Re: [Clamav-users] Virus-bounce emails

2005-04-20 Thread Chris Masters
> > I understand. Is it possible to send me the entire > original file for me to look at? > I'll then be in a better position to comment > knowledgeably. > Thanks for your help on this Nigel. I'll let you know if I manage to reproduce. __ Do You

Re: [Clamav-users] Virus-bounce emails

2005-04-19 Thread Nigel Horne
On Tuesday 19 Apr 2005 10:44, Chris Masters wrote: > > --- Nigel Horne <[EMAIL PROTECTED]> wrote: > > On Tuesday 19 Apr 2005 09:23, Chris Masters wrote: > > > > > > > 3) Should clam detect the virus when given the > > > > entire > > > > > bounce message? > > > > > > > > Yes, if you have a sample

Re: [Clamav-users] Virus-bounce emails

2005-04-19 Thread Chris Masters
--- Nigel Horne <[EMAIL PROTECTED]> wrote: > On Tuesday 19 Apr 2005 09:23, Chris Masters wrote: > > > > > 3) Should clam detect the virus when given the > > > entire > > > > bounce message? > > > > > > Yes, if you have a sample which is not found, > please > > > email it to me. > > > > We curre

Re: [Clamav-users] Virus-bounce emails

2005-04-19 Thread Nigel Horne
On Tuesday 19 Apr 2005 09:23, Chris Masters wrote: > > > 3) Should clam detect the virus when given the > > entire > > > bounce message? > > > > Yes, if you have a sample which is not found, please > > email it to me. > > We currently don't ask clamav to scan the entire raw > message - just each

Re: [Clamav-users] Virus-bounce emails

2005-04-19 Thread Chris Masters
Thanks for your comments Nigel. > > > > So, some questions: > > > > 1) How dangerous are these virus-bounces? > > In theory not at all, but I don't trust MUAs not to > be broken > so clamAV does look for and find them. Exactly! > > > 2) Should clam detect the virus when given the > > text/plai

Re: [Clamav-users] Virus-bounce emails

2005-04-19 Thread Nigel Horne
On Tuesday 19 Apr 2005 00:08, Chris Masters wrote: > Hi All, > > We've had some problems with ligitimate bounces coming > from qmail that contain one text/plain mime part. This > single mime part contains some error information and > then the original raw infected mail in MIME format. > > We scan e