[Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Heimir Eidskrem
How do I turn this off. I am having emails held as virus but they are not. They do contain pdfs and doc files. Could not find it in the manual. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe

re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Shayne Embry
Not too sure you'd want to turn that off. We've been getting hit by a wave of messages the last two days, all with the same vulnerability. I've been too busy to spend any time looking at the payload...but if they're not viruses they are definitely spam. I'm catching about 40 per hour, widely

Re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Darin Cox
We got slammed with them today as well. It caught a bunch that made it past spam filtering (we run AVAFTERJM ON). So I'd second that recommendation to NOT turn it off. If you're concerned about delivery, set up an email notification to let the intended recipient know the message was held,

Re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Heimir Eidskrem
They are neither virus or spam but legit email. Shayne Embry wrote: Not too sure you'd want to turn that off. We've been getting hit by a wave of messages the last two days, all with the same vulnerability. I've been too busy to spend any time looking at the payload...but if they're not

Re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Heimir Eidskrem
Me too.. H. Jared Pickerell wrote: How would you go about setting up the ability to include a link to a script to re-queue the message for delivery? I'd be interested in that. Jared -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darin Cox Sent:

Re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Darin Cox
The point is you may let some not-yet-detected viruses through, but in any case you can do that with a switch in the virus.cfg. Darin. - Original Message - From: Heimir Eidskrem To: declude.virus@declude.com Sent: Tuesday, July 31, 2007 6:23 PM Subject: Re: [Declude.Virus] [Invalid

RE: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Jared Pickerell
Thanks. That's great! I've not blocked these before because of a large number of legitimate emails needing to get through that would have been blocked. This lets me block them if I want, but still let the legits get through. I'm a newbie when in comes to Declude configs. I've pretty much left a

Re: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Darin Cox
Yep. You can use SKIPIFVIRUSNAMEHAS at the top of the vulnerability.eml file to specify the vulnerability you don't want to notify on. Darin. - Original Message - From: Jared Pickerell [EMAIL PROTECTED] To: declude.virus@declude.com Sent: Tuesday, July 31, 2007 6:49 PM Subject: RE:

RE: [Declude.Virus] [Invalid ZIP Vulnerability]

2007-07-31 Thread Jared Pickerell
Darin, Thanks for your help. Guess I was hoping there was something along the lines of and INCLUDEIFVIRUSNAMEHAS to only include the message for specific vulnerabilities and to not have to list all of the ones I didn't want to send for. Is there a list of all of the vulnerabilities, or is this