Take a look at ClearSwift's MIMESweeper. It really looks at the file (PE headers) itself to determine what it is.Originally posted here by mohaughn
What software are you using that can still pick up that a file is an executable with the extension renamed?
We also block all encrypted (this includes zip+password) emails. Only a few people that really need it (for security reasons) are allowed to use encrypted emails.Also, are you blocking password protected zips. If not, the scanners usually can't open them, to see what is inside.
We also block sh*tloads of multimedia content, stuff like mp3, mpeg movies etc..




Reply With Quote