or a recipient who cannot do something about it as then mail is
held on the server in a directory where only the postmaster has access.
Met vriendelijke groet,
Bonno Bloksma
senior systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040
\*.*
Del /Q C:\IMail\spool\proc\work\*.smd.tmp
net start Decludeproc
echo %Date% %Time% End CleanTemp %LogFile%
exit
--quote---
Met vriendelijke groet,
Bonno Bloksma
senior systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el
Hi Andy,
What tool are you using to specify x days old when deleting? Or are you
allready using Powershell?
Met vriendelijke groet,
Bonno Bloksma
senior systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
b.blok
. :-(
The only option I have is to mangle the attachment name in such a way Declude
wil leave it alone, hoping the receiver is smart enough to do what I want them
to do but never to do it when somone else asks them to do something like that.
;-)
Met vriendelijke groet,
Bonno Bloksma
senior
with this vulnerability.
Met vriendelijke groet,
Bonno Bloksma
senior systeembeheerder
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
b.blok...@tio.nl / www.tio.nl
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe
need to be able to handle IPv6 addresses. Declude will be one of the
programs that needs to have a look at which parts of the program will be
affected by this.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t
need to be able to handle IPv6 addresses. Declude will be one of the
programs that needs to have a look at which parts of the program will be
affected by this.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t
.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
- Original Message -
From: Kevin Rogers
To: Declude.Virus@declude.com
Sent
to be delivered anyway. So
if it gets caught again because the sender ip is still listed... that is not
what I want, I need to have it delivered to the users mailbox.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t
the possible copy, routeto,
etc statements can we at least have it for the HOLD action asap?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
deleted mail.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
- Original Message -
From: David Barker
To: declude.virus
\scanners\ClamAV
directory that seems to suggest something else.
So where is a HOWTO to get it up and running with Declude? I'm sure I'm not the
first to look at the combination, so how dit YOU do it. :-)
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en
this week.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
- Original Message -
From: David Barker
To: declude.virus@declude.com
uses the real name of a virus
when multiple scanners report a virus and some don't know the name?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED
program. I used to be able to extract uuencoded stukk with my zip archive tool
but... What to use for base64 encoded stuff?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
Hi,
For those of us who use ClamAV
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
- Original Message -
From: Moritz
.
Is there something similar that we can use?
p.s. I assume they mean IMail1 as there is no IMail.exe in the IMail directory.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL
.
Is there something similar that we can use?
p.s. I assume they mean IMail1 as there is no IMail.exe in the IMail directory.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL
-Location:
http://server/share/docs/BacoDiscussionsBlob.asp?ID={A1243322-3030-48BF-BD72-8A248CB26090}
I'm assuming this Content-Location can be easily spoofed right? Or could I
somehow convince Declude to pass these mails when there is a specific
Contect-Location
Met vriendelijke groet,
Bonno
.
Currently this is not possible I think, would be a nice option though.
How do others currently circumvent this problem?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
I don't think the Bugzilla page is the right place. If I need to report it via
a mailing list, which one?
3) How I can check whether my report was received?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el
Hi,
Yes, mee to, see my other mail in this forum.
I've tried to send a false positive report to ClamAV but I'm not sure it got
there. :-(
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28
to be woking. Both
scanners are also correctly updating their database.
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
---
This E-mail
Hi,
And...?
Met vriendelijke groet,
Bonno Bloksma
hoofd systeembeheer
tio hogeschool hotelmanagement en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
[EMAIL PROTECTED] / www.tio.nl
- Original Message -
From: David Barker
of them
(with a few exeptions) get called in a situation.
Groetjes,
Bonno Bloksma
- Original Message -
From: GlobalWeb.net Webmaster [EMAIL PROTECTED]
To: Declude.Virus@declude.com
Sent: Wednesday, April 19, 2006 7:15 PM
Subject: RE: [Declude.Virus] How to delete quarantined messages
version
as that is the only correct working combination. And if there are any
problems running THAT combination the guys/gals at Declude are determined to
fix it.
Groetjes,
Bonno Bloksma
---
[E-mail scanned at tio.nl for viruses by Declude Virus]
---
[This E-mail was scanned for viruses
Hi,
I must be missing something. I thought I had
blocked exe's in zip's but some new virusses came through using the exe in zip
trick. here is my virus.cfg, what am I missing?
