Development info?

Alex Broens ms-list at alexb.ch
Sun Aug 24 22:07:45 IST 2008


On 8/24/2008 9:47 PM, Hugo van der Kooij wrote:
>> SpamAssassin Rule Actions =
>> TRAP_LINK_EXEC=>store-/var/spool/MailScanner/evidence
> 
> That will store the URL but by the time I can look at that URL to fetch
> the file the infected system might be cleaned out allready. So I need to
> automate this a bit further.

Seems to me you want to do too much within MailScanner...

I'd forward the msg with the malware URI to a separate account, process 
that account with procmail/ripmime/snersoft's "URI" tool/GET and bingo 
you have the malware to do whatever you want with it and you're very 
flexible.

Alex



More information about the MailScanner mailing list