ANNOUNCE: Beta 4.29.1 released

Randal, Phil prandal at HEREFORDSHIRE.GOV.UK
Tue Mar 16 13:51:47 GMT 2004


This is the culprit:

SweepContent.pm:          MailScanner::Config::LanguageValue($message,
'foundscript') . "\n";

and the solution is to add something like the following to
/etc/MailScanner/reports/en/languages.conf:

FoundScript = Found dangerous Script tag in HTML Message

Cheers,

Phil

---------------------------------------------
Phil Randal
Network Engineer
Herefordshire Council
Hereford, UK

> -----Original Message-----
> From: MailScanner mailing list [mailto:MAILSCANNER at JISCMAIL.AC.UK]On
> Behalf Of Martin Hepworth
> Sent: 16 March 2004 13:01
> To: MAILSCANNER at JISCMAIL.AC.UK
> Subject: Re: ANNOUNCE: Beta 4.29.1 released
>
>
> Julian
>
> installed 4.29.1
>
>
> just had this in the error log..
>
>
> Mar 16 12:58:20 soloman MailScanner[93653]: Content Checks: Detected
> HTML-specific exploits in 1B3E1O-000O5y-Dj
> Mar 16 12:58:20 soloman MailScanner[93653]: Looked up unknown string
> foundscript in language translation file
> /opt/MailScanner/etc/reports/en/languages.conf
> Mar 16 12:58:20 soloman MailScanner[93653]: Content Checks: Detected
> HTML-specific exploits in 1B3E1Z-000O5y-Lt
>
>
>
> --
> Martin Hepworth
> Snr Systems Administrator
> Solid State Logic
> Tel: +44 (0)1865 842300
>
>
> Julian Field wrote:
> > I have just released 4.29.1.
> >
> > The ChangeLog for this release is at the bottom of this message.
> >
> > Problems that are still outstanding are:
> >         - Postfix version 2.1 support
> >         - possible Postfix header doubling
> >         - Spam and MCP actions both as "deliver" causes deletion
> >
> > I will hopefully get onto those in the next few days.
> >
> > 16/3/2004 New in Version 4.29.1
> > ===============================
> > * New Features and Improvements *
> > - More robust MIME decoding, should catch postmaster
> bounces a lot better
> >   when they include the entire message with broken MIME headers.
> > - Clam -wrapper script adds /usr/ucb to end of $PATH for
> Solaris users.
> > - Moved cron job maximum update delay to
> /etc/sysconfig/MailScanner so it
> >   is preserved across upgrades.
> > - <Script> tags in HTML message bodies can now be filtered
> out or disarmed,
> >   just like what can be done already with <Form> tags and similar.
> >
> > * Fixes *
> > - When not checking archives at all, they are now passed
> through correctly.
> > - Max Archive Depth should have been settable per-message.
> > - F-Prot output parser re-fixed so that it lets through
> password-encrypted
> >   archives as it should. Don't know what I was thinking
> when I blocked them
> >   here :-(
> > - Various waiting speedups by JJH.
> > - More speedups by me :-)
> > --
> > Julian Field
> > www.MailScanner.info
> > MailScanner thanks transtec Computers for their support
> >
> > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654
>
> **********************************************************************
>
> This email and any files transmitted with it are confidential and
> intended solely for the use of the individual or entity to whom they
> are addressed. If you have received this email in error please notify
> the system manager.
>
> This footnote confirms that this email message has been swept
> for the presence of computer viruses and is believed to be clean.
>
> **********************************************************************
>



More information about the MailScanner mailing list