File(name|type) rules - was hijacked: "Allow Script Tags" affects attachments?

Mark Sapiro mark at msapiro.net
Fri Feb 10 22:43:38 UTC 2017


On 02/10/2017 10:20 AM, Paul Scott wrote:
> Hello Mark,
> 
> This is what I get:
> 
> [root at mail log]# grep 'Feb  8 15:41:4.*MailScanner.14031' maillog
> Feb  8 15:41:46 mail MailScanner[14031]: Message v18NfGNg014804 from 216.205.24.106 (betty.tran at ioausa.com) to mp-eng.com is too big for spam checks (1572191 > 150000 bytes) 
> Feb  8 15:41:46 mail MailScanner[14031]: Spam Checks: Found 1 spam messages 
> Feb  8 15:41:48 mail MailScanner[14031]: Cleaned: Delivered 1 cleaned messages 
> Feb  8 15:41:48 mail MailScanner[14031]: Deleted 2 messages from processing-database 
> Feb  8 15:41:48 mail MailScanner[14031]: Logging message v18NfJdu014805 to SQL 
> Feb  8 15:41:48 mail MailScanner[14031]: Logging message v18NfGNg014804 to SQL



This is somewhat odd. I think the only log messages relating
specifically to this message are:

> Feb  8 15:41:46 mail MailScanner[14031]: Message v18NfGNg014804 from 216.205.24.106 (betty.tran at ioausa.com) to mp-eng.com is too big for spam checks (1572191 > 150000 bytes) 
> Feb  8 15:41:48 mail MailScanner[14031]: Cleaned: Delivered 1 cleaned messages 
> Feb  8 15:41:48 mail MailScanner[14031]: Logging message v18NfGNg014804 to SQL

The messages:

> Feb  8 15:41:46 mail MailScanner[14031]: Spam Checks: Found 1 spam messages 
> Feb  8 15:41:48 mail MailScanner[14031]: Logging message v18NfJdu014805 to SQL 

Appear to refer to a different message and the

> Feb  8 15:41:48 mail MailScanner[14031]: Deleted 2 messages from processing-database 

message refers to both of them.

I would expect to see additional log messages referring to the
"cleaning" of v18NfGNg014804.


> So, yes...the message was still delivered, along with the odd warning message, but the 7 attachments that she was sending were stripped and gone, and the message "Too many attachments" was in the warning message.
> 
> And can you please let me know where this " EdenUSAInc-Attachment-Warning.txt" file is supposed to be, if it is supposed to be a part of the system, or?  I know where the "EdenUSAInc" is coming from.  It is as defined in the mailscanner.conf file here:


I think you are seeing the EdenUSAInc-Attachment-Warning.txt file. It is
what you refer to as the "odd warning message". Your MUA displays it
inline, but it is probably an attached MIME part with name
EdenUSAInc-Attachment-Warning.txt. It comes from the 'Deleted Virus
Message Report' setting in your MailScanner configuration.

-- 
Mark Sapiro <mark at msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan


More information about the MailScanner mailing list