MS Doesn't completely block spam with faulty attachments

Julian Field MailScanner at ecs.soton.ac.uk
Thu Sep 1 15:34:16 IST 2011


He's probably switched on some "Notify Senders" options. Bad idea :-(

On 01/09/2011 12:32, Martin Hepworth wrote:
> what version of MS?
>
> I never inform the sender of junk as you end up with fake messages 
> sent out.
>
> -- 
> Martin Hepworth
> Oxford, UK
>
>
> On 1 September 2011 08:17, Joolee <mailscanner at joolee.nl 
> <mailto:mailscanner at joolee.nl>> wrote:
>
>     Hallo Everybody,
>
>     I've experienced a small flood of virus E-mails. These E-mails
>     (subj.: "ACH Payment *random number* Canceled") contain
>     attachments named like: "report_082011-65.pdf.exe"
>     They obviously get blocked by the "no executables" and "No double
>     file extensions" rules. The problem is that after blocking them,
>     an automated E-mail is send to the original recipient and the 
>     (faked) sender of the message, informing them of the blocked
>     attachment.
>
>     Had the E-mails been processed further, they would've probably hit
>     the virusscanner (not tested) or spamassassin (gives a score of 27
>     when tested) and the E-mail would've silently been discarded as a
>     virus / spam / phishing.
>
>     Is it possible to let the MailScanner continue it's processing
>     when hitting the file name rules and / or running the filename
>     rule at a later time?
>     --
>     MailScanner mailing list
>     mailscanner at lists.mailscanner.info
>     <mailto:mailscanner at lists.mailscanner.info>
>     http://lists.mailscanner.info/mailman/listinfo/mailscanner
>
>     Before posting, read http://wiki.mailscanner.info/posting
>
>     Support MailScanner development - buy the book off the website!
>
>
>
>
>
> Jules
>
> -- 
> Julian Field MEng CITP CEng
> www.MailScanner.info
>
> Buy the MailScanner book at www.MailScanner.info/store
> Need help customising MailScanner? Contact me!
>
> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654
> Follow me at twitter.com/JulesFM
>
> 'It's okay to live without all the answers' - Charlie Eppes, 2011
> 'All programs have a desire to be useful' - Tron, 1982

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.



More information about the MailScanner mailing list