Hi All,

I'm running sendmail 8.12.10 with clamav 0.70 and the clamav-milter. It has
been running for several weeks now with no problems and seems to be doing a
fantastic job of stopping virii getting through - kudos to the team.

However I do have a setup question (or maybe a feature request) - is it
possible to have the milter only bounce some messages, based on what virus
or worm is found in the attachment? For example, I receive a number of
emails every day with the SomeFool, LovGate and Bagle worms - these all use
forged 'from' addresses so bouncing the message back is usually not useful
at all (and clogs up the mail server). In fact I have had a number of emails
from people asking about the email they have supposedly sent me we are
tedious to explain if people don't know about spoofing. However, on the
other hand, if someone I know sends me a Word document with a macro virus, I
definitely want my mail server to bounce the message back to them so they
know there's a problem, that I haven't received their email and they need to
sort out the virus. So I don't want to stop sending some bounces.

So, what would be great would be a feature in the milter where we could only
send bounces out to certain worms or viruses, and not bother with the ones
that are known to spoof From addresses. What does everyone think? Or has
anyone already come up with a way to do that, that they would like to share?

regards,
Gavin



-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to