On Thu, 2004-02-12 at 06:18, Doug Monroe wrote:
> just re-read my post... :(
> duh...that's b/c the "headers" of the -bounced- msgs were no longer 
> "headers", they became part of the -body-, hence neither perlscanner nor 
> clamav "saw" anything to act on...oy...sorry for interuption

Man - you had me scared for a moment then. My "skip virus scan if TEXT"
code caused me many a sleepless night. I am still very worried that some
"corrupted e-mail that Outlook still understands" virus will be released
that Qmail-Scanner misinterprets as TEXT - but so far it hasn't
happened.

It is true that IF a bounce of a virus-infected e-mail occurs, and the
MTA that bounced it *doesn't* attach the original message as an
attachment, and instead just appends the raw e-mail to the bottom of the
bounce (Qmail does this), THEN Qmail-Scanner will treat it as a TEXT
e-mail and won't scan it. However, I haven't seen this as a problem as:

a> reformime wouldn't be able to detach the original e-mail either
b> some virus scanners probably won't find it for the same reason
c> MUAs won't see the virus anyway - they see raw BASE64 encoding - 
   as it wasn't in a MIME mail message

So unless the end-user edits the bounce message, cut-n-pastes the
original bounce out into an *.eml file, then double-clicks on it - they
are never going to get infected.


Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1




-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Qmail-scanner-general mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to