I were you, I&#039;d still try changing the .zip extension to something innoculous, like .txt to test out the intelligence of the AV gateway.  If it doesn&#039;t verify it&#039;s file format, then it probably should be upgraded to something more secure, although you might not be able to convince the admin to do that.

SF]]></description>
		<content:encoded><![CDATA[<p>If I were you, I&#8217;d still try changing the .zip extension to something innoculous, like .txt to test out the intelligence of the AV gateway.  If it doesn&#8217;t verify it&#8217;s file format, then it probably should be upgraded to something more secure, although you might not be able to convince the admin to do that.</p>
<p>SF</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkoch67</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48630</link>
		<dc:creator>dkoch67</dc:creator>
		<pubDate>Wed, 02 Nov 2005 09:06:49 +0000</pubDate>
		<guid isPermaLink="false">#comment-48630</guid>
		<description><![CDATA[Our filtering service responded to my support call and thinks it&#039;s a false positive.  Thanks for all your ideas and comments.

David]]></description>
		<content:encoded><![CDATA[<p>Our filtering service responded to my support call and thinks it&#8217;s a false positive.  Thanks for all your ideas and comments.</p>
<p>David</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: petkoa</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48631</link>
		<dc:creator>petkoa</dc:creator>
		<pubDate>Wed, 02 Nov 2005 07:55:57 +0000</pubDate>
		<guid isPermaLink="false">#comment-48631</guid>
		<description><![CDATA[Hi,

zip-replacing worm isn&#039;t something unthinkable, but I did&#039;t hear any reports about something like this.

If your scanner is so specific about W32/Bagle.G I&#039;ll not suppose problems with encrypted zip or too general rules, but about coincidental generation by the zipper of some bites resembling the Bagle.G signature of the AV product.

BR,

Petko
     ]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>zip-replacing worm isn&#8217;t something unthinkable, but I did&#8217;t hear any reports about something like this.</p>
<p>If your scanner is so specific about W32/Bagle.G I&#8217;ll not suppose problems with encrypted zip or too general rules, but about coincidental generation by the zipper of some bites resembling the Bagle.G signature of the AV product.</p>
<p>BR,</p>
<p>Petko</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mlandes</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48632</link>
		<dc:creator>mlandes</dc:creator>
		<pubDate>Wed, 02 Nov 2005 07:18:30 +0000</pubDate>
		<guid isPermaLink="false">#comment-48632</guid>
		<description><![CDATA[hi, 
try looking at the following:
a. zip protected by password ?
b. the file names are identical to the common beagle characteristics such as subject or filenames or extensions or message body words etc etc.
thanks
moti
]]></description>
		<content:encoded><![CDATA[<p>hi,<br />
try looking at the following:<br />
a. zip protected by password ?<br />
b. the file names are identical to the common beagle characteristics such as subject or filenames or extensions or message body words etc etc.<br />
thanks<br />
moti</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: layer9</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48633</link>
		<dc:creator>layer9</dc:creator>
		<pubDate>Tue, 01 Nov 2005 23:11:49 +0000</pubDate>
		<guid isPermaLink="false">#comment-48633</guid>
		<description><![CDATA[I&#039;m curious what your AV Gateway appliance or software is. 

I have seen this error with several common AV gateway systems where .zip or .txt extensions, or both were filtered by default.

Do you have administrative control over this gateway? Can you confirm that these file extensions are not blocked anywhere on the system?

Chris Weber
Layer9corp.com
]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m curious what your AV Gateway appliance or software is. </p>
<p>I have seen this error with several common AV gateway systems where .zip or .txt extensions, or both were filtered by default.</p>
<p>Do you have administrative control over this gateway? Can you confirm that these file extensions are not blocked anywhere on the system?</p>
<p>Chris Weber<br />
Layer9corp.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sonyfreek</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48634</link>
		<dc:creator>sonyfreek</dc:creator>
		<pubDate>Tue, 01 Nov 2005 19:51:09 +0000</pubDate>
		<guid isPermaLink="false">#comment-48634</guid>
		<description><![CDATA[Does the message you get when you receive the email state that it was blocked due to an infection of the W32/Bagle.G Virus?  We typically configure our virus protection to block *.zip files that are encrypted with a password or that cannot be opened by the virus scanner, but some admins block anything by the extension, such as *.zip files.  It&#039;s typically easy to get around by renaming the .zip file to .txt.  Tell the user to change it to .zip when saving it to the disk and it&#039;ll open up fine.  Try that and see if you are successful.  More than likely, it will work.

SF

]]></description>
		<content:encoded><![CDATA[<p>Does the message you get when you receive the email state that it was blocked due to an infection of the W32/Bagle.G Virus?  We typically configure our virus protection to block *.zip files that are encrypted with a password or that cannot be opened by the virus scanner, but some admins block anything by the extension, such as *.zip files.  It&#8217;s typically easy to get around by renaming the .zip file to .txt.  Tell the user to change it to .zip when saving it to the disk and it&#8217;ll open up fine.  Try that and see if you are successful.  More than likely, it will work.</p>
<p>SF</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkoch67</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/e-mail-filtering-service-thinks-zip-file-is-infected-with-w32bagle-virus/#comment-48635</link>
		<dc:creator>dkoch67</dc:creator>
		<pubDate>Tue, 01 Nov 2005 16:42:23 +0000</pubDate>
		<guid isPermaLink="false">#comment-48635</guid>
		<description><![CDATA[Howard2nd,

They were zipping the files to group them into one attachment.  Size was not the problem here.  This is a situation where the vendor sends out updates on a frequent basis and the number of text files is not constant.

David]]></description>
		<content:encoded><![CDATA[<p>Howard2nd,</p>
<p>They were zipping the files to group them into one attachment.  Size was not the problem here.  This is a situation where the vendor sends out updates on a frequent basis and the number of text files is not constant.</p>
<p>David</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.038 seconds using memcached
Object Caching 365/371 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-21 19:09:05 -->