Portál AbcLinuxu, 25. dubna 2024 11:45


Dotaz: Clamav - zahazuje EXE

12.6.2009 08:59 Tomasekkk
Clamav - zahazuje EXE
Přečteno: 358×
Odpovědět | Admin

Zdravím Vás, rád bych se zeptal, zda-li mi může někdo z vás poradit jak v clamavd nastavit, aby příchozí pošta  nezahazovala emaily kde je v příloze EXE nebo ZIP soubor? Používám amavisd-new + clamavd + postfix, dekuji za pripadnou radu kde problem hledat. Zpět vždy odesílateli z mého serveru přijde e-mail:

BANNED CONTENTS ALERT

Our content checker found
    banned name: multipart/mixed |
      application/x-dosexec,.exe,.exe-ms,=?us-ascii?Q?ccsetup220=2Eexe?=,ccsetup220.exe

in email presumably from you odesilatel

 

 to the following recipient:
-> prijemce

Our internal reference code for your message is 05192-04/GwBk4BAnDW35

First upstream SMTP client IP address: [77.75.76.26] mxh.seznam.cz
According to a 'Received:' trace, the message originated at: [XX.48.XX.99],
  firewall.XXXX.cz firewall.XXXX.cz [XX.48.XX.99]

Return-Path: XXX

 

Message-ID: XXXX
Subject: =?us-ascii?Q?exe=20soubor?=

Delivery of the email was stopped!

The message has been blocked because it contains a component
(as a MIME part or nested within) with declared name
or MIME type or contents type violating our access policy.

To transfer contents that may be considered risky or unwanted
by site policies, or simply too large for mailing, please consider
publishing your content on the web, and only sending an URL of the
document to the recipient.


Depending on the recipient and sender site policies, with a little
effort it might still be possible to send any contents (including
viruses) using one of the following methods:

- encrypted using pgp, gpg or other encryption methods;

- wrapped in a password-protected or scrambled container or archive
  (e.g.: zip -e, arj -g, arc g, rar -p, or other methods)

Note that if the contents is not intended to be secret, the
encryption key or password may be included in the same message
for recipient's convenience.

We are sorry for inconvenience if the contents was not malicious.

The purpose of these restrictions is to cut the most common propagation
methods used by viruses and other malware. These often exploit automatic
mechanisms and security holes in more popular mail readers (Microsoft
mail readers and browsers are a common target). By requiring an explicit
and decisive action from the recipient to decode mail, the danger of
automatic malware propagation is largely reduced.

Nástroje: Začni sledovat (0) ?Zašle upozornění na váš email při vložení nového komentáře.

Odpovědi

12.6.2009 09:26 tomk
Rozbalit Rozbalit vše Re: Clamav - zahazuje EXE
Odpovědět | | Sbalit | Link | Blokovat | Admin

Zdravim, toto chovani nezpusobuje clamav, ale amavisd-new. V jeho konfiguracnim souboru si muzete upravit seznam vyrazu, podle kterych zakazuje urcita jmena souboru v priloze.

Tomas

 

Založit nové vláknoNahoru

Tiskni Sdílej: Linkuj Jaggni to Vybrali.sme.sk Google Del.icio.us Facebook

ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.