Discussion:
Rules for letters with attachments
Valentin Laskov
2014-02-27 10:44:30 UTC
Permalink
Hi all,

Recently my mail servers receive many emails with .exe files attached. These files are actually viruses but ClamAV still does not
recognize them.

MailScanner puts exe files in quarantine, sends the letter without the file to the recipient and sends notice letter to the sender
about the attached file removal. Notice returns with "User unknown" because the sender's e-mail address does not exist.

Here's why:

1. How can I configure MailScanner NOT to send any information to recipients of these letters?

Rules for letters with executable files attached to be like this:

quarantine = yes
send report to sender = yes
send report to recipient = no
send cleaned message to recipient = no

2. Is it possible for MailScanner to provide this new feature:
- email with restricted attachment arrived;
- MailScanner puts the whole letter in quarantine and sends following notice to the sender:
"If you are the real sender of the letter to ......... with ....... file attached, please respond to this letter without any
changes. If you are not the sender please do nothing.
If you are the sender, please confirm, otherwise your original letter will be deleted entirely."
- If MailScanner receive "User unknown" for the notice letter, it deletes original letter immediately;
- If MailScanner does not receive confirmation, it (optionaly informs recipient for the letter with quarantined attached file like
now) waits some days;
- If confirmation received MailScanner sends the original letter optionaly with or without attachment;
- If timeout of some days expired and no confirmation received, MailScanner deletes the letter.

Regards!
Valentin Laskov
Jerry Benton
2014-02-27 11:46:28 UTC
Permalink
Set:

Notify Senders Of Viruses = no

As for clamav not picking up the infection, I would run a MailScanner
--lint to make sure you are not getting lstat() errors. If you are, you
need to check permissions and validate what user clamd is running as.
Post by Valentin Laskov
Hi all,
Recently my mail servers receive many emails with .exe files attached.
These files are actually viruses but ClamAV still does not
recognize them.
MailScanner puts exe files in quarantine, sends the letter without the
file to the recipient and sends notice letter to the sender
about the attached file removal. Notice returns with "User unknown"
because the sender's e-mail address does not exist.
1. How can I configure MailScanner NOT to send any information to
recipients of these letters?
quarantine = yes
send report to sender = yes
send report to recipient = no
send cleaned message to recipient = no
- email with restricted attachment arrived;
- MailScanner puts the whole letter in quarantine and sends following
"If you are the real sender of the letter to ......... with ....... file
attached, please respond to this letter without any
changes. If you are not the sender please do nothing.
If you are the sender, please confirm, otherwise your original letter will
be deleted entirely."
- If MailScanner receive "User unknown" for the notice letter, it
deletes original letter immediately;
- If MailScanner does not receive confirmation, it (optionaly informs
recipient for the letter with quarantined attached file like
now) waits some days;
- If confirmation received MailScanner sends the original letter
optionaly with or without attachment;
- If timeout of some days expired and no confirmation received,
MailScanner deletes the letter.
Regards!
Valentin Laskov
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
--
Jerry Benton
Mailborder Systems
www.mailborder.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140227/18162d01/attachment.html
Steve Basford
2014-02-27 12:10:18 UTC
Permalink
Post by Valentin Laskov
Hi all,
Recently my mail servers receive many emails with .exe files attached.
These files are actually viruses but ClamAV still does not
recognize them.
Are you using the official signatures only on ClamAV or Third-Party ones
as well:

http://sanesecurity.com/usage/linux-scripts/
http://sanesecurity.com/foxhole-databases/

If you want to discuss, off-list...

Cheers,

Steve
Sanesecurity.com
Valentin Laskov
2014-02-27 13:27:31 UTC
Permalink
Hi Jerry, Hi Steve,

First of all, thank you for your answers!

Jerry, in this case I don't care for senders and yes, in my MailScanner.conf
Notify Senders Of Viruses = no
I can set
Notify Senders Of Blocked Filenames Or Filetypes = yes
to NO but this is not my aim. I would like to protect recipients of unnecessary letters.
MailScanner and Clamd work well and other files are detected as viruses.

Steve, I'm using the official ClamAV signatures only. I looked at the descriptions of Foxhole databases, but their action if I'm not
wrong, covers the operation of MailScanner or are not intended for new .exe viruses.

I attached a Bad Filename Detected report below.

Cheers,
Valentin

The following e-mails were found to have: Bad Filename Detected

Sender: brunchskt1 at gmail.com
IP Address: 71.59.80.26
Recipient: kkkkk at festa.bg
Subject: image Id 942349204-PicL7674 TYPE==MMS
MessageID: s1RDGcHS022468
Quarantine: /var/spool/MailScanner/quarantine/20140227/s1RDGcHS022468
Report: MailScanner: Executable DOS/Windows programs are dangerous in email (IMG000006371.exe)
No programs allowed (IMG000006371.exe)
Report: MailScanner: Executable DOS/Windows programs are dangerous in email (IMG000006371.exe)
No programs allowed (IMG000006371.exe)

Full headers are:

Return-Path: <g>
Received: from c-71-59-80-26.hsd1.nj.comcast.net (c-71-59-80-26.hsd1.nj.comcast.net [71.59.80.26])
by mail.festa.bg (8.14.1/8.14.1) with ESMTP id s1RDGcHS022468
for <kkkkk at festa.bg>; Thu, 27 Feb 2014 15:16:40 +0200
Received: from apache by leebenbbgnccfghb. with local (Exim 4.63)
(envelope-from <gearkff3 at yahoo.com>)
id 1EKF1Z-S649PO-22
for <kkkkk at festa.bg>; Thu, 27 Feb 2014 08:16:39 -0500
To: <kkkkk at festa.bg>
Subject: image Id 942349204-PicL7674 TYPE==MMS
Date: Thu, 27 Feb 2014 08:16:39 -0500
From: mms.service9105 at mms.Vodafone.co.uk
Message-ID: <07DB53C2B8DB8357FB60848BC4946124 at leebenbbgnccfghb.>
X-Priority: 3
X-Mailer: PHPMailer 5.1 (phpmailer.sourceforge.net)
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="------------01050100901040406020602"

Loading...