<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : D&#111;n&#146;t get the point of using a AV</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : D&#111;n&#146;t get the point of using a AV]]></description>
  <pubDate>Sat, 06 Jun 2026 10:25:34 +0000</pubDate>
  <lastBuildDate>Fri, 18 Mar 2005 16:20:58 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=5102</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : Not at all... there is nothing...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5472&amp;title=dont-get-the-point-of-using-a-av#5472</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 18 March 2005 at 4:20pm<br /><br />Not at all... there is nothing that needs to execute. The Windows DLLthat decodes the JPG has a buffer overrrun bug. With the buffer overruna hacker can execute a program embedded in the JPG without the userhaving to run anything. All he needs to do is *view* the JPG.<br><br>... and to be more exact, they may not even have to *view* it. In somecases all that is needed is to *hover* over the file with the mouse.Windows will launch the DLL that decodes the JPG to extract itsthumbnail. This is all that's needed for you to get infected, as thebuffer overun will kick in right away.<br><br>In the JPG we attached in the zip, the buffer overrun will create abackdoor by running a reverse shellcode on the victim's PC, allowingthe hacker to remote into the victim's PC and effectively having aremote command prompt on it.<br><br>Summary:<br>****there is no program that needs to run/download for the machine to be infected****<br>]]>
   </description>
   <pubDate>Fri, 18 Mar 2005 16:20:58 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5472&amp;title=dont-get-the-point-of-using-a-av#5472</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : Iunderstand that, but the JPEG...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5471&amp;title=dont-get-the-point-of-using-a-av#5471</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=41">chinabee</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 18 March 2005 at 11:20am<br /><br />I&nbsp;understand that, but the JPEG file needs other code/program to work, doesn't it?]]>
   </description>
   <pubDate>Fri, 18 Mar 2005 11:20:35 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5471&amp;title=dont-get-the-point-of-using-a-av#5471</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : Perhaps you are seeing the word...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5469&amp;title=dont-get-the-point-of-using-a-av#5469</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=22">Desperado</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 18 March 2005 at 11:17am<br /><br /><P>Perhaps you are seeing the word "download" and thinking that this is download link or something.&nbsp; When you browse to a site that has any images on it (like most sites do) your browser downloads the images without you asking.&nbsp;&nbsp; Mail clients do the same.&nbsp; So, if I email you and embed an inline image tag, you will get the image.&nbsp; I can send an example if you want.</P><P>Dan</P><P>&nbsp;</P>]]>
   </description>
   <pubDate>Fri, 18 Mar 2005 11:17:57 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5469&amp;title=dont-get-the-point-of-using-a-av#5469</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : the JPEG file still needs to download...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5468&amp;title=dont-get-the-point-of-using-a-av#5468</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=41">chinabee</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 18 March 2005 at 10:42am<br /><br /><P>the JPEG file still needs to download and run a malicious code/program to infect. </P><P>My firewall only allows HTTP/HTTPS traffic and my filter does not allow any user to download any executable files including zip file.</P><P>Even though I received such JPEG files, they would still do no harm as they couldn't run any malicious code.</P>]]>
   </description>
   <pubDate>Fri, 18 Mar 2005 10:42:09 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5468&amp;title=dont-get-the-point-of-using-a-av#5468</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : ...because the file is a jpeg,...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5455&amp;title=dont-get-the-point-of-using-a-av#5455</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 6:24pm<br /><br />...because the file is a jpeg, not an exe. Your filter, unless itchecks the http stream for viruses, will not block it. If however thefilter is blocking images, then yes, it will work, but your users arelikely not going to be enjoying their browsing experience.]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 18:24:38 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5455&amp;title=dont-get-the-point-of-using-a-av#5455</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : My filter is on HTTP traffic....