Jump to content

replicant101

Members
  • Posts

    6
  • Joined

  • Last visited

Everything posted by replicant101

  1. We block executable files and we scan compressed files for executable content. Do people still allow compressed files through mail? Was thinking of adding this to our block list but haven't found time to search if it's now best practice to block it. our Fortigate firewall is usually quite quick in blocking those dodgy websites through clickable links. But again those zero day attacks are difficult.
  2. we had a teacher who was one of the lucky ones to be part of the zero day attacked with locky. after some reading best way to block these was to delete attachments with macro's. We get about one user a day forwarding an email where the attachment was removed because of macros and the user wants to know why they cant open the invoice :-) we decided to instead of just removing the attachment to block the whole mail if it contains macro's. BTW how did your user get the virus @NewBoy?
  3. We're planning on rolling this out next week. thanks for those steps jaykelly
×
×
  • Create New...