We started seeing these are 8am this morning

The attachment comes as photos.zip and so far neither Mcafee or F-prot is
catching them.

We recommend adding a line "BANNAME photos.zip" to the \IMail\Declude\virus.cfg file (with v1.76 or higher), which will catch this.


From: james@<current domain> (The from address may be spoofed to appear that
it is coming from the current domain) - our had knox.edu there.

It does seem that Mimail.c forges the return address, always using a james@ account. Anyone with v1.76 or higher, or who already has a line "SKIPIFVIRUSNAMEHAS Mimail" in the appropriate .eml files, will not have to worry about bogus notifications getting sent out.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to