## Declude Virus configuration file##
This file was distributed with v2.0#
CODE
glad I'm using two scanners. ;-)
Met vriendelijke groet,
Bonno Bloksma
---
[E-mail scanned at tio.nl for viruses by Declude Virus]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives
, 16:46 CET
Using f-prot 3.16b
Groetjes,
Bonno Bloksma
- Original Message -
From: Colbeck, Andrew [EMAIL PROTECTED]
To: Declude.Virus@declude.com
Sent: Monday, May 02, 2005 8:37 PM
Subject: RE: [Declude.Virus] Viruses appearing to be getting through...
F-Prot may have already fixed
and there is as of yet no update. Just
did a manual update and no new version. I'm at:
SIGN.DEF 2-may-2005, 13:32 CET
SIGN2.DEF 2-may-2005, 16:46 CET
Using f-prot 3.16b
Groetjes,
Bonno Bloksma
- Original Message -
From: Colbeck, Andrew [EMAIL PROTECTED]
To: Declude.Virus@declude.com
Sent: Monday
Hi Jim,
Here are the relevant lines for the config file:
SCANFILE C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOMEM
/ARCHIVE=3
/NOBOOT /NOFLOPPY /DUMB /REPORT=report.txt
Remove the /NOFLOPPY when using fpcmd.exe
Groetjes,
Bonno Bloksma
---
[E-mail scanned at tio.nl for viruses
, then if it's not spam, run the AV.
Sorry forgot, don't want to use that option because of the danger it implies
when returning a mesage to the queue.
One caveat is that if you move a message from spam quarantine, it
will not be scanned for virii.
Right. ;-)
Groetjes,
Bonno Bloksma
Back
r when it's not spam. Does anybody
know of a way?
I'm using Virus Pro and JM standard.
Groetjes,
Bonno Bloksma
generate false
positives and if so, how many?
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
---
[E-mail scanned at tio.nl for viruses by Declude Virus]
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from
:ErrMov1s
%DTLOG% %LOGFILE% Error moving SMD files to VirusDay1 directory
Dir . /a %LogFile%
Goto Einde
:ErrMov1g
%DTLOG% %LOGFILE% Error moving GSC files to VirusDay1 directory
Dir . /a %LogFile%
Goto Einde
:Einde
SET LOGFILE=
SET DTLOG=
Groetjes,
Bonno Bloksma
Back up my hard drive
the servers are in the process of being updated themselves and don't
accept connections, or something like it.
Hmmm I think I'll CC this to [EMAIL PROTECTED]
Groetjes,
Bonno Bloksma
---
[E-mail scanned at tio.nl for viruses by Declude Virus]
---
[This E-mail was scanned for viruses by Declude Virus
all the information I can find on that site, they have heard
of it and are catching it.
2) Is this a forging virus we need to add to the
list? If so, does Declude allready have it in his forging virus
list?
Groetjes,
Bonno Bloksma
on the virus front overhere (NL).
Groetjes,
Bonno Bloksma
- Original Message -
From:
Markus Gufler
To: [EMAIL PROTECTED]
Sent: Wednesday, July 28, 2004 12:10
PM
Subject: [Declude.Virus] wave of unknown
viruses?
I'm not sure but
in the last few minutes I can see
is in *one*
place where it can do the most good, any other place can simply use the info
it provides.
Scott, maybe updating the default config to reflect this would be a good
idea.
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
- Original Message -
From: R
reason today, either the sender or
receiver is on a slow dial-up and want's to send/receive across *dial-up
sessions* for whatever reason. If that's the case, maybe they should split
up the file beforehand using ZIP/RAR/etc. and sent eacht part seperate.
Groetjes,
Bonno Bloksma
---
[E-mail scanned
notproduce
*any* hit. Maybe that should be adressed as well, as it is a big feature of
Declude virus.
Groetjes,
Bonno Bloksma
/02/2004 19:09:51
Q2b5d083f02240435 Scanned: CONTAINS A VIRUS [MIME: 439830]05/02/2004
19:09:51 Q2b5d083f02240435 From: To: [EMAIL PROTECTED][incoming from
192.87.5.144]05/02/2004 19:09:51 Q2b5d083f02240435 Subject: Undelivered Mail
Returned toSenderGroetjes,Bonno Bloksma Back up
my hard
[MIME: 4
37310]
04/26/2004 20:44:17 Q588000ad02465470 From: To: [EMAIL PROTECTED]
[incoming from 192.87.5.144]
04/26/2004 20:44:17 Q588000ad02465470 Subject: Undelivered Mail Returned to
Sender
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
- Original Message
anymore.
