Mailscanner / Sophos does not block viruses

Jerry Benton jerry.benton at mailborder.com
Thu Nov 7 12:39:47 GMT 2013


Check: Quarantine Infections in /etc/MailScanner/MailScanner.conf


On Thu, Nov 7, 2013 at 12:45 PM, <ci at holmco.de> wrote:

> Hello,
>
> we are running Mailscanner with Sophos Antivirus as virus scanner.
> So far it's working, but Mailscanner does not block the attachment.
> I made sure that sophos-wrapper is executed by Mailscanner. The
> resulting sophos command line scans and detects files in the spool
> directory and delivers exit status > 0.
>
> Mailscanner notices that the mail is infected. The admin gets
> information mail from Mailscanner:
>
> ------------------------------------------------------------------------
>  Subject: [SAV-LINUX] Threat detected during on-demand scan on <mailserver>
>  To: admin at domain.tld
>
> A threat was detected during an on-demand scan. Details follow:
> 3 files scanned.
> Number of infections detected: 1
> Number of infected files detected: 1
> /var/spool/MailScanner/incoming/10458/1VeN1P-0002nK-8i/neicar.txt is
> infected
> with EICAR-AV-Test.
> ------------------------------------------------------------------------
>
> The mail reaches the receiptient *with* eicar still attached.
>
> What's going wrong here?
>
>
> Greetings,
> --
> R. Cirksena <ci at holmco.de>
> --
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
>
> Before posting, read http://wiki.mailscanner.info/posting
>
> Support MailScanner development - buy the book off the website!
>



-- 

--
Jerry Benton
Mailborder Systems
www.mailborder.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20131107/d947a287/attachment.html 


More information about the MailScanner mailing list