Thank you very much for this detailed answer. I will keep an eye on it and see 
if I can identify rules that tend to misbehave.

Dirk

------ Originalnachricht ------
Von "Thomas Eckardt" 
<[email protected]<mailto:[email protected]>>
An "Dirk Kulmsee" <[email protected]<mailto:[email protected]>>; "For 
Users of ASSP" 
<[email protected]<mailto:[email protected]>>
Datum 23.08.2026 11:36:21
Betreff Re: [Assp-user] noScan setting not working?

I can see, assp is working like configured.

- noscan is observed by the SMTP worker - in case, the mail was delivered 
without any virus scan/detection

but :
>..... info: scanning stored file 
>/opt/assp/notspam/Coverage_for_Perpetual_Paradox--219085.eml for virus ( 
>forced by ClamAVLogScan and/or FileLogScan )

both ClamAVLogScan and FileLogScan are set to 'scan resend folder and collected 
files'
this forces an unconditional recommended virus (post) scan for the stored .eml 
file, if the mail was not scanned by the SMTP worker before - this makes sure, 
that the corpus is virus-clean!

Question: does it make sense to NOT scan ALL mails? -> Here because ' 
unofficial sigs have recognized something spammy'

Suggestion:  it is much more better to scan all mails but to ignore specific 
scan results (e.g. SuspiciousVirus using low weights) or to not use the 
signatures that detects spammy content (e.g. remove the signatures from the 
.hdb or .yara file after download)

example for SuspiciousVirus:

SecuriteInfo\.com\.Spam\.\d+=>0

bash example to remove lines from a signature file (check the sed syntax for 
your sed version first!)

sed -i.bak '/SecuriteInfo\.com\.Spam\.\d+/d' ./securiteinfo.hdb

- make a backup file ./securiteinfo.hdb.bak from ./securiteinfo.hdb
- inplace remove all those lines from ./securiteinfo.hdb

the same can be done using perl or awk ....

Thomas

DISCLAIMER:
*******************************************************
This email and any files transmitted with it may be confidential, legally 
privileged and protected in law and are intended solely for the use of the
individual to whom it is addressed.
This email was multiple times scanned for viruses. There should be no known 
virus in this email!
*******************************************************



Von:        "Dirk Kulmsee via Assp-user" <[email protected]>
An:        "[email protected]" <[email protected]>
Kopie:        "Dirk Kulmsee" <[email protected]>
Datum:        22.08.2026 23:06
Betreff:        [Assp-user] noScan setting not working?
________________________________

[cid:_1_0C75D70C0C75D3240034C4B5C1258E5C]       
[cid:_1_0C75E0400C75DC580034C4B5C1258E5C]




Hi guys,
I'm running on ASSP 2.8.2 (26204). I have spiced up my ClamAV with unofficial 
sigs from Securiteinfo. This sometimes triggers a virus alert, which rather 
means the unofficial sigs have recognized something spammy.  I saw this with 
newsletters coming in and decided to except these from virus scanning.

_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user


_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to