> On Thu, Nov 14, 2002 at 11:13:53AM +0800, Antonio Rabena wrote:
> > CertaintyTech wrote:
> > >>FWIW- using above - clamav picks it up:
> > > sophie does not!
> > trophie does.
> 
> Indeed - it just goes to show there are differences between vendors...
> 
> ...that's why I run two scanners...
> 
> -- 
> Cheers
> 
> Jason Haar


Has anyone looked at the "-r" option on reformime?  It may help with
this.  The man page says:

     -r   Rewrite message, adding or standardizing RFC 2045  MIME
          headers.

I just ran it on the W32/Bride message and it strips out the virus
because it is not standard MIME and the message that gets thru is no
longer dangerous.  I also tried it on a normal message and it does not
appear to alter it. Possible Q-S could run the message thru "reformime
-r" before attempting to unpack attachments?  That way if the message
has broken MIME this will correct it before the "reformime -x" is run on
the message.  Does this make sense?  Maybe run "reformime -r <
$scandir/$wmaildir/new/$file_id | reformime -x"  Not sure what the exact
commandline would be. Any input from others?

Ed.




-------------------------------------------------------
This sf.net email is sponsored by: To learn the basics of securing 
your web site with SSL, click here to get a FREE TRIAL of a Thawte 
Server Certificate: http://www.gothawte.com/rd524.html
_______________________________________________
Qmail-scanner-general mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to