> On Thu, Nov 14, 2002 at 11:13:53AM +0800, Antonio Rabena wrote: > > CertaintyTech wrote: > > >>FWIW- using above - clamav picks it up: > > > sophie does not! > > trophie does. > > Indeed - it just goes to show there are differences between vendors... > > ...that's why I run two scanners... > > -- > Cheers > > Jason Haar
Has anyone looked at the "-r" option on reformime? It may help with this. The man page says: -r Rewrite message, adding or standardizing RFC 2045 MIME headers. I just ran it on the W32/Bride message and it strips out the virus because it is not standard MIME and the message that gets thru is no longer dangerous. I also tried it on a normal message and it does not appear to alter it. Possible Q-S could run the message thru "reformime -r" before attempting to unpack attachments? That way if the message has broken MIME this will correct it before the "reformime -x" is run on the message. Does this make sense? Maybe run "reformime -r < $scandir/$wmaildir/new/$file_id | reformime -x" Not sure what the exact commandline would be. Any input from others? Ed. ------------------------------------------------------- This sf.net email is sponsored by: To learn the basics of securing your web site with SSL, click here to get a FREE TRIAL of a Thawte Server Certificate: http://www.gothawte.com/rd524.html _______________________________________________ Qmail-scanner-general mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general