Deep test virus scan rule that doesnt work

Nicola Piazzi Nicola.Piazzi at gruppocomet.it
Tue Jan 12 08:54:42 UTC 2021



[In the MailScanner.conf i put Virus Scanning directive so it use a fixed path file so i am sure that is not wrong]
vi /etc/MailScanner/MailScanner.conf
Virus Scanning = /mio/mio.rule

[In the file i put only negate scan by default]
vi /mio/mio.rule
FromOrTo: Default No

[chmod dir and file to ensure access]
chmod 777 /mio;chmod 777 /mio/mio.rule

[restart mailscanner]
systemctl stop mailscanner;sleep 2;systemctl start mailscanner

[but clamd still scan incoming mail]
# tail -f /var/log/clamd.scan
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nimage003.png: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nimage002.png: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nimage006.jpg: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nimage004.png: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nimage005.png: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY.header: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nmsg-9751-4.txt: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nmsg-9751-6.txt: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY/nmsg-9751-5.html: OK
/var/spool/MailScanner/incoming/9751/4DFPPX5htrzlfcMY.message: OK
/var/spool/MailScanner/incoming/9751/4DFPPb6C85zlfdyp/nmsg-9751-7.txt: OK


[The only way to stop clamd scan email is to put "Virus Scanning = No" in MailScanner.conf, Using a rule is the same of "Virus Scanning = Yes", it doesnt watch rule contants]












-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.mailscanner.info/pipermail/mailscanner/attachments/20210112/a732b595/attachment.html>


More information about the MailScanner mailing list