I like the suggestion to check for (multiple) occurrences of
SQL-statements etc.. If you think of it, it's just like UCE/UBE
filtering.
Maybe it's possible to use software like SpamAssassin and/or
BogoFilter to determine if a file is "definitely insecure",
"definitely secure" or "not sure". Of course, they would require a
whole different ruleset and perhaps some extra training depending on
the site, but I do think this may have some perspective.
Also, performance wise this may be a good idea: SA and BF are designed
for realtime email processing, so I don't see why they shouldn't be
able to process a sufficient number of files, even on modest hardware.
Regards,
Martin
--
Martin Schapendonk, martin.schapendonk_at_gmail.com
Received on Jan 24 2005