What's Going on here?

Antony Stone Antony at SOFT-SOLUTIONS.CO.UK
Fri Aug 29 22:20:39 IST 2003


On Friday 29 August 2003 10:15 pm, Jason Balicki wrote:

> >I've seen several emails come through that look like they got
> >past Sophos,
> >but the filename alone caught it.  For the most part, Sophos says the
> >attachment is infected with Sobig.  Thoughts?
>
> [snip]
>
> I have seen this as well.  I just assumed that MailScanner
> rejected it before it passed the message to Sophos (and
> therefore, didn't need to -- it had already stripped the
> attachment.)  I could be wrong.

No, that doesn't explain why there's nothing reported by Sophos after the
"Virus and Content Scanning" message below:

> Aug 29 15:31:03 genesis MailScanner[8931]: Virus and Content Scanning:
> Starting
> Aug 29 15:31:05 genesis MailScanner[8931]: Filename Checks: Possible MS-Dos
> program shortcut attack (your_details.pif)
> Aug 29 15:31:05 genesis MailScanner[8931]: Filetype Checks: No executables
> (your_details.pif)

It should at least report it found a virus, so that MailScanner can decide
what to do about it.

Antony

--

The truth is rarely pure, and never simple.

 - Oscar Wilde



More information about the MailScanner mailing list