Virus reporting
    Julian Field 
    mailscanner at ecs.soton.ac.uk
       
    Fri Nov 28 11:22:26 GMT 2003
    
    
  
At 10:56 28/11/2003, you wrote:
>After being hammered yesterday by an infected external host trying to send
>Swen to dozens of users here we temporarily changed "Still Deliver Silent
>Viruses" to no.
If you are using sendmail, check out the new "IPBlock" code in
CustomConfig.pm when I release it all this weekend. This will rate-limit
various systems and/or networks to a configurable number of messages per
hour, so you will no longer be swamped by the occasional infected host,
either internal or external.
>The MailScanner.conf says this can be a ruleset.  Is it possible to not
>deliver based on virus names, and if so, what would such a ruleset look
>like?  The FAQ needs updating on this issue.
Virus:  some-virus-name yes
Virus:  other-virus-name        no
FromOrTo: default               yes
>Cheers,
>
>Phil
>
>---------------------------------------------
>Phil Randal
>Network Engineer
>Herefordshire Council
>Hereford, UK
--
Julian Field
www.MailScanner.info
MailScanner thanks transtec Computers for their support
PGP footprint: EE81 D763 3DB0 0BFD E1DC  7222 11F6 5947 1415 B654
    
    
More information about the MailScanner
mailing list