Hi List;

I have noticed that I've had a couple instances of the Lentin.F virus getting
through qmail-scanner/fsav.

I did some digging through the log files and found that it seems like reformime
isn't properly putting the attachment back together.  The filename ends up .pif
or .bat and never gets scanned.  

=-=- Output of log =-=-

03/11/2002 13:26:46:24371: d_m: starting /usr/local/bin/reformime 
-x/var/spool/qmailscan/EOTnetworks.com103635520642324371/
</var/spool/qmailscan/working/new/EOTnetworks.com103635520642324371
[1036355207.36303]
03/11/2002 13:26:46:24371: d_m: finished /usr/local/bin/reformime 
-x/var/spool/qmailscan/EOTnetworks.com103635520642324371/ [1036355207.37951]
03/11/2002 13:26:46:24371: d_m: Checking all attachments to see if they're MS-TNEF
03/11/2002 13:26:46:24371: d_m: is
/var/spool/qmailscan/EOTnetworks.com103635520642324371/.pif is a TNEF file?: 256
[1036355207.38323]
03/11/2002 13:26:46:24371: d_m: is
/var/spool/qmailscan/EOTnetworks.com103635520642324371/1036355207.24375-0.EOTnetworks.com
is a TNEF file?: 256 [1036355207.38686]

And for a message that properly gets unpacked...

=-=- Output of log =-=-

03/11/2002 13:55:45:30657: d_m: starting /usr/local/bin/reformime 
-x/var/spool/qmailscan/EOTnetworks.com103635694542330657/
</var/spool/qmailscan/working/new/EOTnetworks.com103635694542330657
[1036356945.61038]
03/11/2002 13:55:45:30657: d_m: finished /usr/local/bin/reformime 
-x/var/spool/qmailscan/EOTnetworks.com103635694542330657/ [1036356945.6565]
03/11/2002 13:55:45:30657: d_m: Checking all attachments to see if they're MS-TNEF
03/11/2002 13:55:45:30657: d_m: is
/var/spool/qmailscan/EOTnetworks.com103635694542330657/goldfish.dat.scr is a
TNEF file?: 256 [1036356945.66033]
03/11/2002 13:55:45:30657: d_m: is
/var/spool/qmailscan/EOTnetworks.com103635694542330657/1036356945.30671-0.EOTnetworks.com
is a TNEF file?: 256 [1036356945.66405]

I am running qmail-scanner version 1.14 with reformime version 1.40

If there is any more information I should be providing, or if this should be
going to the maildrop mailing list, please let me know.  

Also, if this is just a problem with reformime, is there an alternative to it? 
I've noted over the past couple years that some people do not like this program
and have had problems with it.

Regards,

Tren

--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
- Tren Blackburn - Owner                mailto:tren@;eotnetworks.com  =
= EOT Networks                           http://www.eotnetworks.com  -
- Phone (403) 818-7658                           Fax (403) 269-2122  =
=             ** Infinite Solutions for a Finite World **            -
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
--
------------------------------------------------------------------------
DISCLAIMER:  This e-mail message is intended only for the named 
recipient(s) above and may contain information that is privileged, 
confidential and/or exempt from disclosure under applicable law. If you 
have received this message in error, or are not the named recipient(s), 
please immediately notify the sender and delete this e-mail message.
------------------------------------------------------------------------

--------------------------------------------------------
This message sent via EOT-Mail: http://www.eot-mail.com/


-------------------------------------------------------
This sf.net email is sponsored by: See the NEW Palm 
Tungsten T handheld. Power & Color in a compact size!
http://ads.sourceforge.net/cgi-bin/redirect.pl?palm0001en
_______________________________________________
Qmail-scanner-general mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to