On Tue, 17 Feb 2009 11:10:00 +1100, Steven D'Aprano wrote:

> On Tue, 17 Feb 2009 07:30:55 am Paul Crawford wrote:
>> I just tried saving a suspect file of the avi.exe sort to see how it
>> behaved under LINUX using Pan 0.132 and I found it used '755'
>> permission settings thus rendering it (theoretically, at least)
>> executable.
> 
> Oh boy. I've just confirmed this in the wild:
> 
> Newsgroups: alt.binaries.howard-stern Subject: Re: REQ Repost Amelie
> video. - Private-Amelie-14-27.avi [1/1] Date: Fri, 13 Feb 2009 18:41:22
> -0000 Message-ID:
> <mpg.23ffce20e57626ba98a...@news.giganews.com>
> 
> This contains a trojan "Private-Amelie-14-27.avi.exe" which is saved as
> executable under Linux using Pan 0.132. In contrast, other attachments
> (e.g. JPEGs) are saved as non-executable...

I don't know what you and I are doing differently, but I just saved that same
attachment and got 644, as I would expect.  Are you saving to a FAT filesystem,
maybe?




_______________________________________________
Pan-users mailing list
Pan-users@nongnu.org
http://lists.nongnu.org/mailman/listinfo/pan-users

Reply via email to