Blocking emails with dangerous attachments

Randal, Phil prandal at herefordshire.gov.uk
Tue Apr 5 11:01:21 IST 2011


Easiest way is to use MimeHeader SA plugin, and create rules to detect attachment names like UPS.ZIP (and all the variants you see) and score them highly.

Phil

-- 
Phil Randal | Infrastructure Engineer 
NHS Herefordshire & Herefordshire Council  | Deputy Chief Executive's Office | I.C.T. Services Division 
Thorn Office Centre, Rotherwas, Hereford, HR2 6JT 
Tel: 01432 260160

-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Richard Coombe
Sent: 05 April 2011 10:45
To: 'mailscanner at lists.mailscanner.info'
Subject: Blocking emails with dangerous attachments

Hi,

We're blocking all incoming exe attachments. However we're getting some spam/virus email with exe attachments, ("Your DHL / UPS package is ready" type stuff). The exe gets removed and then the rest of the message is delivered with an attachment warning report. This is annoying my end users as they're not interested in the email in any way.

Is there a config setting to quarantine emails that have had their attachments stripped?

I can only find 'Deliver Cleaned Messages' in MailScanner.conf. However I also have emails from other legitimate mailing lists that have URLs in them which get 'disarmed' and I _do_ want to deliver these message. So I don't think I can change this to 'no', I think I need a more fine grained approach.

Am using Mailscanner with spamassassin and clamav.

Cheers,
Richard
IT Manager, Taff Housing Association







This message is private and confidential. If you have received this message in error, please notify us and remove it from your system.
Please consider the environment before printing this email.

Any views or other information in this message which do not relate to our business are not authorised by us, nor does this message form part of any contract unless so stated.

Taff Housing Association - www.taffhousing.co.uk - A Charitable Housing Association registered under the Industrial and Provident Societies Acts 1965 No. 21408R. Registered by The National Assembly for Wales No. L009. Registered address: Alexandra House, 307-315 Cowbridge Road East, Cardiff CF5 1JD. VAT Registration Number: 869 8405 65.
-- 
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 
Any opinion expressed in this e-mail or any attached files are those of the individual and not necessarily those of Herefordshire Council.
You should be aware that Herefordshire Council monitors its email service.
This e-mail and any attached files are confidential and intended solely for the use of the addressee. This communication may contain material protected by law from being passed on. If you are not the intended recipient and have received this e-mail in error, you are advised that any use, dissemination, forwarding, printing or copying of this e-mail is strictly prohibited. If you have received this e-mail in error please contact the sender immediately and destroy all copies of it.


More information about the MailScanner mailing list