Discussion:
unable-to-release-qurantine-message
Mohammed Ejaz
2015-03-15 14:31:11 UTC
Permalink
Hill



I am trying to release the quarantine message with the below send mail
command, but still it get failed to release and shows the below error. Any
help would be highly appreciated.





Thanks in advance







Below are my settings In MailScanner.conf

Quarantine Whole Messages As Queue Files = no

and in the quarantine directory you have a file called message (this is the
complete human-readible message, but without the envelope info). Just do



Command



cd /path/to/quarantine/dir

sendmail -t -i < message





Error



============================================================================
================

his is a message from the MailScanner E-Mail Virus Protection Service

----------------------------------------------------------------------

The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"

is on the list of unacceptable attachments for this site and has been

replaced by this warning message.



If you wish to receive a copy of the original attachment, please

e-mail helpdesk and include the whole of this message

in your request. Alternatively, you can call them, with

the contents of this message to hand when you call.



At Sun Mar 15 17:16:24 2015 the virus scanner said:

MailScanner: Attempt to hide real filename extension (EAWEMA150300207,
ELSHERIF AHMED.RAMI.doc)



Note to Help Desk: Look on the yoursite (nmersal.cyberia.net.sa) MailScanner
in /var/spool/MailScanner/quarantine/20150315 (message 1208F5DFF51.A76CD).
--
Postmaster

Your Organisation Name Here

www.your-organisation.com



For all your IT requirements visit: http://www.transtec.co.uk

============================================================================
======================================
Jeremy McSpadden
2015-03-15 15:21:28 UTC
Permalink
The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"

Your file has a double extension.

.rami.doc

--
Jeremy McSpadden | Flux Labs
Local - 850-250-5590x501<tel:850-250-5590;501> | Mobile - 850-890-2543<tel:850-890-2543>
Fax - 850-254-2955<tel:850-254-2955> | Toll Free - 877-699-FLUX<tel:877-699-FLUX>
Web - http://www.fluxlabs.net<http://www.fluxlabs.net/>


On Mar 15, 2015, at 9:49 AM, Mohammed Ejaz <***@cyberia.net.sa<mailto:***@cyberia.net.sa>> wrote:


Hill

I am trying to release the quarantine message with the below send mail command, but still it get failed to release and shows the below error. Any help would be highly appreciated.


Thanks in advance



Below are my settings In MailScanner.conf
Quarantine Whole Messages As Queue Files = no
and in the quarantine directory you have a file called message (this is the complete human-readible message, but without the envelope info). Just do

Command

cd /path/to/quarantine/dir
sendmail -t -i < message


Error

============================================================================================
his is a message from the MailScanner E-Mail Virus Protection Service
----------------------------------------------------------------------
The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"
is on the list of unacceptable attachments for this site and has been
replaced by this warning message.

If you wish to receive a copy of the original attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.

At Sun Mar 15 17:16:24 2015 the virus scanner said:
MailScanner: Attempt to hide real filename extension (EAWEMA150300207, ELSHERIF AHMED.RAMI.doc)

Note to Help Desk: Look on the yoursite (nmersal.cyberia.net.sa) MailScanner in /var/spool/MailScanner/quarantine/20150315 (message 1208F5DFF51.A76CD).
--
Postmaster
Your Organisation Name Here
www.your-organisation.com<http://www.your-organisation.com>

For all your IT requirements visit: http://www.transtec.co.uk
==================================================================================================================
--
MailScanner mailing list
***@lists.mailscanner.info<mailto:***@lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Mohammed Ejaz
2015-03-15 15:50:37 UTC
Permalink
Is there any way to overcome this problem. as I wanted to allow double
extension. It should be from the filename.rules file.



This is the syntax is it??



# Deny all other double file extensions. This catches any hidden filenames.

allow \.[a-z][a-z0-9]{2,3}\s*\.[a-z0-9]{3}$ Found possible filename
hiding Attempt to hide real filename extension



Ejaz



From: mailscanner-***@lists.mailscanner.info
[mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Jeremy
McSpadden
Sent: Sunday, March 15, 2015 6:21 PM
To: MailScanner discussion
Subject: Re: unable-to-release-qurantine-message



The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"



Your file has a double extension.



