Blocking of Files with multiple extensions

Denis Beauchemin Denis.Beauchemin at USHERBROOKE.CA
Thu Jun 17 16:50:33 IST 2004


User Groups wrote:

>Hi All,
>
>Good Day...
>
>The conclusion we reached is mailscanner blocks only those attachments which
>have 3 or 4 alphabets in between 2 dots .
>
>Does this make sense ?
>
>Can it be rectified? Is this a known Issue ?
>
>Our /etc/MailScanner/filename.rules.conf has the following line in it.
>
>Deny all other double file extensions. This catches any hidden filenames.
>deny    \.[a-z][a-z0-9]{2,3}\s*\.[a-z0-9]{3}$   Found possible filename hiding
>        Attempt to hide real filename extension
>
>What if we remove / comment this line totally ? Are we putting our customers
>at a great risk ?
>
>  
>
This line has been commented out in my conf files for a long time now 
and I had no problems with it.

Of course I block all executables (exe, pif, bat, ...) in that same file.

Denis

-- 
   _
  °v°   Denis Beauchemin, analyste
 /(_)\  Université de Sherbrooke, S.T.I.
  ^ ^   T: 819.821.8000x2252 F: 819.821.8045

-------------------------- MailScanner list ----------------------
To leave, send    leave mailscanner    to jiscmail at jiscmail.ac.uk
Before posting, please see the Most Asked Questions at
http://www.mailscanner.biz/maq/     and the archives at
http://www.jiscmail.ac.uk/lists/mailscanner.html




More information about the MailScanner mailing list