On Thu, 2004-02-12 at 06:18, Doug Monroe wrote: > just re-read my post... :( > duh...that's b/c the "headers" of the -bounced- msgs were no longer > "headers", they became part of the -body-, hence neither perlscanner nor > clamav "saw" anything to act on...oy...sorry for interuption
Man - you had me scared for a moment then. My "skip virus scan if TEXT" code caused me many a sleepless night. I am still very worried that some "corrupted e-mail that Outlook still understands" virus will be released that Qmail-Scanner misinterprets as TEXT - but so far it hasn't happened. It is true that IF a bounce of a virus-infected e-mail occurs, and the MTA that bounced it *doesn't* attach the original message as an attachment, and instead just appends the raw e-mail to the bottom of the bounce (Qmail does this), THEN Qmail-Scanner will treat it as a TEXT e-mail and won't scan it. However, I haven't seen this as a problem as: a> reformime wouldn't be able to detach the original e-mail either b> some virus scanners probably won't find it for the same reason c> MUAs won't see the virus anyway - they see raw BASE64 encoding - as it wasn't in a MIME mail message So unless the end-user edits the bounce message, cut-n-pastes the original bounce out into an *.eml file, then double-clicks on it - they are never going to get infected. Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 ------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click _______________________________________________ Qmail-scanner-general mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general
