We have a special virus notification that is set to
ONLYSENDIFLOCALSENDER. It goes to the helpdesk to let us know someone on
campus possibly has a virus. Unfortunately with Sobig spoofing some of
our user names and sending messages to us from outside campus, the helpdesk is
being flooding
Sobig ALLWAYS forges the sender, so this
is a mute point.
John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of John Carter
Sent: Thursday,
August
Is there a way (or could it be added to the program [hint, hint]) to check
the IP (or IP class) instead of sender domain. Example: ONLYSENDIFIP
172.22.12.240 or ONLYSENDIFIP 172.22.*.*
An ONLYSENDIFIP option will be added to the next release (where it would
look for a partial match, such as
Every day, when you roll-over to a new virus log, this batch process
could be kicked off that would read the just-completed virus.log for the
MEDIUM log information, collate it by user and then send a daily
anti-virus summary to each user:
That is a good idea -- I'll add that to the suggestion
Thanks, Scott. You are one of the big reasons I stay with Imail.
(Sorry my subject line was kind of off. Message started off about
combining the use of statements, but the manual straighten me out on
that. But it didn't help with the problem of still getting notices from
inside campus
Is there a way to delete .pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added
B~(name=.*\.pif):NUL
but I still see virues showing up in the hold folder.
Thanks,
Danny
---
[This E-mail was scanned for viruses by
Is there a way to delete .pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added
B~(name=.*\.pif):NUL
but I still see virues showing up in the hold folder.
Declude Virus runs before the rules do, so this may not be
Is there a way to delete pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added
B~(name=DOT*\DOTpif):NUL
but I still see virues showing up in the hold folder.
Thanks,
Danny
---
[This E-mail was scanned for viruses by