[Declude.Virus] pif files
Is there a way to delete pif emails before they get scanned? I'm trying to cut back on system resources. I think declude runs before rules.ima as I added B~(name="DOT*\DOTpif"):NUL but I still see virues showing up in the hold folder. Thanks, Danny --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] pif files
Is there a way to delete .pif emails before they get scanned? I'm trying to cut back on system resources. I think declude runs before rules.ima as I added B~(name=".*\.pif"):NUL but I still see virues showing up in the hold folder. Declude Virus runs before the rules do, so this may not be possible. Although Declude Virus can delete viruses automatically, it won't delete banned attachments automatically (as in many cases they are legitimate). -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you have been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
[Declude.Virus] pif files
Is there a way to delete .pif emails before they get scanned? I'm trying to cut back on system resources. I think declude runs before rules.ima as I added B~(name=".*\.pif"):NUL but I still see virues showing up in the hold folder. Thanks, Danny --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Combining SKIPIF and ONLYSENDIF
Thanks, Scott. You are one of the big reasons I stay with Imail. (Sorry my subject line was kind of off. Message started off about combining the use of statements, but the manual straighten me out on that. But it didn't help with the problem of still getting notices from inside campus machines. Thus the IP question.) Again, thanks. John -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Thursday, August 28, 2003 11:32 AM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Combining SKIPIF and ONLYSENDIF >Is there a way (or could it be added to the program [hint, hint]) to check >the IP (or IP class) instead of sender domain. Example: ONLYSENDIFIP >172.22.12.240 or ONLYSENDIFIP 172.22.*.* An ONLYSENDIFIP option will be added to the next release (where it would look for a partial match, such as either "ONLYSENDIFIP 172.22.12.240" or "ONLYSENDIFIP 172.22."). -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Daily Virus Notification
Every day, when you "roll-over" to a new virus log, this batch process could be kicked off that would read the just-completed virus.log for the MEDIUM log information, collate it by user and then send a daily anti-virus summary to each user: That is a good idea -- I'll add that to the suggestion database. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you have been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Combining SKIPIF and ONLYSENDIF
Is there a way (or could it be added to the program [hint, hint]) to check the IP (or IP class) instead of sender domain. Example: ONLYSENDIFIP 172.22.12.240 or ONLYSENDIFIP 172.22.*.* An ONLYSENDIFIP option will be added to the next release (where it would look for a partial match, such as either "ONLYSENDIFIP 172.22.12.240" or "ONLYSENDIFIP 172.22."). -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you have been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Combining SKIPIF and ONLYSENDIF
Sobig ALLWAYS forges the sender, so this is a mute point. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Carter Sent: Thursday, August 28, 2003 6:39 AM To: Declude Anti-virus Forum Subject: [Declude.Virus] Combining SKIPIF and ONLYSENDIF We have a special virus notification that is set to ONLYSENDIFLOCALSENDER. It goes to the helpdesk to let us know someone on campus possibly has a virus. Unfortunately with Sobig spoofing some of our user names and sending messages to us from outside campus, the helpdesk is being flooding with false notices. The only way to stop it, to my knowledge, is to disable the notice. Is there a way (or could it be added to the program [hint, hint]) to check the IP (or IP class) instead of sender domain. Example: ONLYSENDIFIP 172.22.12.240 or ONLYSENDIFIP 172.22.*.* (Sorry if this was already suggested in the recent flurry of messages about banning notifications. Plus, the archive is days behind.) John
[Declude.Virus] Combining SKIPIF and ONLYSENDIF
We have a special virus notification that is set to ONLYSENDIFLOCALSENDER. It goes to the helpdesk to let us know someone on campus possibly has a virus. Unfortunately with Sobig spoofing some of our user names and sending messages to us from outside campus, the helpdesk is being flooding with false notices. The only way to stop it, to my knowledge, is to disable the notice. Is there a way (or could it be added to the program [hint, hint]) to check the IP (or IP class) instead of sender domain. Example: ONLYSENDIFIP 172.22.12.240 or ONLYSENDIFIP 172.22.*.* (Sorry if this was already suggested in the recent flurry of messages about banning notifications. Plus, the archive is days behind.) John