[Declude.Virus] pif files

2003-08-28 Thread Danny Klopfer
Is there a way to delete pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added

B~(name="DOT*\DOTpif"):NUL

but I still see virues showing up in the hold folder.

Thanks,


Danny


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] pif files

2003-08-28 Thread R. Scott Perry

Is there a way to delete .pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added
B~(name=".*\.pif"):NUL

but I still see virues showing up in the hold folder.
Declude Virus runs before the rules do, so this may not be 
possible.  Although Declude Virus can delete viruses automatically, it 
won't delete banned attachments automatically (as in many cases they are 
legitimate).

   -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] pif files

2003-08-28 Thread Danny Klopfer
Is there a way to delete .pif emails before they get scanned? I'm trying to
cut back on system resources. I think declude runs before rules.ima as I
added

B~(name=".*\.pif"):NUL

but I still see virues showing up in the hold folder.

Thanks,


Danny


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Combining SKIPIF and ONLYSENDIF

2003-08-28 Thread John Carter

Thanks, Scott.  You are one of the big reasons I stay with Imail.  

(Sorry my subject line was kind of off.  Message started off about
combining the use of statements, but the manual straighten me out on
that.  But it didn't help with the problem of still getting notices from
inside campus machines. Thus the IP question.)

Again, thanks.

John 

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
Sent: Thursday, August 28, 2003 11:32 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Combining SKIPIF and ONLYSENDIF


>Is there a way (or could it be added to the program [hint, hint]) to
check 
>the IP (or IP class) instead of sender domain.  Example: ONLYSENDIFIP 
>172.22.12.240 or ONLYSENDIFIP 172.22.*.*

An ONLYSENDIFIP option will be added to the next release (where it would

look for a partial match, such as either "ONLYSENDIFIP 172.22.12.240" or

"ONLYSENDIFIP 172.22.").

-Scott


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] Daily Virus Notification

2003-08-28 Thread R. Scott Perry

Every day, when you "roll-over" to a new virus log, this batch process 
could be kicked off that would read the just-completed virus.log for the 
MEDIUM log information, collate it by user and then send a daily 
anti-virus summary to each user:
That is a good idea -- I'll add that to the suggestion database.

   -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] Combining SKIPIF and ONLYSENDIF

2003-08-28 Thread R. Scott Perry

Is there a way (or could it be added to the program [hint, hint]) to check 
the IP (or IP class) instead of sender domain.  Example: ONLYSENDIFIP 
172.22.12.240 or ONLYSENDIFIP 172.22.*.*
An ONLYSENDIFIP option will be added to the next release (where it would 
look for a partial match, such as either "ONLYSENDIFIP 172.22.12.240" or 
"ONLYSENDIFIP 172.22.").

   -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Combining SKIPIF and ONLYSENDIF

2003-08-28 Thread John Tolmachoff \(Lists\)








Sobig ALLWAYS forges the sender, so this
is a mute point.

 





John Tolmachoff MCSE CSSA

Engineer/Consultant

eServices For You

www.eservicesforyou.com





 



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of John Carter
Sent: Thursday,
 August 28, 2003 6:39 AM
To: Declude Anti-virus Forum
Subject: [Declude.Virus] Combining
SKIPIF and ONLYSENDIF

 

We have a special virus notification that is set to
ONLYSENDIFLOCALSENDER.  It goes to the helpdesk to let us know someone on
campus possibly has a virus.  Unfortunately with Sobig spoofing some of
our user names and sending messages to us from outside campus, the helpdesk is
being flooding with false notices.  The only way to stop it, to my
knowledge, is to disable the notice.

 

Is there a way (or could it be added to the program [hint,
hint]) to check the IP (or IP class) instead of sender domain.  Example: ONLYSENDIFIP
172.22.12.240 or ONLYSENDIFIP 172.22.*.*

 

(Sorry if this was already suggested in the recent flurry of
messages about banning notifications.  Plus, the archive is days behind.)

 

John










[Declude.Virus] Combining SKIPIF and ONLYSENDIF

2003-08-28 Thread John Carter








We have a special virus notification that is set to
ONLYSENDIFLOCALSENDER.  It goes to the helpdesk to let us know someone on
campus possibly has a virus.  Unfortunately with Sobig spoofing some of
our user names and sending messages to us from outside campus, the helpdesk is
being flooding with false notices.  The only way to stop it, to my
knowledge, is to disable the notice.

 

Is there a way (or could it be added to the program [hint,
hint]) to check the IP (or IP class) instead of sender domain.  Example:
ONLYSENDIFIP 172.22.12.240 or ONLYSENDIFIP 172.22.*.*

 

(Sorry if this was already suggested in the recent flurry of
messages about banning notifications.  Plus, the archive is days behind.)

 

John