.rami.doc

--
Jeremy McSpadden | Flux Labs
Local - 850-250-5590x501 <tel:850-250-5590;501> | Mobile - 850-890-2543
Fax - 850-254-2955 | Toll Free - 877-699-FLUX
Web - http://www.fluxlabs.net <http://www.fluxlabs.net/>




On Mar 15, 2015, at 9:49 AM, Mohammed Ejaz <***@cyberia.net.sa> wrote:



Hill



I am trying to release the quarantine message with the below send mail
command, but still it get failed to release and shows the below error. Any
help would be highly appreciated.





Thanks in advance







Below are my settings In MailScanner.conf

Quarantine Whole Messages As Queue Files = no

and in the quarantine directory you have a file called message (this is the
complete human-readible message, but without the envelope info). Just do



Command



cd /path/to/quarantine/dir

sendmail -t -i < message





Error



============================================================================
================

his is a message from the MailScanner E-Mail Virus Protection Service

----------------------------------------------------------------------

The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"

is on the list of unacceptable attachments for this site and has been

replaced by this warning message.



If you wish to receive a copy of the original attachment, please

e-mail helpdesk and include the whole of this message

in your request. Alternatively, you can call them, with

the contents of this message to hand when you call.



At Sun Mar 15 17:16:24 2015 the virus scanner said:

MailScanner: Attempt to hide real filename extension (EAWEMA150300207,
ELSHERIF AHMED.RAMI.doc)



Note to Help Desk: Look on the yoursite (nmersal.cyberia.net.sa) MailScanner
in /var/spool/MailScanner/quarantine/20150315 (message 1208F5DFF51.A76CD).
--
Postmaster

Your Organisation Name Here

www.your-organisation.com



For all your IT requirements visit: http://www.transtec.co.uk

============================================================================
======================================
--
MailScanner mailing list
***@lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Jerry Benton
2015-03-15 16:28:14 UTC
Permalink
You must do this for it to work correctly:

Quarantine Whole Messages As Queue Files = yes

-
Jerry Benton
www.mailborder.com
Is there any way to overcome this problem. as I wanted to allow double extension. It should be from the filename.rules file.
This is the syntax is it??
# Deny all other double file extensions. This catches any hidden filenames.
allow \.[a-z][a-z0-9]{2,3}\s*\.[a-z0-9]{3}$ Found possible filename hiding Attempt to hide real filename extension
Ejaz
Sent: Sunday, March 15, 2015 6:21 PM
To: MailScanner discussion
Subject: Re: unable-to-release-qurantine-message
The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"
Your file has a double extension.
.rami.doc
--
Jeremy McSpadden | Flux Labs
Local - 850-250-5590x501 <tel:850-250-5590;501> | Mobile - 850-890-2543 <tel:850-890-2543>
Fax - 850-254-2955 <tel:850-254-2955> | Toll Free - 877-699-FLUX <tel:877-699-FLUX>
Web - http://www.fluxlabs.net <http://www.fluxlabs.net/>
Post by Jeremy McSpadden
Hill
I am trying to release the quarantine message with the below send mail command, but still it get failed to release and shows the below error. Any help would be highly appreciated.
Thanks in advance
Below are my settings In MailScanner.conf
Quarantine Whole Messages As Queue Files = no
and in the quarantine directory you have a file called message (this is the complete human-readible message, but without the envelope info). Just do
Command
cd /path/to/quarantine/dir
sendmail -t -i < message
Error
============================================================================================
his is a message from the MailScanner E-Mail Virus Protection Service
----------------------------------------------------------------------
The original e-mail attachment "EAWEMA150300207, ELSHERIF AHMED.RAMI.doc"
is on the list of unacceptable attachments for this site and has been
replaced by this warning message.
If you wish to receive a copy of the original attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.
MailScanner: Attempt to hide real filename extension (EAWEMA150300207, ELSHERIF AHMED.RAMI.doc)
Note to Help Desk: Look on the yoursite (nmersal.cyberia.net.sa) MailScanner in /var/spool/MailScanner/quarantine/20150315 (message 1208F5DFF51.A76CD).
--
Postmaster
Your Organisation Name Here
www.your-organisation.com <http://www.your-organisation.com/>
For all your IT requirements visit: http://www.transtec.co.uk <http://www.transtec.co.uk/>
==================================================================================================================
--
MailScanner mailing list
http://lists.mailscanner.info/mailman/listinfo/mailscanner <http://lists.mailscanner.info/mailman/listinfo/mailscanner>
Before posting, read http://wiki.mailscanner.info/posting <http://wiki.mailscanner.info/posting>
Support MailScanner development - buy the book off the website!
--
MailScanner mailing list
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Loading...