Hi all,
I have a RH9 with qmail installed and working. I
installed qmail-scanner 1.16 and sophos antivirus, all seems to work, except
that any message is stopped.
Im working with virtual domains...maybe here is the
problem...
Any idea??
This is one example of the qmail-quee.log generated
by test_installation script:
30/06/2003 10:21:49:2655: +++ starting debugging
for process 2655 by uid=0 at 30/06/2003 10:21:49
30/06/2003 10:21:49:2655: setting UID to EUID so subprocesses can access files generated by this script 30/06/2003 10:21:49:2655: program name is qmail-scanner-queue.pl, version 1.16 30/06/2003 10:21:49:2655: incoming pipe connection from via local process 2655 30/06/2003 10:21:49:2655: w_c: mkdir /var/spool/qmailscan/linux.es10569613094262655 30/06/2003 10:21:49:2655: w_c: start dumping incoming msg into /var/spool/qmailscan/working/tmp/linux.es10569613094262655 [1056961309.19$ 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: illegal breakage found in header name - potential virus 30/06/2003 10:21:49:2655: w_c: rename new msg from /var/spool/qmailscan/working/tmp/linux.es10569613094262655 to /var/spool/qmailscan/wo$ 30/06/2003 10:21:49:2655: d_m: starting /usr/local/bin/reformime -x/var/spool/qmailscan/linux.es10569613094262655/ </var/spool/qmailsca$ 30/06/2003 10:21:49:2655: d_m: finished /usr/local/bin/reformime -x/var/spool/qmailscan/linux.es10569613094262655/ [1056961309.23068] 30/06/2003 10:21:49:2655: d_m: Checking all attachments to see if they're MS-TNEF 30/06/2003 10:21:49:2655: d_m: is /var/spool/qmailscan/linux.es10569613094262655/Eicar.com is a TNEF file?: 256 [1056961309.24348] 30/06/2003 10:21:49:2655: d_m: Manually unpack any zip files as some virus scanners don't do zip under Unix! 30/06/2003 10:21:49:2655: d_m: unpacking message took 0.041842 seconds 30/06/2003 10:21:49:2655: unsetting QMAILQUEUE env var 30/06/2003 10:21:49:2655: g_e_h: return-path is "", recips is postmaster@fakeadress.com 30/06/2003 10:21:49:2655: from=,subj=, x-qmail-scanner-message-id= via local process 2655 30/06/2003 10:21:49:2655: ini_sc: start scanning 30/06/2003 10:21:49:2655: p_s: starting scan of directory "/var/spool/qmailscan/linux.es10569613094262655"... 30/06/2003 10:21:49:2655: p_s: '81:ILOVEYOU' = 'Virus-subject' = 'Love Letter Virus/Trojan' 30/06/2003 10:21:49:2655: p_s: type is a header! 30/06/2003 10:21:49:2655: p_s: checking for objects containing subject: ILOVEYOU .
.
.
30/06/2003 10:21:49:2655: ini_sc: recursively scan
the directory /var/spool/qmailscan/linux.es10569613094262655/
30/06/2003 10:21:49:2655: scanloop: starting scan of directory "/var/spool/qmailscan/linux.es10569613094262655"... 30/06/2003 10:21:49:2655: sweep: starting scan of directory "/var/spool/qmailscan/linux.es10569613094262655"... 30/06/2003 10:21:49:2655: run /usr/local/bin/sweep -f -all -eec -sc -nc -ss -nb -archive /var/spool/qmailscan/linux.es1056961309426265$ 30/06/2003 10:21:49:2655: --output of sophos sweep was: -- 30/06/2003 10:21:49:2655: sweep: finished scan of dir "/var/spool/qmailscan/linux.sirt.es10569613094262655" in 2.658694 secs 30/06/2003 10:21:49:2655: scanloop: finished scan of "/var/spool/qmailscan/linux.sirt.es10569613094262655"... 30/06/2003 10:21:49:2655: ini_sc: scanning message took 2.674565 seconds 30/06/2003 10:21:49:2655: q_r: fork off child into /var/qmail/bin/qmail-queue... 30/06/2003 10:21:49:2655: qmail-scanner[2655]: Clear: 2.735976 935 <> [EMAIL PROTECTED] <> <> <> 30/06/2003 10:21:49:2655: cleanup: /bin/rm -rf /var/spool/qmailscan/linux.es10569613094262655/ /var/spool/qmailscan/working/new/linux.$ 30/06/2003 10:21:52:2655: all finished. Total of 2.825985 secs |