<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ant Drewery &#187; Anti-Virus</title>
	<atom:link href="http://blog.drewery.net/category/anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.drewery.net</link>
	<description>IT infrastructure, support and strategy</description>
	<lastBuildDate>Thu, 01 Dec 2011 09:47:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.drewery.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Ant Drewery &#187; Anti-Virus</title>
		<link>http://blog.drewery.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.drewery.net/osd.xml" title="Ant Drewery" />
	<atom:link rel='hub' href='http://blog.drewery.net/?pushpress=hub'/>
		<item>
		<title>File level AV scanning on an Exchange server</title>
		<link>http://blog.drewery.net/2006/02/03/file-level-av-scanning-on-an-exchange-server/</link>
		<comments>http://blog.drewery.net/2006/02/03/file-level-av-scanning-on-an-exchange-server/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 14:51:46 +0000</pubDate>
		<dc:creator>Anthony Drewery</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Exchange]]></category>

		<guid isPermaLink="false">http://www.drewery.net/blog/2006/02/03/file-level-av-scanning-on-an-exchange-server/</guid>
		<description><![CDATA[I first started working with Exchange in 1998 and up until a couple of years ago usually avoided installing a file level real-time anti-virus scanner on a dedicated Exchange server. (The exception to this is where an Exchange server has other functions like file sharing, or is a Small Business Server.) Unfortunately with the growing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=53&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I first started working with Exchange in 1998 and up until a couple of years ago usually avoided installing a file level real-time anti-virus scanner on a dedicated Exchange server. (<em>The exception to this is where an Exchange server has other functions like file sharing, or is a <a target="_blank" href="http://www.microsoft.com/windowsserver2003/sbs/default.mspx">Small Business Server</a>.</em>) Unfortunately with the growing number of nasties in circulation a file level (and memory resident) AV scanner has become a precautionary requirement.</p>
<p>If you do use file level anti-virus scanning you should exclude the databases, logs and SMTP Mailroot folders. Failure to do so could leave you with possible log/DB corruption and excessive CPU time on your AV processes. In fact, I&#8217;d recommend excluding all Exchange folders from scanning. This also applies to scheduled and manual scans.</p>
<p>[tags]Exchange, Anti-Virus[/tags]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antdrewery.wordpress.com/53/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antdrewery.wordpress.com/53/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antdrewery.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antdrewery.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antdrewery.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=53&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.drewery.net/2006/02/03/file-level-av-scanning-on-an-exchange-server/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ac112d149b667282aee5e6cc74ecf5a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Ant</media:title>
		</media:content>
	</item>
		<item>
		<title>Real-time Black Lists</title>
		<link>http://blog.drewery.net/2005/12/13/real-time-black-lists/</link>
		<comments>http://blog.drewery.net/2005/12/13/real-time-black-lists/#comments</comments>
		<pubDate>Tue, 13 Dec 2005 16:09:06 +0000</pubDate>
		<dc:creator>Anthony Drewery</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Mailsweeper]]></category>

		<guid isPermaLink="false">http://www.drewery.net/blog/?p=27</guid>
		<description><![CDATA[It&#8217;s official, I hate RBLs. For sometime I&#8217;ve tolerated and indeed used well run and respected lists like SURBL but then SURBL works differently to the rest. SURBL does not block listed hosts but rather allows you to block messages based on the URIs that they contain. It works well in conjunction with our MailSweeper [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=27&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s official, I hate RBLs. For sometime I&#8217;ve tolerated and indeed used well run and respected lists like <a href="http://www.surbl.org/">SURBL</a> but then SURBL works differently to the rest. SURBL does not block listed hosts but rather allows you to block messages based on the URIs that they contain. It works well in conjunction with our MailSweeper servers.</p>
<p>The main problem with these types of service is that no one governs them. I could set one up tomorrow and list whoever I liked. Of course, you&#8217;d have to chose to use my list with your systems.</p>
<p>Most of these services make it fairly painless to be removed so although inconvenient  it&#8217;s not the end of the world if you are listed in error, and indeed if you are an open relay then it can be a justified kick up the backside. However, there are some real cowboys out there.</p>
<p>Today we&#8217;ve found one of our gateways listed with such a cowboy <a href="http://www.us.sorbs.net/">http://www.us.sorbs.net/</a>. I&#8217;ve scanned the box for Trojans and viruses with 2 different products and have thrown every relay test I know against it.  Nada. So how did it get listed? SORBS claim that our box sent an email (not a spam, just a regular email) to one of its honey trap addresses. That&#8217;s just plain crazy. It could have been an NDR or virus notification in response to a message that spoofed the SORBS address. To make things worse SORBS want a fine to have our box de-listed. This fine is in the form of a donation which I guess gets them round any extortion charges. What a joke.</p>
<p>I&#8217;m even more shocked to find a company like Vodafone uses this list as part of their anti-spam measures. Their admins should be shot.</p>
<p>That&#8217;s my rant over for now. I need to get back to getting de-listed.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antdrewery.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antdrewery.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antdrewery.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antdrewery.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antdrewery.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=27&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.drewery.net/2005/12/13/real-time-black-lists/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ac112d149b667282aee5e6cc74ecf5a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Ant</media:title>
		</media:content>
	</item>
		<item>
		<title>Layers of defence</title>
		<link>http://blog.drewery.net/2005/11/23/layers-of-defence/</link>
		<comments>http://blog.drewery.net/2005/11/23/layers-of-defence/#comments</comments>
		<pubDate>Wed, 23 Nov 2005 12:17:38 +0000</pubDate>
		<dc:creator>Anthony Drewery</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Mailsweeper]]></category>

