Unsolicited testimonials I have received in my email:
Date: Tue, 21 May 2002 17:03:43 -0400 From: Kent WagonerTo: jhardin@impsec.org Subject: Compliments on the E-Mail Sanitizer Mr. Hardin, I just wanted to send you a short note thanking you for your e-mail sanitizer system. It has, without a doubt, saved my company (and my sanity) many times over. Since installing it on my company's central mailserver, I have trapped and disposed of every single inbound e-mail virus that has come our way. We have a zero-percent infection rate for systems that get their mail from my mailserver. In fact, some of my users have grown so confident in the mailserver's ability to stop viruses and worms that they've talked about removing the anti-virus software installed on their workstations (an idea I have strongly discouraged.) My thanks for an incredible application. You've made this SysAdmin's life much, much easier. Kent J. Wagoner System Administrator Osprey Technologies / ViewCast Corporation
Date: Wed, 07 Feb 2001 08:29:06 -0800 From: ****** To: ***** Cc: jhardin@wolfenet.com Subject: Helpful E-mail for getting rid of Hybris and other net based virii - system admins Here's the deal: I'm a network admin with a few mail servers running Sendmail 8.11. E-mail security has ALWAYS been the highest priority on our security checklist for invasion techniques. Today we were battling with the Hybris worm, behind the scenes... Point blank, we've stopped the following dead, even before the news services caught on to the onslaught: Melissa (all variants) CIH Hermes Hybris ProLin MyRomeo I Love You Navidad New Apt Explore Zip All VBS, SCR, CHM, PIF delivered virii And more... All I can say is: Jason[sic] Hardin's Procmail script http://www.impsec.org/email-tools/procmail-security.html This script has saved myself, and our company well into the ten-thousands of dollars of downtime, productivity, and overall potential destruction by these viruses. It's easy to use, and anyone with a UNIX mail server and procmail should implement this (either sitewide or per user).
Thanks!
n.b.: my name is John...
I can be contacted at <jhardin@impsec.org> - you could also visit my home page.