« Active Internet Worms and the Dartmouth ICMP BCC: System | Main | Malware Analysis for Administrators »

Blocking Windows Worms at the Server with Procmail on a VPS

I've been using the procmail tool for several years now to detect and stop mass mailer malware from getting into my inbox. It works pretty well, despite some false negatives. Here's another document showing you some basic recipes to trap such malware.
My own humble list of worm recipes (the bulk of this document) may serve as a starting point for those new to procmail, but for more complete anti-worm protection, the seeker is directed to Nancy McGough's list first (the other links below may also be found on her site).
Source: Blocking Windows Worms at the Server with Procmail on a VPS by Scott Wiersdorf.

October 5, 2005 in defense, mass mailers, tools | Permalink
Tell others: digg submit | del.icio.us this | Reddit

Comments

The comments to this entry are closed.