('binary' encoding is not supported, stored as-is)
HI
How can I write a signature for a virus which is coming as an
attachment? The attachment may be done by using base64 or binhex encoding.
Shall I have to create signature for each type?
Has anybody implemented the idea of decoding the attachment (IDS) and
then parsing the file to look for some pattern?
Regards,
Babu
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------
Received on Feb 06 2006