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5452&amp;title=dont-get-the-point-of-using-a-av#5452</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=41">chinabee</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 4:49pm<br /><br />My filter is on HTTP traffic. How would the IE download anything without an agreement from my filter? ]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 16:49:08 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5452&amp;title=dont-get-the-point-of-using-a-av#5452</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : chinabee,  That would actually...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5448&amp;title=dont-get-the-point-of-using-a-av#5448</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 3:59pm<br /><br />chinabee,<br><br>That would actually work just fine bypassing all your filtering if theiframe simply causes the email client/browser to display, in the abovecase, the infected jpg.<br><br>Also note that in this particularly nasty case, the email itself doesnot contain the attachment, so it will not be blocked. The emailcontains an iframe, which causes the *end-user's* PC to download thevirus in the jpg. The only way to stop this is toeither have anantivirus on the client PC, or to have an AV product scanning your HTTPtraffic (such products do exist).<br><br>The moral is, nobody is as secure as they think they are. There isusually a compromise in how much you are willing to risk and how manyresources you're going to dedicate to protect your environment.<br>]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 15:59:46 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5448&amp;title=dont-get-the-point-of-using-a-av#5448</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : This won&amp;#039;t work on my system....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5446&amp;title=dont-get-the-point-of-using-a-av#5446</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=41">chinabee</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 3:18pm<br /><br /><P>This won't work on my system. I have filter set up so that no executable file can be downloaded and only port 80 and 443&nbsp;is available to users. </P><P>If the virus works on port 80, the filter will stop it from downloading anything executable.</P><P><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by Desperado" alt="Originally posted by Desperado" style="vertical-align: text-bottom;" /> <strong>Desperado wrote:</strong><br /><br /></P><P>How about anything using "iframe".&nbsp; The attachment is NOT in the message but on a remote server.&nbsp; The iframe launches the download.</P><P>Dan</P><P>&nbsp;</P></td></tr></table> <span style="font-size:10px"><br /><br />Edited by chinabee</span>]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 15:18:59 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5446&amp;title=dont-get-the-point-of-using-a-av#5446</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : Norman, like other AV&amp;#039;s,...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5445&amp;title=dont-get-the-point-of-using-a-av#5445</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=22">Desperado</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 3:04pm<br /><br /><DIV>Norman, like other AV's, constantly updates it's definitions. Norman, unlike other AV's, has what it calls "Sand Box Technology".&nbsp; What this does is if it sees something that it feels is suspicious, it places it in a protected area (the sand box) and sees if it does anything "Virus Like".&nbsp; </DIV><DIV>&nbsp;</DIV><DIV>From their site:</DIV><DIV><DIV =focuser>Norman Sandbox technology </DIV><DIV =focusBlock><DIV =focusBlockTitle>Norman Sandbox technology - the hows and whys</DIV>This article&nbsp;aims to explain a bit more in depth how&nbsp;Norman Sandbox really&nbsp;works and&nbsp;why it is different from other solutions out there. <BR>Norman&nbsp;Sandbox is a fully simulated computer. No code is executed on the real CPU except for the Norman Virus Control emulator engine;&nbsp; even the hardware in the simulated PC is emulated.&nbsp;&nbsp;&nbsp; See: <A href="http://www.norman.com/Virus/13927/en-us" target="_blank"><FONT color=#800080>http://www.norman.com/Virus/13927/en-us</FONT></A></DIV><DIV =focusBlock><FONT face=Arial color=#800080 size=2></FONT>&nbsp;</DIV><DIV =focusBlock><FONT face=Arial size=2>Regards,</FONT></DIV></DIV>]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 15:04:38 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5445&amp;title=dont-get-the-point-of-using-a-av#5445</guid>
  </item> 
  <item>
   <title><![CDATA[D&#111;n&#146;t get the point of using a AV : chianabee,  That&amp;#039;s exactly...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5444&amp;title=dont-get-the-point-of-using-a-av#5444</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5102<br /><strong>Posted:</strong> 16 March 2005 at 3:02pm<br /><br />chianabee,<br><br>That's exactly why you pay for AV software.... They have staff thatfinds the viruses and updates the patterns to detect them. If you had*any* decent AV software scanning on your mail server the virus youdownloaded from my post would have been caught. The beta ofSpamFilter's AV plugin for example catches it just fine.<br>]]>
   </description>
   <pubDate>Wed, 16 Mar 2005 15:02:03 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5102&amp;PID=5444&amp;title=dont-get-the-point-of-using-a-av#5444</guid>
  </item> 
 </channel>
</rss>