What's Going on here?
Antony Stone
Antony at SOFT-SOLUTIONS.CO.UK
Fri Aug 29 22:20:39 IST 2003
On Friday 29 August 2003 10:15 pm, Jason Balicki wrote:
> >I've seen several emails come through that look like they got
> >past Sophos,
> >but the filename alone caught it. For the most part, Sophos says the
> >attachment is infected with Sobig. Thoughts?
>
> [snip]
>
> I have seen this as well. I just assumed that MailScanner
> rejected it before it passed the message to Sophos (and
> therefore, didn't need to -- it had already stripped the
> attachment.) I could be wrong.
No, that doesn't explain why there's nothing reported by Sophos after the
"Virus and Content Scanning" message below:
> Aug 29 15:31:03 genesis MailScanner[8931]: Virus and Content Scanning:
> Starting
> Aug 29 15:31:05 genesis MailScanner[8931]: Filename Checks: Possible MS-Dos
> program shortcut attack (your_details.pif)
> Aug 29 15:31:05 genesis MailScanner[8931]: Filetype Checks: No executables
> (your_details.pif)
It should at least report it found a virus, so that MailScanner can decide
what to do about it.
Antony
--
The truth is rarely pure, and never simple.
- Oscar Wilde
More information about the MailScanner
mailing list