		<guid isPermaLink="false">http://www.drewery.net/blog/?p=21</guid>
		<description><![CDATA[Due to the critical nature of our email usage a major virus outbreak on our Exchange servers would probably cost me my job. So to help me sleep easier at night I use layers of defence. We run one anti-virus product on our MailSweeper gateway servers and a product from a different vendor on all [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=21&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Due to the critical nature of our email usage a major virus outbreak on our Exchange servers would probably cost me my job. So to help me sleep easier at night I use layers of defence. We run one anti-virus product on our MailSweeper gateway servers and a product from a different vendor on all of our internal Exchange servers. The concept of using different products is if one vendor doesn&#8217;t have a definition available to detect a certain virus the other vendor might. This layered approach gives us a fighting chance if a virus gets past MailSweeper or hits us from the inside via a webmail service.</p>
<p>As additional precaution we set the automatic definition updates to be as frequent as possible and also block any executable attachments (internal &amp; external).</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antdrewery.wordpress.com/21/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antdrewery.wordpress.com/21/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antdrewery.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antdrewery.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antdrewery.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=21&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.drewery.net/2005/11/23/layers-of-defence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ac112d149b667282aee5e6cc74ecf5a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Ant</media:title>
		</media:content>
	</item>
		<item>
		<title>Increase in virus traffic</title>
		<link>http://blog.drewery.net/2005/11/23/increase-in-virus-traffic/</link>
		<comments>http://blog.drewery.net/2005/11/23/increase-in-virus-traffic/#comments</comments>
		<pubDate>Wed, 23 Nov 2005 12:00:54 +0000</pubDate>
		<dc:creator>Anthony Drewery</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Mailsweeper]]></category>

		<guid isPermaLink="false">http://www.drewery.net/blog/?p=20</guid>
		<description><![CDATA[We saw a sharp increase in the amount of viruses caught by our MailSweeper servers yesterday, double the usual volume. Here are the top 10 viruses that we&#8217;ve caught so far this month: 1 &#8211; W32/NetSky.P@mm 2 &#8211; Email-Worm.Win32.NetSky.q 3 &#8211; Exploit.HTML.Iframe.FileDownload 4 &#8211; Email-Worm.Win32.Sober.y 5 &#8211; HTML/IFrame@expl(exact) 6 &#8211; Net-Worm.Win32.Mytob.cg 7 &#8211; Net-Worm.Win32.Mytob.c 8 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=20&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We saw a sharp increase in the amount of viruses caught by our MailSweeper servers yesterday, double the usual volume. Here are the top 10 viruses that we&#8217;ve caught so far this month:</p>
<p>1 &#8211; W32/NetSky.P@mm<br />
2 &#8211; Email-Worm.Win32.NetSky.q<br />
3 &#8211; Exploit.HTML.Iframe.FileDownload<br />
4 &#8211; Email-Worm.Win32.Sober.y<br />
5 &#8211; HTML/IFrame@expl(exact)<br />
6 &#8211; Net-Worm.Win32.Mytob.cg<br />
7 &#8211; Net-Worm.Win32.Mytob.c<br />
8 &#8211; Trojan-Spy.HTML.Bayfraud.hn<br />
9 &#8211; Email-Worm.Win32.NetSky.r<br />
10 &#8211; Net-Worm.Win32.Mytob.ab</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antdrewery.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antdrewery.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antdrewery.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antdrewery.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antdrewery.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.drewery.net&amp;blog=6502410&amp;post=20&amp;subd=antdrewery&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.drewery.net/2005/11/23/increase-in-virus-traffic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ac112d149b667282aee5e6cc74ecf5a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Ant</media:title>
		</media:content>
	</item>
	</channel>
</rss>
