<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:copyright="http://blogs.law.harvard.edu/tech/rss" xmlns:image="http://purl.org/rss/1.0/modules/image/">
    <channel>
        <title>Emerald Spam Shield</title>
        <link>http://techtalk.emeraldshield.com/category/7.aspx</link>
        <description>Information related to our Emerald Spam Shield product line.  Updates to the service and just general talk about things we do and why.</description>
        <language>en-US</language>
        <copyright>Emerald Technology, Inc.</copyright>
        <managingEditor>contactus@emeraldshield.com</managingEditor>
        <generator>Subtext Version 1.9.4.78</generator>
        <item>
            <title>PDF Spam gone wild</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/08/03/39.aspx</link>
            <description>&lt;p&gt;Is anyone else sick of PDF spam yet?&lt;/p&gt;
&lt;p&gt;This has to be one of the dummest forms of spam yet.  Outlook does not auto preview PDF files.  And since we all know that spammers target Outlook what is the point?  You would have to double click the PDF and launch Reader to see the stock image embedded in the PDF.  Some of the new ones now include only text, and some are now zipping the PDF to get around the PDF block some companies have put into place.  &lt;/p&gt;
&lt;p&gt;Sad.  I guess not enough idiots bought the pump and dump stock from just PDF spam, now they have to send millions more.  I received over 5,000 in ONE email box yesterday.  Wow.  Like anyone would bother to open all of those and buy some stock that way?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you should do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;First, if you do not need PDF's in your company attachment list, just remove them.  Set PDF as a blocked attachment.  This is not a great solution, but it works.&lt;/p&gt;
&lt;p&gt;Make sure your userlist is uploaded and wildcard receive is turned OFF.&lt;/p&gt;
&lt;p&gt;Turn on Relay Delay.  Yes, this slows down your first contact from remote users, but it really does work well for this type of spammer.  If you can't afford to have email delays during the day, turn it on Friday night and leave it until Monday.  That will help you with the huge deluge of spam you see first thing Monday morning.&lt;/p&gt;
&lt;p&gt;Up the trust level of the RBLs, and set them to REJECT.  Most of these new spammers are smart enough to stay off the RBLs, but it does help some.  &lt;/p&gt;
&lt;p&gt;Use a nonstandard port on your server.  Spammers know that companies like Emerald exist and will try to get around us and connect direct to your server.  Especially if your server is named mail.domain they will hit it more and more these days.  &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Spammers and bot nets getting smarter&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;They are now getting smarter in their blasting techniques.  They will only send 10-20 at a time from a machine, and then let the machine stay idle for an hour or more.  It means they have to run more bot nets, but it keeps their bots alive longer.  The person with the machine probably does not notice a slight slowdown once an hour, and they stay useful to the spammer longer.  I personally applaud the efforts of some of the ISP's now to block outbound port 25 from their residential customers.  99% of this traffic is probably bots sending spam.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/39.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/08/03/39.aspx</guid>
            <pubDate>Fri, 03 Aug 2007 08:36:20 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/08/03/39.aspx#feedback</comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/39.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Celeste with Small Business Trends Radio</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/03/09/30.aspx</link>
            <description>&lt;p&gt;Celeste was interviewed for Small Business Trends radio!&lt;/p&gt;
&lt;p&gt;I think you can tell she was pretty nervous (her first public speaking engagement).&lt;/p&gt;
&lt;p&gt;She is talking about Email Archival and spam filtration.  Click the button to listen!&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.smbtrendwire.com/SBSNYC_EMERALDTECHNOLOGY.mp3"&gt;&lt;img title="Heard on Small Business Trends Radio" alt="Heard on Small Business Trends Radio" border="0" src="http://www.smbtrendwire.com/sbtradio8.gif" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/30.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/03/09/30.aspx</guid>
            <pubDate>Fri, 09 Mar 2007 06:34:46 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/03/09/30.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/30.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Moving our Virus Scanner to ClamAV</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/02/28/29.aspx</link>
            <description>&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;Moving our Virus Scanner to ClamAV&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;I wrote up a while back about my &lt;/font&gt;&lt;a href="http://techtalk.emeraldshield.com/archive/2007/02/06/24.aspx"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;testing of ClamAV&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt; and why I thought it was a good product.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It is, and I like it a lot.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;After that write up I spent more time testing, and was even more impressed.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Some of their Phishing detection was better than any other AV product I tested.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And the service native to Win32 is rock solid.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;I ran over 500,000 spam messages through the test system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Not one fault.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And I was pleasantly surprised that is detected a number of EBay scams, and other Phishing messages.