LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-24-2003, 04:53 PM   #1
lewt
Member
 
Registered: Aug 2003
Posts: 43

Rep: Reputation: 15
Exclamation MS Security Virus Email bypasses Procmail Filter


We cant figure it out.. we filter any .exe's that come through and those attachments are still slipping past procmail.

Anyone having similar experiences?
 
Old 09-24-2003, 05:28 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
We can't either w/o you posting your procmail recipe's, but if you "egrep mbox -ie "^content-type: (multi|audio)"" and compare it with your recipe's you prolly see why.
 
Old 09-24-2003, 05:45 PM   #3
lewt
Member
 
Registered: Aug 2003
Posts: 43

Original Poster
Rep: Reputation: 15
Sorry

Code:
VERBOSE=OFF
LOGFILE=/var/log/procmail.info
PATH="/usr/bin:$PATH:/usr/local/bin"
DROPPRIVS=NO

SHELL=/bin/sh



MANGLE_EXTENSIONS="exe|exe |com|cmd|bat|pif|sc[rt]|lnk|dll|ocx|do[ct]|xl[swt]|p[po]t|rtf|vb[se]?|hta|p[lm]|sh[bs]|hlp|chm|eml|ws[cfh]|ad[ep]|jse?|md[abe$
POISONED_EXECUTABLES=/etc/procmail/poisoned
SECURITY_NOTIFY="postmaster"

SECRET="xxxxxx"


SECURITY_QUARANTINE=/dev/null
POISONED_SCORE=25


SCORE_HISTORY=/var/log/macro-scanner-scores
# LOGFILE=/var/log/procmail.log


# Finished setting up, now run the sanitizer...
INCLUDERC=/etc/procmail/html-trap.procmail


# Reset some things to avoid leaking info to
# the users...
POISONED_EXECUTABLES=
SECURITY_NOTIFY=
SECURITY_NOTIFY_VERBOSE=
SECURITY_NOTIFY_SENDER=
SECURITY_QUARANTINE=
SECRET=
 
Old 09-24-2003, 06:32 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
This does a whole lotta.. ah, nuttin :-]
It clearly references files in subdirs you did not include. If this is a regular package post the name and version. Besides verbose is off, so logging will be way less, and to troubleshoot you want to have as much loggable info as you can.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
procmail virus scanner Red Squirrel Linux - Software 3 05-15-2005 06:25 PM
Email filter graveworm Linux - Software 1 07-07-2004 10:39 AM
Spam/Virus fIlter mail gateway tarballedtux Linux - Software 0 02-24-2004 06:23 AM
qmail getmail redhat 9 spam virus filter baronsam Linux - Networking 0 10-19-2003 06:15 AM
Procmail or other filter for outgoing mail gabriele_101 Linux - Software 3 08-18-2003 05:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration