Development info?
Alex Broens
ms-list at alexb.ch
Sun Aug 24 22:07:45 IST 2008
On 8/24/2008 9:47 PM, Hugo van der Kooij wrote:
>> SpamAssassin Rule Actions =
>> TRAP_LINK_EXEC=>store-/var/spool/MailScanner/evidence
>
> That will store the URL but by the time I can look at that URL to fetch
> the file the infected system might be cleaned out allready. So I need to
> automate this a bit further.
Seems to me you want to do too much within MailScanner...
I'd forward the msg with the malware URI to a separate account, process
that account with procmail/ripmime/snersoft's "URI" tool/GET and bingo
you have the malware to do whatever you want with it and you're very
flexible.
Alex
More information about the MailScanner
mailing list