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;That is an added bonus for us since we already scan for that type of stuff, but having a second opinion is a good thing.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;The other big bonus for us is improved scan speed.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Since the virus definitions are kept in RAM with the ClamD service, the clamdscan application does not have to load the database every email.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It passes the data to the service and gets a reply over a local socket.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This improves our scan speed, but it uses a LOT more CPU than our older solution.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;There is no free lunch, so we are willing to take the hit on CPU usage.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;CPU’s keep getting faster, and we will upgrade the processors on the servers if we need to in order to meet the load.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;When is this going live?&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;This should be live on most of the servers by March 1, 2007.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;We expect all servers to be upgraded by March 4&lt;sup&gt;th&lt;/sup&gt;.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;You should not need to make any changes to your settings.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/29.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/02/28/29.aspx</guid>
            <pubDate>Wed, 28 Feb 2007 17:59:19 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/02/28/29.aspx#feedback</comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/29.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Country Code reporting useful again?</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/02/13/27.aspx</link>
            <description>&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;These are interesting times to be in the spam industry for sure.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Spammers are changing tactics on average about once every three weeks right now.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And the rise of the stock spam is growing faster than anyone had ever thought possible.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;We are always evaluating our technique for effectiveness and changing to meet the times.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Looks like it is time to implement the country code system again…&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="FONT-SIZE: 14pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;Country Codes – useful again?&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Do you only receive email from certain countries?&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Would you like to be able to stop email based on the country it comes from?&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;We used to have a country blocking system, but over time it became very ineffective.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Most of the spammers started using zombie machines from here in the USA.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;They were not sending from their originating servers.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And in many cases they were using open relays in other countries as well.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;We took a sample of 250,000 stock spams delivered over the past seven days and looked them up in the country code database.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Any guess as to what percentage came from one country?&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;41% came from Russia, and 18% came from China directly.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Wow.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;We did not expect that at all.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="FONT-SIZE: 14pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;GeoIP database&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;We are going to start using the &lt;/font&gt;&lt;a href="http://www.maxmind.com/app/country"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;GeoIP Country database&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt; from MaxMind.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;They claim a 99% accuracy for countries, including AOL and other dialup providers that were almost always wrong in our old database.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And they update their system every week.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;The pricing is very reasonable as well.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/27.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/02/13/27.aspx</guid>
            <pubDate>Tue, 13 Feb 2007 15:02:54 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/02/13/27.aspx#feedback</comments>
            <slash:comments>12</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/27.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Update on our virus scanner plans</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/02/06/24.aspx</link>
