At 22.24 01/12/2004, you wrote:
>Jason Haar wrote:
>> However, a lot of sites complained. They actually looked at the logs and
>> they didn't like seeing that 44% of their quarantine events were "PIF
>> blocked" - they wanted to know WHAT VIRUS IT WAS.
>
>But you have the PIF in quarantine anyway.  Couldn't you save CPU by
>PIF-blocking the attachment, then scanning it later (during off-peak hours,
>or in a nice process) to find out what virus it was?

This is not to be happened, usually you block in advance such attach name on a company policy or because of your policy.
Your users are usually awarned that "pif file is not a valid attach and it will be rejected".


Btw:
I told this because this was one thing that RAV AV had and it is the first thing our companies usually ask for
Now we are told that vexira/avmilter will have this soon... I saw that virusbuster has ...
Smtp-vilter has.


So I thought it was a smart thing to have for clamav-milter too, but it is not a problem if it dislikes to everybody :-)






Best Regards, Gianmarco Giovannelli , "Unix expert since yesterday" http://utenti.gufi.org/~gmarco/

_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Reply via email to