We receive many messages with executable attached file, for example:
Content-Disposition: attachment; filename="SITUATIE ORDINE 01.2003.xls.scr"
or
Content-Disposition: attachment; filename="Jeux de mots et de
mémoire.htm.exe"
I tried to catch these files with the following rules:
rawbody UF_DB
VORLET Jean-Pierre wrote:
We receive many messages with executable attached file, for example:
Content-Disposition: attachment; filename="
or
Content-Disposition: attachment; filename="
These are viruses, which are not really part of SA's remit.
The best way to stop them is to block all e