Fragmented messages?

Julian Field mailscanner at ecs.soton.ac.uk
Wed Nov 5 16:07:59 GMT 2003


Take a look at MailScanner.conf and you will see this:

# Do you want to allow partial messages, which only contain a fraction of
# the attachments, not the whole thing? There is absolutely no way to
# scan these "partial messages" properly for viruses, as MailScanner never
# sees all of the attachment at the same time. Enabling this option can
# allow viruses through. You have been warned.

In addition to this, MailScanner cannot attempt to collect together all the
parts of a message and then scan the whole thing, as this would create a
vast Denial of Service attack possibility. Imagine what happens when
someone mails you a 10 MByte file which claims to be part 1 of 1,000,000.
And then he sends you a million different messages of the same size, all of
which claim to be part 1. Say goodnight to your memory, disk, CPU, service....

At 15:57 05/11/2003, you wrote:
>I have a client that sent me this MailScanner report and is wondering why
>the email isn't getting through:
>
>
>Report: MailScanner: Fragmented messages cannot be scanned and are removed
>
>I'm not familiar w/what makes a "Fragmented message", so if someone can
>explain that to me so I can give an explanation to my client, that'd be great!
>
>thx
>
>k

--
Julian Field
www.MailScanner.info
MailScanner thanks transtec Computers for their support

PGP footprint: EE81 D763 3DB0 0BFD E1DC  7222 11F6 5947 1415 B654



More information about the MailScanner mailing list