Virus reporting

Julian Field mailscanner at ecs.soton.ac.uk
Fri Nov 28 11:22:26 GMT 2003


At 10:56 28/11/2003, you wrote:
>After being hammered yesterday by an infected external host trying to send
>Swen to dozens of users here we temporarily changed "Still Deliver Silent
>Viruses" to no.

If you are using sendmail, check out the new "IPBlock" code in
CustomConfig.pm when I release it all this weekend. This will rate-limit
various systems and/or networks to a configurable number of messages per
hour, so you will no longer be swamped by the occasional infected host,
either internal or external.

>The MailScanner.conf says this can be a ruleset.  Is it possible to not
>deliver based on virus names, and if so, what would such a ruleset look
>like?  The FAQ needs updating on this issue.

Virus:  some-virus-name yes
Virus:  other-virus-name        no
FromOrTo: default               yes



>Cheers,
>
>Phil
>
>---------------------------------------------
>Phil Randal
>Network Engineer
>Herefordshire Council
>Hereford, UK

--
Julian Field
www.MailScanner.info
MailScanner thanks transtec Computers for their support

PGP footprint: EE81 D763 3DB0 0BFD E1DC  7222 11F6 5947 1415 B654



More information about the MailScanner mailing list