[Dshield] Blocked Dshield list

Kenneth Coney superc at visuallink.com
Tue Sep 23 20:33:07 GMT 2003

Well, today they quarantined vol 9, issue 38 also even though I had already 
opted out of their filters, and I went off.  They had ignored my previous 
"end user" emails about the quarantine, and then they did it again.  I 
called my IP and was told there was no way to get things out of quarantine. 
  At that point I raged until they gave me "real live human" contact info 
for Postini, then I contacted them.  I ignored their end user spiel as 
there is a little clause buried somewhere in the Electronic 
Telecommunications Act (ETA) about intentionally blocking someone's email 
without their consent being a Federal crime, and I made mention of it and 
asked for contact info for their General Counsel, if they weren't going to 
fix the problem.  Seems dumb to sue someone for a blocked Dshield list I 
know, but I only work 4 hours or so a week and it is the principal of the 
thing, and I do have the time...  It worked.  The hint about the ETA and 
potential losses to me if I can't receive my emails got a response and 
Postini and my IP promptly got together and found a way of releasing the 
quarantines.  It remains to be seen if the fix is permanent or just for today.

Subject: Re: [Dshield] Blocked Dshield list
From: Ed Truitt <ed.truitt at etee2k.net>
Date: Tue, 23 Sep 2003 07:33:09 -0500
To: General DShield Discussion List <list at dshield.org>

Kenneth Coney wrote:

 > My IP decided a few days ago to use Postini.com as an email filter.  As 
a result the DShield text streams (the digest) are being trapped by the 
McAfee virus screener.  According to it, the DShield streams are all 
infected.  The reported specific is: X-pstnvirus: Exploit-MIME.gen.b
 > Postini advises the emails can not be fixed for forwarding to me. 
Emails to the support desk are not being answered.  I suspect McAfee 
doesn't know how to handle the application known as octet-stream, either 
that, or the list really is infected.     Either way I ain't getting the 
I noticed a few emails from the list that were quarantined as "infected" by 
Postini. - one from John Sage on 9-19 (RE:  Microsoft Patch), and the other 
from Doug White on 9-20 (RE:  MS Virus Header).  In both cases, the AV 
service Postini provides could not remove the "virus" from the email.

Ed Truitt
PGP fingerprint:  5368 D25E 468C A250 9833  CCD6 DBAE 9C25 02F9 0AB9

More information about the list mailing list