Discussion:
MailScanner Digest, Vol 98, Issue 1
Tiago Eduardo Zacarias
2014-02-01 13:39:22 UTC
Permalink
Good morning Martin Hepworth


Restarted the service mailscanner and yet the policy described in
/etc/mailscanner/files- types.conf not and applied as observed in test
with attachments and compressed files pure. Example executables files
when attached in the policy even deny the mailscanner does not block,
already put debug in order to see something but does not return
anything, so that was checked informs entered the path of the program
/usr/bin/file now and then forwards it to the clamav anti-virus.

What may be you could give me a light, do not know if I can forward my
list to facilitate mailscanner.conf.

I thank you for your attention.

Att

Tiago Eduardo Zacarias
LPIC-1
Send MailScanner mailing list submissions to
mailscanner at lists.mailscanner.info
To subscribe or unsubscribe via the World Wide Web, visit
http://lists.mailscanner.info/mailman/listinfo/mailscanner
or, via email, send a message with subject or body 'help' to
mailscanner-request at lists.mailscanner.info
You can reach the person managing the list at
mailscanner-owner at lists.mailscanner.info
When replying, please edit your Subject line so it is more specific
than "Re: Contents of MailScanner digest..."
1. Filter-Files (Tiago Eduardo Zacarias)
2. Re: Filter-Files (Martin Hepworth)
----------------------------------------------------------------------
Message: 1
Date: Fri, 31 Jan 2014 13:09:53 -0200
From: Tiago Eduardo Zacarias <tiago at tiagoti.com.br>
Subject: Filter-Files
To: mailscanner at lists.mailscanner.info
Message-ID: <52EBBCC1.80600 at tiagoti.com.br>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Good Morning List MailScanner,
I ha a few days trying to accomplish in the file filter mailscanner
unsuccessfully already realized reinstalling it with all dependencies,
and even by setting the parameters to allow and deny files to the files
filetypes but I can not perform the filter in mailscanner if I send out
direct aqruivo example executable type attached zipped or not the
mailscanner blocks, like a support to this problem.
Attached the file mailscanner.
Thank you.
CPU = Pentium 4 3 Ghz
Postfix Version: 2.6.6-2.2
MailScanner Version: 4.84.6-1
------------------------------
Message: 2
Date: Fri, 31 Jan 2014 16:15:14 +0000
From: Martin Hepworth <maxsec at gmail.com>
Subject: Re: Filter-Files
To: MailScanner discussion <mailscanner at lists.mailscanner.info>
<CAGDKorLiogMp8QTGuHhbFcXaaotBVd4qh1LNHpgESU7nYvOMEg at mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"
What have you tried with the filetypes thats doesnt work and did you start
and stop MailScanner after the change?
Tiago Eduardo Zacarias
2014-02-01 13:49:36 UTC
Permalink
Good morning Martin Hepworth


Restarted the service mailscanner and yet the policy described in / etc
/ mailscanner / files - not types.conf and applied as observed in test
with attachments and compressed files pure . Example executables files
when attached in the policy even deny the mailscanner does not block ,
already put debug in order to see something but does not return anything
, so that was checked informs entered the path of the program / ??usr /
bin / file now and then forwards it to the clamav anti -virus .

Example of policy

Contet of /etc/mailscanner/files-types.conf :

# To disable this feature , set this to just " Filetype Rules = " or
September
# The location of the file command to a blank string .
Filetype Rules = % etc -dir % / filetype.rules.conf

Content of / filetype.rules.conf :

allow text -
allow \ bscript -
allow archive -
allow postscript -
deny self -extract No self-extracting archives Self-extracting archives
The allowed
deny executable No executables No programs allowed
# EXAMPLE : deny - x - dosexec In DOS executables No DOS programs allowed
deny ELF No executables No programs allowed
rename Registry Windows Registry entries ( renamed ) Windows Registry
files ( renamed )

I thank you for your attention .

Att

Tiago Eduardo Zacarias
LPIC-1
Send MailScanner mailing list submissions to
mailscanner at lists.mailscanner.info
To subscribe or unsubscribe via the World Wide Web, visit
http://lists.mailscanner.info/mailman/listinfo/mailscanner
or, via email, send a message with subject or body 'help' to
mailscanner-request at lists.mailscanner.info
You can reach the person managing the list at
mailscanner-owner at lists.mailscanner.info
When replying, please edit your Subject line so it is more specific
than "Re: Contents of MailScanner digest..."
1. Filter-Files (Tiago Eduardo Zacarias)
2. Re: Filter-Files (Martin Hepworth)
----------------------------------------------------------------------
Message: 1
Date: Fri, 31 Jan 2014 13:09:53 -0200
From: Tiago Eduardo Zacarias <tiago at tiagoti.com.br>
Subject: Filter-Files
To: mailscanner at lists.mailscanner.info
Message-ID: <52EBBCC1.80600 at tiagoti.com.br>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Good Morning List MailScanner,
I ha a few days trying to accomplish in the file filter mailscanner
unsuccessfully already realized reinstalling it with all dependencies,
and even by setting the parameters to allow and deny files to the files
filetypes but I can not perform the filter in mailscanner if I send out
direct aqruivo example executable type attached zipped or not the
mailscanner blocks, like a support to this problem.
Attached the file mailscanner.
Thank you.
CPU = Pentium 4 3 Ghz
Postfix Version: 2.6.6-2.2
MailScanner Version: 4.84.6-1
------------------------------
Message: 2
Date: Fri, 31 Jan 2014 16:15:14 +0000
From: Martin Hepworth <maxsec at gmail.com>
Subject: Re: Filter-Files
To: MailScanner discussion <mailscanner at lists.mailscanner.info>
<CAGDKorLiogMp8QTGuHhbFcXaaotBVd4qh1LNHpgESU7nYvOMEg at mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"
What have you tried with the filetypes thats doesnt work and did you start
and stop MailScanner after the change?
Mark Sapiro
2014-02-02 02:59:16 UTC
Permalink
Post by Tiago Eduardo Zacarias
Restarted the service mailscanner and yet the policy described in / etc
/ mailscanner / files - not types.conf and applied as observed in test
with attachments and compressed files pure . Example executables files
when attached in the policy even deny the mailscanner does not block ,
already put debug in order to see something but does not return anything
, so that was checked informs entered the path of the program / ??usr /
bin / file now and then forwards it to the clamav anti -virus .
It is very difficult for me to understand exactly what you are trying to
say, but in your MailScanner.conf file do you have

File Command = /usr/bin/file

or some other path? what do you get when you invoke /usr/bin/file or
whatever path it is on the 'executable' file that is not blocked by
MailScanner?
--
Mark Sapiro <mark at msapiro.net> The highway is for gamblers,
San Francisco Bay Area, California better use your sense - B. Dylan
Loading...