[EMAIL PROTECTED] wrote:
I'm trying to catch viral attachments, namely those with the extention scr, exe, bat, com, pif, etc. The Content-Disposition header to catch the filename.
What do you mean by "catch"? Filter, quarantine or scan?
SpamAssassin is probably not your best bet (and the Wiki says so!). Yes, you can configure rules to detect attachments based on name. No, that's not effective as a "good" anti-virus measure.
Better would be to:
1. Use an external tool (i.e. clamav) to do an actual scan based on content, rather than just the stated file name.
or
2. Filter/remove/quarantine all incoming attachments. (Just doing this based on name is subject to the same limitations.)
There are a couple of other threads going on this same topic that get into more specifics of how to do this with other tools.
- Bob
