<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: AV stats</title>
	<atom:link href="http://mcwresearch.com/archives/605/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com/archives/605</link>
	<description>Things I think I've thought about</description>
	<pubDate>Thu, 20 Nov 2008 11:51:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: kurt wismer</title>
		<link>http://mcwresearch.com/archives/605#comment-4928</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Tue, 19 Feb 2008 19:38:58 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/archives/605#comment-4928</guid>
		<description>i think i have a handle on the decomposer engine issue now... 

it has to do with compressed files - password protection (scanners can't guess passwords) and recursively compressed archives that go past the threshold depth that the scanner is willing to go (don't want to get bogged down by a zip bomb)... both of these things will cause the scanner to stop trying and log the event...

it's my understanding, though, that you can configure things to quarantine what can't be scanned and since you only have av on the mail gateways it stands to reason that if you do have things configured that way those 1253 decomposer engine failures shouldn't represent potential threats that have slipped through your defenses...</description>
		<content:encoded><![CDATA[<p>i think i have a handle on the decomposer engine issue now&#8230; </p>
<p>it has to do with compressed files - password protection (scanners can&#8217;t guess passwords) and recursively compressed archives that go past the threshold depth that the scanner is willing to go (don&#8217;t want to get bogged down by a zip bomb)&#8230; both of these things will cause the scanner to stop trying and log the event&#8230;</p>
<p>it&#8217;s my understanding, though, that you can configure things to quarantine what can&#8217;t be scanned and since you only have av on the mail gateways it stands to reason that if you do have things configured that way those 1253 decomposer engine failures shouldn&#8217;t represent potential threats that have slipped through your defenses&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