            <description>&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;Update on Virus Scanner changes&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;I have been looking at &lt;/font&gt;&lt;a href="http://www.clamav.net/"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;ClamAV&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; for the past few days.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;I am very impressed.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Not only have they managed to port the Unix anti-virus scanner to Windows, but they have done a good job of it.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;For those of you who do not know what ClamAV is I will provide a brief summary.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt 0.5in"&gt;&lt;font face="Calibri"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: #333333; LINE-HEIGHT: 115%"&gt;Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use with your own software. Most importantly, the virus database is &lt;em&gt;&lt;span style="FONT-FAMILY: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi"&gt;kept up to date&lt;/span&gt;&lt;/em&gt; .&lt;/span&gt;&lt;span style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;They have also ported the base packages to Windows &lt;/font&gt;&lt;a href="http://w32.clamav.net/"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This is not a mere port.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;There is no Unix interop layer, and the ClamD (The service to use the windows terminology) is very small using less than 30 MB of RAM, and runs multi threaded very well.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;If you are interested in their stand alone scanner take a look at the &lt;/font&gt;&lt;a href="http://www.clamwin.com/"&gt;&lt;font face="Calibri" color="#800080" size="3"&gt;Clam Win&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; site.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This is the client experience application.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It is a pretty good GUI, a scanning scheduler, auto downloading of updates, an Outlook plugin to scan attachments, and more.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This is a LOT to offer for free.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Now you have no reason not to install an anti-virus on all your PC’s.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;The only option missing from the system is a real time scan system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;I personally have never really been a big fan of them since they can really impact your system performance.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;I almost always have mine turned off on my other systems. &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;Why use a client server anti-virus scanner?&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Our current solution from F-Prot is not a client server system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;So this is the basic flow that happens for each email:&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Email and file attachments are stored to disk&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Command line scanner is run &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Command line scanner has to load the entire virus database into ram&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;File is scanned&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Result is returned and all memory is freed up&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;This is how we have done it since 2003 when we added the anti-virus scanning to the system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It is not very fast, but it does work.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And since F-Prot was charging us a very good price I was willing to live with the performance hit.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It has caused us a few backlogs over the years waiting for the scanners to finish files, but not enough to really worry about it.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;The “big guys” have nice SDK’s that you call in this manner:&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;A service is started at Windows startup that loads the virus database&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Email and file attachments are stored to disk – OR – streamed across a socket to the service&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Command line scanner only contacts the service to tell it what to scan (very small memory footprint)&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2"&gt;&lt;span style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT: 7pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;File is scanned by the service and the result is returned&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Obviously this is a much more efficient way of handling the files.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;But we could not afford to use most of these SDK based products due to costs.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;One vendor wanted over $4,000 for the SDK, and then to charge us over $10,000 per month for an unlimited mailbox license.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;No way is that cost effective.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Well, guess what?&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Clam AV has both of these models implemented.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;You can scan one file at a time, or use the service.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Your choice.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;You can even install the scanner on a Unix machine and scan from the Windows to the Unix machine.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Now that is what I call flexible.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;The tests I performed&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;I have quite a huge sampling of spam and virus attachments on my drives since this is what we do for a living.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;So I took a small sample of 27,498 emails (246.3 MB) that arrived in our spam traps and ran them through the system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;My first test was our existing F-Prot Version 3 engine.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Then I tried the F-Prot Version 6 (new version).&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Then I also tried the Clam AV command line scanner, and the ClamD (think client / server) version as well.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;In all cases these files were in a temp directory on my drive locally.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;All of these tests were performed on an Intel Core 2 Duo CPU with 4 GB of RAM.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;F-Prot Version 3&lt;br /&gt;
&lt;/strong&gt;This is the system we have in place right now.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It can scan at a decent speed, but is not the best solution for the reasons mentioned above.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;The files that were skipped are an oddity to me.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;None of them were really bad, they had bad encoding due to spammers doing crazy things, but the anti-virus scanner should not skip them in my opinion.&lt;br /&gt;
Files Tagged:&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;34&lt;br /&gt;
Files Skipped due to Error: 29&lt;br /&gt;
Total Time:&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;21:02&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;F-Prot Version 6 &lt;br /&gt;
&lt;/strong&gt;Not sure why they jumped the version numbers this way, but they did.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This is the new model and will cost us a LOT more money if we were to deploy it.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;They have changed their licensing and we would no longer be able to use the versions that we have in place right now.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;F-Prot does have an SDK now, but it is not available to mere mortals like us without a lot of NDA paperwork and contracts&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;- no thanks.&lt;br /&gt;
Files Tagged: 34&lt;br /&gt;
Files Skipped due to error: 24&lt;br /&gt;
Total Time:&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;1:18:34&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;ClamAV Command Line&lt;br /&gt;
&lt;/strong&gt;This is the true apples to apples comparison because this version is a command line scanner just like F-Prot.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It has different return codes, but it works basically the same way.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Notices that zero files were skipped.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Maybe they couldn’t decode them either, but they did scan what they found anyway.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And they actually managed to tag two of the “bad” files from F-Prot as I-FRAME exploits.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Kudos to ClamAV!&lt;br /&gt;
Files tagged:&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;36&lt;br /&gt;
Files skipped: 0&lt;br /&gt;
Total Time: 31:18&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;ClamAV Client Server&lt;br /&gt;
&lt;/strong&gt;Now this is not the best comparison since F-Prot is command line and this is client server, but I am going to do it anyway.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Same options as the ClamAV command line scan above, but with a much faster completion time.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;By far the fastest, and if I were to actually spin up two or more of these it can take advantage of the dual core chips much better since we are not duplicating the 25 MB virus database in ram for each instance.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Running several threads did not provide a linear speed up mostly because the drive starts to become the limiting factor.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Single Threaded Test&lt;br /&gt;
Files tagged: 36&lt;br /&gt;
Files skipped: 0&lt;br /&gt;
Total time: 9:21&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Five Thread Test&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;&lt;br /&gt;
Files tagged: 36&lt;br /&gt;
Files skipped: 0&lt;br /&gt;
Total time: 5:47&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Now I know some people will say that I could spin up multiple copies of the command line version as well.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And you are correct, but I would be paying a much larger price in terms of memory usage.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;For each app that starts we would use approximately 28 MB of RAM.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;So starting five copies means you use 140 MB of RAM, where the ClamAV service still only uses that base 28 MB.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;Should you get rid of your local anti virus?&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;Absolutely not.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This system is not a replacement for other ways bad files get onto your system.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;And like any software it is not fool proof.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Having more than one vendor scanning for bad attachments is always a good practice.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;You can just look at our service being your first line of defense, but you still need a local scanner.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;strong style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 16pt; LINE-HEIGHT: 115%"&gt;&lt;font face="Calibri"&gt;What does all this mean?&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;OK, sorry for the rather long winded explanation as to why I think we are going to change our anti-virus system to ClamAV.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;It will mean less CPU usage, which means that we can continue to offer the best prices for our customers.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;We are going to deploy the ClamAV system onto our spam traps and beta servers and evaluate it further.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Make sure there are no crashes, memory leaks, etc.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;This is a normal deployment scenario for us whenever a component changes.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;We implement it internally, and then stage it to the beta servers.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;Our spam traps generate a TON of attacks and some really bad virus attachments, so it is a logical place for us to test this as well.&lt;span style="mso-spacerun: yes"&gt;  &lt;/span&gt;If all goes well I expect to announce that we are moving everyone sometime in early March 2007.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="Calibri" size="3"&gt;As always, any concerns or feedback is greatly appreciated.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/24.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/02/06/24.aspx</guid>
