On Tue, Feb 05, 2008 at 06:27:15AM -0000, Alexander Belchenko wrote:
> Paul Pelzl ??????????:
> | Another idea: it is possible that Sophos just looks at the .ZIP file
> | extension to decide that the file may be "unsafe." I wonder if simply
> | using a different archive name, e.g. "library.foo" would solve the
> | problem.
>
> Here is test build with mangled name of library.zip (renamed to just 'python').
> http://bzrdev.bialix.com/bzr-setup-1.2.0.dev.0-mangled.exe
>
> Paul, can you test it?
Unfortunately, this doesn't perform any better. Probably Sophos is
scanning for the magic numbers in the zip header.
On Tue, Feb 05, 2008 at 06:27:15AM -0000, Alexander Belchenko wrote: bzrdev. bialix. com/bzr- setup-1. 2.0.dev. 0-mangled. exe
> Paul Pelzl ??????????:
> | Another idea: it is possible that Sophos just looks at the .ZIP file
> | extension to decide that the file may be "unsafe." I wonder if simply
> | using a different archive name, e.g. "library.foo" would solve the
> | problem.
>
> Here is test build with mangled name of library.zip (renamed to just 'python').
> http://
>
> Paul, can you test it?
Unfortunately, this doesn't perform any better. Probably Sophos is
scanning for the magic numbers in the zip header.
Paul