Naresh wrote:

Hi all,

I am running Qmail (patched with qmail-smtpd-viruscan-1.1.patch)+qmail-scanner+spam
assassin+clamAV on FreeBSD.

My users are on windows and use MS Outlook (I hate this!!! But they refuse to switch to
any other; I have to live with this reality). And I am responsible for their security.

I tested my setup for -

1. ActiveX vulnerability test
2. CLSID extension vulnerability test
3. Eicar anti-virus software test
4. Fragmented message vulnerability (for Outlook Express)
5. GFI's Access exploit vulnerability test
6. Iframe remote vulnerability test
7. Malformed file extension vulnerability test (for Outlook 2002)
8. MIME header vulnerability test (Nimda & Klez testing)
9. Object Codebase vulnerability test
10. VBS attachment vulnerability test

NOTE: >>> All the details about these tests can be found at
http://www.windowsecurity.com/emailsecuritytest/.

I could prevent Eicar Virus, VBS, MIME header with the qmail-scanner settings.

BUT all other mails were delivered to the user and were actually doing what they were
intended to do - actually test in this case.

I want to secure my mail server for

1. ActiveX vulnerability
2. CLSID extension vulnerability
3. Fragmented message vulnerability
4. Access exploit vulnerability
5. Iframe remote vulnerability
6. Malformed file extension vulnerability

If anyone can suggest how to achieve this at server-end I would really appreciate. Or 
can
suggest additional
packages to be installed for this purpose ...

this has been discussed before- see archives: e.g.- http://sourceforge.net/mailarchive/message.php?msg_id=5759496 http://sourceforge.net/mailarchive/message.php?msg_id=6027182




------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Qmail-scanner-general mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to