Re: post-delivery virus scan

2016-11-10 Thread Dmitry Melekhov
10.11.2016 16:47, Frank Elsner пишет: On Wed, 9 Nov 2016 15:36:33 -0600 Brad Koehn wrote: [ ... ] To help detect and remove the infected messages after they’ve been delivered to users’ mailboxes, I created a small script that iterates the INBOX and Junk mailbox directories, scans recent m

Re: post-delivery virus scan

2016-11-10 Thread Stephan Bosch
Op 10-11-2016 om 12:25 schreef Brad Koehn: On Nov 10, 2016, at 3:38 AM, Stephan Bosch wrote: Op 11/10/2016 om 10:05 AM schreef Teemu Huovila: On 09.11.2016 23:36, Brad Koehn wrote: I’m wondering if there’s a better way to scan recent messages and eradicate them so the Dovecot isn’t upset w

Re: post-delivery virus scan

2016-11-10 Thread Brad Koehn
Turns out the technical part of your reasoning is correct: MUAs that have downloaded the message don’t get any updates, and hold onto the infected message. No legal ramifications here; it’s my personal server, and it’s in the US. Strange to think that deleting the content of a message would some

Re: post-delivery virus scan

2016-11-10 Thread Frank Elsner
On Wed, 9 Nov 2016 15:36:33 -0600 Brad Koehn wrote: [ ... ] > To help detect and remove the infected messages after they’ve been delivered > to users’ mailboxes, I created a small script that iterates the INBOX and > Junk mailbox directories, scans recent messages for viruses, and deletes the

Re: post-delivery virus scan

2016-11-10 Thread Brad Koehn
I’ve decided to try this approach. I’ve updated my script as follows: #!/bin/bash # Scan junk folders for messages containing viruses we didn't have definitions # for when the mail was received. Truncate the body of infected messages and # replace the body with a message. cd /var/mail for dir

Re: post-delivery virus scan

2016-11-10 Thread Brad Koehn
> On Nov 10, 2016, at 3:38 AM, Stephan Bosch wrote: > > Op 11/10/2016 om 10:05 AM schreef Teemu Huovila: >> >> On 09.11.2016 23:36, Brad Koehn wrote: >>> I have discovered that many times the virus definitions I use for scanning >>> messages (ClamAV, with the unofficial signatures >>> http://

Re: post-delivery virus scan

2016-11-10 Thread Stephan Bosch
Op 11/10/2016 om 10:05 AM schreef Teemu Huovila: > > On 09.11.2016 23:36, Brad Koehn wrote: >> I have discovered that many times the virus definitions I use for scanning >> messages (ClamAV, with the unofficial signatures >> http://sanesecurity.com/usage/linux-scripts/) are updated some time afte

Re: post-delivery virus scan

2016-11-10 Thread Teemu Huovila
On 09.11.2016 23:36, Brad Koehn wrote: > I have discovered that many times the virus definitions I use for scanning > messages (ClamAV, with the unofficial signatures > http://sanesecurity.com/usage/linux-scripts/) are updated some time after my > server has received an infected email. It seem

Re: post-delivery virus scan

2016-11-09 Thread mick crane
On 2016-11-09 21:36, Brad Koehn wrote: I have discovered that many times the virus definitions I use for scanning messages (ClamAV, with the unofficial signatures http://sanesecurity.com/usage/linux-scripts/) are updated some time after my server has received an infected email. It seems the virus

post-delivery virus scan

2016-11-09 Thread Brad Koehn
I have discovered that many times the virus definitions I use for scanning messages (ClamAV, with the unofficial signatures http://sanesecurity.com/usage/linux-scripts/) are updated some time after my server has received an infected email. It seems the virus creators are trying to race the viru