Met vriendelijke groet,
Bonno Bloksma
- Original Message -
From: Scott Fisher [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Friday, April 23, 2004 3:54 PM
Subject: Re: [Declude.Virus] W32.Netsky.Q got through..
I've noticed that Virusscan does a better job of catching viruses
: To: [EMAIL PROTECTED] [incoming
from 131.174.93.39]
04/19/2004 08:55:47 Q77f00fb601282210 Subject: Undelivered Mail Returned to
Sender
Groetjes,
Bonno Bloksma
- Original Message -
From: Postmaster [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, April 19, 2004 8:55 AM
Subject: Declude Virus
of that.
The latest interim release should scan web messaging E-mail again.
I'll update to the latest interim on monday then. I won't introduce a change
like that minutes before I'm leaving for the weekend. It's past 5 pm here.
;-) Have a nice weekend.
Groetjes,
Bonno Bloksma
---
[This E-mail scanned
at the top of the
mail?
Groetjes,
Bonno Bloksma
. Will general stuff like this be available on a static
link we canrefer peopleto?
Groetjes,
Bonno Bloksma Back up my hard drive? How do I put it in
reverse?
Hi Scott,
If I understand the IMail directory structure correctly the spool\web
directory is only used for mail attachments sent via the webinterface. If
that is indeed the case then here a logfile from Sophos to show you why it
is important to scan webmail for virusses.
Groetjes,
Bonno Bloksma
needs to be BANnotify.eml
While we are on the subject, can I easily delete e-mails with a 0 byte zip
file, as they are just broken virusses anyway?
Like I wrote below, I have IMail (8.05), Declude (1.78i28) Junkmail standard
and virus pro
Met vriendelijke groet,
Bonno Bloksma
- Original
in the test virus menu yet.
Of course it's quite easy to create those files myself but this would
probably be another hint about the quality of Declude.
Groetjes,
Bonno Bloksma
---
[This E-mail scanned for viruses by Declude Virus using f-prot and Sophos]
---
[This E-mail was scanned for viruses
.
For advice consult www.sophos.com, email [EMAIL PROTECTED]
or telephone +44 1235 559933
Ending Sophos Anti-Virus.
--
Met vriendelijke groet,
Bonno Bloksma
---
[This E-mail scanned for viruses by Declude Virus using f-prot and Sophos]
---
[This E-mail was scanned for viruses
eicar.com file [eicarzip]
Spool File: Df84100200154a8a7.SMD
Remote IP: 216.58.174.203
Headers:
[...]
As you can see Declude is using the right template. I guess it's time for
the debug mode?
Met vriendelijke groet,
Bonno Bloksma
---
[This E-mail scanned for viruses
viruses and is
maintained by/for Declude.
but forging..
Yeah. :) It's not the dns which is being forged which kinda gets you on the
wrong track.
Probabaly something simple though. :P
Yup. ;-)
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
---
[This E-mail
reason.
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
- Original Message -
From: Karen D. Oland [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, November 25, 2003 7:46 PM
Subject: RE: [Declude.Virus] Current Forging Virus list
I've also seen
Hi,
It seems the templates at the Declude site are not updatet yet. So euther
Scott did not get around to it yet or he has other information. We got a few
Sobers as well and they claim to have come from an alias we only use for
receiving mail.
Met vriendelijke groet,
Bonno Bloksma
Hi,
I'm thinking of leaving the banext in place but
want to allert the sender and/or recipient when a mail is being held. I've
downloaded the BANnotify.eml file but don't see how Declude decides when to use
it. Do I need to put any extra control lines at the beginning?
Groetjes,
Bonno
something you need to have fixed. Or make it a policy
to update every 3 months to the latest version that is free to you at that
time. I started at 7.00 and am now at 7.07HF2.
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
---
[This E-mail scanned for viruses
, because a few hours later today after the
virusscanner was updated it turned out this exe file contained a virus
called W32/Lirva.D@mm. Am I glad Declude is catching those MIME errors as
well. :-)
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
---
[This E-mail scanned
in a filename) but now it is
visible, in stead of hidden beyond the end of our screen.
Met vriendelijke groet,
Bonno Bloksma
- Original Message -
From: Postmaster [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, December 09, 2002 11:28 AM
Subject: Declude Virus caught a virus
Declude
.
Groetjes,
Bonno Bloksma
Back up my hard drive? How do I put it in reverse?
-Original Message-
From: John Tolmachoff [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, December 03, 2002 10:40 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Opinion on Virus Scanner
F-Prot. Cost
61 matches
Mail list logo