            <pubDate>Tue, 06 Feb 2007 10:50:23 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/02/06/24.aspx#feedback</comments>
            <slash:comments>4</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/24.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Anti Virus prices going up</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/01/30/23.aspx</link>
            <description>&lt;p&gt;As we have discussed before we use F-Protect as our antivirus solution on our servers.  Well, a new version of F-Protect has been released and they are changing the pricing model for servers.  We have a corporate license agreement with them that expires in March, so look for prices to go up when we renew.  I don't agree with their new pricing model, but we don't have much say in the matter either.  (Let's just say the cost to us will be FIVE TIMES higher than what we pay now)&lt;/p&gt;
&lt;p&gt;Pricing is now based on the number of mailboxes scanned.  I don't understand why though.  They don't pay for the CPU time, I do.  There is no difference to them if I scan 10 files or 10 million files.  I am the one paying the CPU time.  The updates are the same.  There is not even a real API to call their system, we use a command line app that returns status codes to us.  That has been OK with us in the past because they were so inexpesive compared to the big guys.  But the big guys have fancy API's that you call in process and avoid a lot of CPU overhead.  I always figured it was a price / performance trade off.  Now we are going to have to evaluate if F-Protect is the right antivirus vendor for us.&lt;/p&gt;
&lt;p&gt;We had avoided most of the other vedors because they were extremely expensive for a small service like ours.  Some of them were $4,000 or more for the server, and then you still had to pay on a per mailbox basis.  That is just too expensive.  We may have to look into ClamAV or some of the other smaller vendors out there.  I had liked F-Prot because they always scored a 10/10 on all the antivirus roundup tests.&lt;/p&gt;
&lt;p&gt;Anyone else have an anti virus solution that is cost effective for small business?&lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/23.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/01/30/23.aspx</guid>
            <pubDate>Tue, 30 Jan 2007 19:26:40 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/01/30/23.aspx#feedback</comments>
            <slash:comments>2</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/23.aspx</wfw:commentRss>
        </item>
        <item>
            <title>New File Formats for Office 2007</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/01/26/21.aspx</link>
            <description>&lt;font face="Arial"&gt;
&lt;p&gt;&lt;font size="4"&gt;New file extensions in Microsoft Office 2007&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;Microsoft has changed all their internal file formats for the new release of Office 2007.  They are almost all XML based now, and they are open and documented.  This is good news going forward, but could be a problem for a while until everyone gets upgraded.  Fortunately they have provided the ability to “save as” an older format so you can send them to existing users, and they have added a few new nice changes as well.   &lt;/p&gt;
&lt;p&gt;&lt;font size="4"&gt;PDF from Office&lt;/font&gt;&lt;br /&gt;
You can now save as a PDF direct from Office 2007 almost everywhere.  It is not “built in”, but a free download from Microsoft’s site.  The presenter at the show said that was due to legal reasons.  Don’t expect to digitally sign or anything fancy with the PDF, but you can make basic PDF files with ease.  And let’s face it, that is what 99% of the people do with the Acrobat system right now.  Basic PDF output.  That is why Adobe made the “Adobe Elements” product line.   It could only make basic PDF’s, but they still charged you a license fee for it.  You cannot import PDF files back into Office 2007 either.  Only very simple output.  So it is not a replacement for Acrobat, but it will meet the needs of most of your staff.&lt;/p&gt;
&lt;p&gt;&lt;font size="4"&gt;XPS File Format&lt;/font&gt;&lt;br /&gt;
XPS is a new file format for Windows Vista, but you can get viewers for it for legacy systems as well.  &lt;/p&gt;
&lt;p&gt;Here is the official text:&lt;/p&gt;
&lt;table style="WIDTH: 90%" cellspacing="1" cellpadding="1" align="center" summary="" border="1"&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;td&gt;
            &lt;p&gt;&lt;font face="Arial"&gt;Document Experience&lt;/font&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;&lt;font face="Arial"&gt;In Windows Vista, you can easily create a document in a paginated, fixed-layout format. An XML Paper Specification (XPS) Document is a page-by-page view of the document's content as it would be printed. In other words, it turns on-screen content into true electronic paper.&lt;br /&gt;
            The XPS Document Viewer comes with Windows Vista and is also available for Windows XP and Windows Server 2003. The XPS Document Viewer allows you to open and read XPS Documents without using the original authoring application. You can also use the XPS Document Viewer to view and apply digital signatures to XPS Documents. The XPS Document Viewer is a Windows Rights Management Services (RMS)-enabled application so that any XPS Document protected with Windows RMS can be authenticated by the viewer.&lt;br /&gt;
            2007 Microsoft Office system applications can create XPS Documents from within the application, making it very simple to create XPS Documents from applications you are already used to using. The Microsoft XPS Document Writer can also be used by any Windows-compatible application to easily create an XPS Document. The Microsoft XPS Document Writer is a print-to-file converter that creates XPS Document files.&lt;/font&gt;&lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;/font&gt;&lt;blockquote dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;/blockquote&gt;&lt;font face="Arial"&gt;
