I have tried McAfee Webshield SMTP scanning and banning certain
attachments.. handing off mail to IMail, but even COM, EXE, BAT, VBS, SCR,
PIF and the lot get through it occassionally.

I believe that McAfee is susceptible to several mailserver AV vulnerabilities (see http://www.declude.com/virus/vulnerability.htm for a list of mailserver AV vulnerabilities), which could account for why those got through.


I guess nothing is perfect. I just wanted IMail to be the last line of defense
after everything else I might have preceeding it. What do these new rules
look for that filter COM attachments? I'd like to give them a try. I guess I could search the list,
but if anyone knows them right-off, I'd like to look at them. Thanks!

I can't recall offhand -- we don't use IMail filters at all here. The key things to remember are that you may see "name=" and/or "filename=" (so "name=" will catch more, but with more false positives than "filename="), and that filters can't catch all types of attachments (uuencode/binhex/TNEF, vulnerabilities, etc.).


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to