On Wed, 8 Sep 2004 22:07:53 -0700, you wrote: >I have currently tuned my SARE spam filters, and am humming right along, I get >one or 2 uncaught spams a day which is no big deal. But I would like to catch >the virus emails that have Win exe, scr, bat, and the like for attachments, >but I can't find a rule for them. > >Is there one? How can I catch them otherwise? > >Rob
Rob, I don't pretend this is the best way to solve your problem (what you ideally want to do is look at amavisd-new), but assuming you have a good reason for doing it this way, here's a half-assed approach. Below are uuencoded translations for a few common windows executable markers. Set up rules looking for them and any others you can find. This program cannot be run in DOS mode VGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGU This program must be run under Win32 VGhpcyBwcm9ncmFtIG11c3QgYmUgcnVuIHVuZGVyIFdpbjMy Good luck! Mike- -- If you can keep your head while those around you are losing theirs... You may have a great career as a network administrator ahead! -- Please note - Due to the intense volume of spam, we have installed site-wide spam filters at catherders.com. If email from you bounces, try non-HTML, non-encoded, non-attachments,