&lt;p&gt;Sounds a lot like a competitor to PDF, right?  Here is the link to download the XPS viewer and more information at Microsoft.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/whdc/xps/viewxps.mspx "&gt;Microsoft XPS Viewer&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="3"&gt;File Extension Changes&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;Most of the new file extensions are the same base, but with an X at the end for XML.  So a Word .doc file becomes a .docx file. &lt;/p&gt;
&lt;p&gt;These are the file extensions we will be adding to the default block lists of each customer.  Feel free to edit them as always.  Many of these can be used to install macro and plugin systems to Office 2007, so we are recommending you block them by default.  It is only a matter of time until some hacker comes up with a clever way to use them to attack users.&lt;/p&gt;
&lt;p&gt;&lt;font face="Courier New"&gt;XLSX, XLSM, XLSB, PRN, SLK, XLA, XLAM, XPS, DOCX, DOCM, DOTX, DOTM, MHT, MHTML, PSW, PWD&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;We will be adding these to accounts over the weekend and will post a note in the account alert when it is complete.  If you do not want us to add them please let us know.  If we see you have made major changes to your file list we will ask before making changes.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/font&gt; &lt;font face="Tahoma" size="2"&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/font&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/21.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/01/26/21.aspx</guid>
            <pubDate>Fri, 26 Jan 2007 21:25:15 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/01/26/21.aspx#feedback</comments>
            <slash:comments>10</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/21.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Anti Virus Update</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/01/24/19.aspx</link>
            <description>&lt;p&gt;We are going to make a few changes to the anti virus detection system this week.&lt;/p&gt;
&lt;p&gt;We currently use &lt;a href="http://www.f-prot.com"&gt;F-Prot&lt;/a&gt; for our anti virus scanning.  They have started flagging some types of attachments as suspicious that we think should be tagged as a virus.&lt;/p&gt;
&lt;p&gt;For example, one of our customers received an email with an EXE in it that contained a W32/Downloader.HYDY.  This file is not actually a virus.  But it does go out to the Internet and download the virus to install it on your machine.  So, they return the code that it is suspicious. &lt;/p&gt;
&lt;p&gt;We handle suspicious attachments by looking harder at the email.  We add some points to the email for that response code, but if we don't find anything else we pass the email.  The only files we had ever seen returned as suspicious in the past were VBScript files in zips, or encrypted zips that contained EXEs; things of that nature.&lt;/p&gt;
&lt;p&gt;Our current thinking is to add a new handler and let you choose what to do with suspicious attachments.  Tag them differently (something like maybe subject: [CAUTION] rather than simply tagging it as spam.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/19.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/01/24/19.aspx</guid>
            <pubDate>Wed, 24 Jan 2007 20:09:05 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/01/24/19.aspx#feedback</comments>
            <slash:comments>4</slash:comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/19.aspx</wfw:commentRss>
        </item>
        <item>
            <title>New Image Filter</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/01/24/18.aspx</link>
            <description>&lt;p&gt;We released a new version of the image detection system yesterday.&lt;/p&gt;
&lt;p&gt;Our current system was detecting images that were part of the background (like the snow for winter / flowers for spring) type of thing.  These should now be safely ignored.  We have already identified one older version of Outlook Express that does not attach them correctly (but modern Outlooks still show them to you).  Please let us know if any others are tagged.&lt;/p&gt;
&lt;p&gt;We have also changed the way we look at some types of image.  Images that are part of a signature block should be safely ignored now as well.&lt;/p&gt;
&lt;p&gt;Please let us know if you have any problems.&lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/18.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/01/24/18.aspx</guid>
            <pubDate>Wed, 24 Jan 2007 20:01:33 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/01/24/18.aspx#feedback</comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/18.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Autologout on the secure site</title>
            <link>http://techtalk.emeraldshield.com/archive/2007/01/24/8.aspx</link>
            <description>&lt;p&gt;You may notice that if you sit on a single page longer than fifteen minutes you will automatically be logged out.  This is to release the server handles more quickly.  We have seen some customers who login to the site and leave the browser window open for 12 hours or more.  This can lead to errors on the site since session information expires much sooner than that.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;img src="http://techtalk.emeraldshield.com/aggbug/8.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Emerald Technology, Inc.</dc:creator>
            <guid>http://techtalk.emeraldshield.com/archive/2007/01/24/8.aspx</guid>
            <pubDate>Wed, 24 Jan 2007 18:51:53 GMT</pubDate>
            <comments>http://techtalk.emeraldshield.com/archive/2007/01/24/8.aspx#feedback</comments>
            <wfw:commentRss>http://techtalk.emeraldshield.com/comments/commentRss/8.aspx</wfw:commentRss>
        </item>
    </channel>
</rss>