MailScanner, winmail.dat, docx and anitwordy

The Doctor doctor at doctor.nl2k.ab.ca
Mon Nov 12 21:28:23 GMT 2012


On Mon, Nov 12, 2012 at 09:09:09PM +0000, Martin Hepworth wrote:
> What version of mailscanner are you using
>

4.84.5-2
 
> And more importantly why are you still having to cope with winmail.dat
> which is outdated insecure and still a bad idea :-)
> 

Because people using Outhouse Excess and Windopws Mail vista Onwards
still uses that.


Also docx xlsx pptx are not accounted for.

> Martin
> 
> On Monday, 12 November 2012, The Doctor wrote:
> 
> > All right.
> >
> > Are there any updates for MilScanner so that modern
> > winmail.dat files can be read?
> >
> > --
> > Member - Liberal International  This is doctor at nl2k.ab.ca <javascript:;>Ici
> > doctor at nl2k.ab.ca <javascript:;>
> > God,Queen and country!Never Satan President Republic!Beware AntiChrist
> > rising!
> > http://www.fullyfollow.me/rootnl2k  Lest We Forget 11 NOv 2012
> >
> > --
> > This message has been scanned for viruses and
> > dangerous content by MailScanner, and is
> > believed to be clean.
> >
> > --
> > MailScanner mailing list
> > mailscanner at lists.mailscanner.info <javascript:;>
> > http://lists.mailscanner.info/mailman/listinfo/mailscanner
> >
> > Before posting, read http://wiki.mailscanner.info/posting
> >
> > Support MailScanner development - buy the book off the website!
> >
> 
> 
> -- 
> -- 
> Martin Hepworth, CISSP
> Oxford, UK

> -- 
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
> 
> Before posting, read http://wiki.mailscanner.info/posting
> 
> Support MailScanner development - buy the book off the website! 

> This message has been 'sanitized'.  This means that potentially
> dangerous content has been rewritten or removed.  The following
> log describes which actions were taken.
> 
> Sanitizer (start="1352754823"):
>   Part (pos="3350"):
>     Part (pos="107"):
>       SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):
>         Match (names="unnamed.txt", rule="2"):
>           Enforced policy: accept
> 
>     Part (pos="1223"):
>       SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):
>         Match (names="unnamed.html, filetype.html", rule="2"):
>           Enforced policy: accept
> 
>       Note: Styles and layers give attackers many tools to fool the
>       user and common browsers interpret Javascript code found
>       within style definitions.
>       
>       Rewrote HTML tag: >>_div_<<
>                     as: >>_p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_/div_<<
>                     as: >>_/p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_div_<<
>                     as: >>_p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_/div_<<
>                     as: >>_/p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_div_<<
>                     as: >>_p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_/div_<<
>                     as: >>_/p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_div_<<
>                     as: >>_p__DEFANGED_div_<<
>       Rewrote HTML tag: >>_span_<<
>                     as: >>_DEFANGED_span_<<
>       Rewrote HTML tag: >>_/span_<<
>                     as: >>_/DEFANGED_span_<<
>       Rewrote HTML tag: >>_blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"_<<
>                     as: >>_blockquote class="gmail_quote" DEFANGED_style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"_<<
>       Rewrote HTML tag: >>_a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;doctor at nl2k.ab.ca&#39;)"_<<
>                     as: >>_a DEFANGED_href="javascript:;" DEFANGED_onclick="_e(event, &#39;cvml&#39;, &#39;doctor at nl2k.ab.ca&#39;)"_<<
>       Rewrote HTML tag: >>_a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;doctor at nl2k.ab.ca&#39;)"_<<
>                     as: >>_a DEFANGED_href="javascript:;" DEFANGED_onclick="_e(event, &#39;cvml&#39;, &#39;doctor at nl2k.ab.ca&#39;)"_<<
>       Rewrote HTML tag: >>_a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;mailscanner at lists.mailscanner.info&#39;)"_<<
>                     as: >>_a DEFANGED_href="javascript:;" DEFANGED_onclick="_e(event, &#39;cvml&#39;, &#39;mailscanner at lists.mailscanner.info&#39;)"_<<
>       Rewrote HTML tag: >>_/div_<<
>                     as: >>_/p__DEFANGED_div_<<
> 
>   Part (pos="6549"):
>     SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):
>       Match (names="unnamed.txt", rule="2"):
>         Enforced policy: accept
> 
>   Total modifications so far: 17
> 
> 
> Anomy 0.0.0 : Sanitizer.pm
> $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $


-- 
Member - Liberal International	This is doctor at nl2k.ab.ca Ici doctor at nl2k.ab.ca
God,Queen and country!Never Satan President Republic!Beware AntiChrist rising! 
http://www.fullyfollow.me/rootnl2k  Lest We Forget 11 NOv 2012 


More information about the MailScanner mailing list