Mail Server Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationMail Server Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 27th, 2004, 08:40 AM
jsbruns jsbruns is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: Sep 2003
Location: Washington, D.C.
Posts: 625 jsbruns User rank is Private First Class (20 - 50 Reputation Level)jsbruns User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 2 Days 16 h 47 m 55 sec
Reputation Power: 6
Sendmail & How to reject mail with executable attachments

Hello-
Recently I've been getting a lot of mail with attatchments "test.scr" and "appl.exe", a few of which have been identified as viruses. I'm wondering if there is any way to tell sendmail to reject any email containing an executable attatchment.

The following was returned from another machine, as my outlook has apparently delivered to my address book.

-->

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

adam@thewatchdesk.com
This message has been rejected because it has
a potentially executable attachment "test.scr"
This form of attachment has been used by
recent viruses or other malware.
If you meant to send this file then please
package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------

Return-path: <jbruns@webdevsol.com>
Received: from [24.53.186.180] (helo=webdevsol.com)
by fhh.firehousehosting.com with esmtp (Exim 4.24)
id 1AlU4p-0004PI-BQ
for adam@thewatchdesk.com; Tue, 27 Jan 2004 09:20:27 -0500
From: jbruns@webdevsol.com
To: adam@thewatchdesk.com
Subject: Error
Date: Tue, 27 Jan 2004 09:18:59 -0500
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0006_70F4F082.659BE0AC"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <E1AlU4p-0004PI-BQ@fhh.firehousehosting.com>

This is a multi-part message in MIME format.

------=_NextPart_000_0006_70F4F082.659BE0AC
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

The message contains Unicode characters and has been sent as a binary attachment.


------=_NextPart_000_0006_70F4F082.659BE0AC
Content-Type: application/octet-stream;
name="test.scr"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="test.scr"

TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAqAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAUEUA
AEwBAwAAAAAAAAAAAAAAAADgAA8BCwEHAABQAAAAEAAAAGAAAGC+AAAAcAAAAMAAAAAASgAAEAAA
AAIAAAQAAAAAAAAABAAAAAAAAAAA0AAAABAAAAAAAAACAAAAAAAQAAAQAAAAABAAABAAAAAAAAAQ
AAAAAAAAAAAAAADowQAAMAEAAADAAADoAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

Reply With Quote
  #2  
Old January 28th, 2004, 03:20 PM
alexgreg's Avatar
alexgreg alexgreg is offline
Full Access
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Jun 2000
Location: London, UK
Posts: 2,019 alexgreg User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 sec
Reputation Power: 11
I've no idea how to do it with sendmail, but it's trivial to do with qmail:
http://www.qmail.org/qmail-smtpd-viruscan-1.3.patch
__________________
Alex
(http://www.alex-greg.com)

Reply With Quote
  #3  
Old February 4th, 2004, 03:46 PM
WorldBuilder's Avatar
WorldBuilder WorldBuilder is offline
Big Daddy
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Sep 2003
Location: Boston
Posts: 1,470 WorldBuilder User rank is Sergeant (500 - 2000 Reputation Level)WorldBuilder User rank is Sergeant (500 - 2000 Reputation Level)WorldBuilder User rank is Sergeant (500 - 2000 Reputation Level)WorldBuilder User rank is Sergeant (500 - 2000 Reputation Level)WorldBuilder User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 4 h 53 m 8 sec
Reputation Power: 21
Send a message via AIM to WorldBuilder
Look into procmail for mail filtering.

Chris
__________________
Pop, pop, fizz, fizz, oh what a relief it is!

Reply With Quote
  #4  
Old February 13th, 2004, 08:31 PM
dumorian dumorian is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 9 dumorian User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
A cure

I've installed the E-mail Sanitizer. It's an easy setup and the attachments are completely user configurable. Also, you can do a bit of AV filtering if you like.

The program can be found on

http://www.impsec.org/email-tools/p...l-security.html

It runs through an easy and basic procmail system.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationMail Server Help > Sendmail & How to reject mail with executable attachments


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT