MailScanner not working properly
MailScanner not working properly
Hi guys.
Using EFA (latest version).
MailScanner is not inspecting URL's ok in docs.google.com case.
If I sent this link to a user which is behind EFA, mailscanner complaints about being fraud:
https://docs.google.com/spreadsheets/d/ ... sp=sharing
but it seems irrasonable to do that.
We have tried with changing mailscanner conf file settings:
We have changed "Use Stricter phishing net" to NO, but still hyperlinks with docs.google.com are being treated by mailscanner a potentially FRAUD.
Is it a bug or is it a feature?
MailScanner has detected definite fraud in the website at "docs.google.com". Do not trust this website: https://docs.google.com/spreadsheets/d/ ... sp=sharing
Thanks, with best regards
Using EFA (latest version).
MailScanner is not inspecting URL's ok in docs.google.com case.
If I sent this link to a user which is behind EFA, mailscanner complaints about being fraud:
https://docs.google.com/spreadsheets/d/ ... sp=sharing
but it seems irrasonable to do that.
We have tried with changing mailscanner conf file settings:
We have changed "Use Stricter phishing net" to NO, but still hyperlinks with docs.google.com are being treated by mailscanner a potentially FRAUD.
Is it a bug or is it a feature?
MailScanner has detected definite fraud in the website at "docs.google.com". Do not trust this website: https://docs.google.com/spreadsheets/d/ ... sp=sharing
Thanks, with best regards
Last edited by bostjanc on 16 Aug 2016 14:43, edited 1 time in total.
Re: MailScanner not working properly
well, if you click the link, where does it take you?
Re: MailScanner not working properly
Hi.
Thank you for your reply.
If I click on link it takes me to:
https://docs.google.com/spreadsheets/d/ ... edit#gid=0
But it's the same even if I sent this hyperlink in the message, mail scanner will "false-positive" complain again.
MailScanner has detected definite fraud in the website at "docs.google.com". Do not trust this website: https://docs.google.com/spreadsheets/d/ ... edit#gid=0
Thank you for your reply.
If I click on link it takes me to:
https://docs.google.com/spreadsheets/d/ ... edit#gid=0
But it's the same even if I sent this hyperlink in the message, mail scanner will "false-positive" complain again.
MailScanner has detected definite fraud in the website at "docs.google.com". Do not trust this website: https://docs.google.com/spreadsheets/d/ ... edit#gid=0
Re: MailScanner not working properly
anyone please help
Re: MailScanner not working properly
I can't help you much except show you what Mailscanner considers phishing:
https://www.mailscanner.info/MailScanne ... .html#Find Phishing Fraud
https://www.mailscanner.info/MailScanne ... x.html#Use Stricter Phishing Net
maybe add docs.google.com to the safe domains? => https://www.mailscanner.info/MailScanne ... l#Phishing Safe Sites File
apart from that the only reason I can think of this to happen is if you are sending shortened links? aka goo.gl/123 which then redirect to docs.google.com or links where the link text is a different URL than the actual link?
https://www.mailscanner.info/MailScanne ... .html#Find Phishing Fraud
https://www.mailscanner.info/MailScanne ... x.html#Use Stricter Phishing Net
maybe add docs.google.com to the safe domains? => https://www.mailscanner.info/MailScanne ... l#Phishing Safe Sites File
apart from that the only reason I can think of this to happen is if you are sending shortened links? aka goo.gl/123 which then redirect to docs.google.com or links where the link text is a different URL than the actual link?
Re: MailScanner not working properly
Hi there.
Thank you for your reply.
But in this case the link text and the URL are same.
Why is then this considered as fraud if the text and URL are the same?
adding googledocs to trusted domain can be a nasty (from security perspective) workaround...
With best regards
Thank you for your reply.
But in this case the link text and the URL are same.
Why is then this considered as fraud if the text and URL are the same?
adding googledocs to trusted domain can be a nasty (from security perspective) workaround...
With best regards
Re: MailScanner not working properly
I've emailed you asking you to send me an email with that link to see what my EFA appliance makes of it.
Re: MailScanner not working properly
Thanks for the email.
message was sent.
With best regards
message was sent.
With best regards
Re: MailScanner not working properly
So I had the exact same results:
This is a bit of a concern, any official way to solve this?
but the mistery is solved. Looking into: /etc/MailScanner/phishing.bad.sites.conf and I see: docs.google.comMailScanner has detected definite fraud in the website at "docs.google.com". Do not trust this website: https://docs.google.com/spreadsheets/d/ ... edit#gid=0
This is a bit of a concern, any official way to solve this?
Re: MailScanner not working properly
Nice to found the root of the problem...
So what are the best practices regarding that?
With best regards
So what are the best practices regarding that?
With best regards
Re: MailScanner not working properly
as a workaround, I'd delete the url in there but it seems its being updated daily.
Not sure where to address this, some official MailScanner forum maybe?
Not sure where to address this, some official MailScanner forum maybe?
Re: MailScanner not working properly
https://github.com/MailScanner/v5/searc ... sites.conf
You could try /etc/MailScanner/phishing.safe.sites.conf, oh a moment...
it's in there
with a *.google.com
you could try to write docs.google.com to /etc/MailScanner/phishing.safe.sites.conf and see who's winning
You could try /etc/MailScanner/phishing.safe.sites.conf, oh a moment...
it's in there
with a *.google.com
you could try to write docs.google.com to /etc/MailScanner/phishing.safe.sites.conf and see who's winning
Last edited by DaN on 17 Aug 2016 11:55, edited 3 times in total.
Re: MailScanner not working properly
Maybe deleting that line with crontab 

Re: MailScanner not working properly
I read somewhere that BAD trumps SAFE.
So manually deleting from BAD is the way to go.
couldn't find anything via Google as to why its in there in the first place. seems there was a wave of phishing attacks in 2014 but nothing current...
So manually deleting from BAD is the way to go.
couldn't find anything via Google as to why its in there in the first place. seems there was a wave of phishing attacks in 2014 but nothing current...
Re: MailScanner not working properly
I've read some "same articles" that google went "wild" in the past (with phishing) 

Re: MailScanner not working properly
For the conclusion, so what is the best approach for fix this?
With best regards
With best regards
Re: MailScanner not working properly
FYI
Posted my question also on mailscanner forum:
https://forum.configserver.com/viewtopi ... =19&t=9696
Posted my question also on mailscanner forum:
https://forum.configserver.com/viewtopi ... =19&t=9696
Re: MailScanner not working properly
It wasn't the "right forum".
Tried my luck also here:
http://forum.mailcleaner.org/viewtopic.php?f=12&t=2400
Tried my luck also here:
http://forum.mailcleaner.org/viewtopic.php?f=12&t=2400
Re: MailScanner not working properly
I think the right place would be going to https://www.mailscanner.info/ then checking under SUPPORT )
You can either use the mailing list: http://lists.mailscanner.info/listinfo/mailscanner
(or possibly the issue tracker: https://github.com/MailScanner/v5/issues=
You can either use the mailing list: http://lists.mailscanner.info/listinfo/mailscanner
(or possibly the issue tracker: https://github.com/MailScanner/v5/issues=
Re: MailScanner not working properly
I love the title of this post.
Add your custom edits to the .custom file for each respective list. The build script merges the values. If your site is in the safe sites, the bad sites will not fire if the same host (domain) is present in both files. Wildcards do not work and from a security standpoint would be a bad idea anyway. If you are using MailScanner v4, then you need to update to MailScanner v5.
Read this to get a general idea of how the phishing sites is built: http://phishing.mailscanner.info/
Read this to get a general idea of how the safe sites is built: http://phishing.mailscanner.info/update_phishing_sites
Read line 7315: https://github.com/MailScanner/v5/blob/ ... Message.pm
Posting bug reports on github is for ... well .... bugs. If you have a MailScanner question, please use the MailScanner mailing list.
Jerry Benton
Add your custom edits to the .custom file for each respective list. The build script merges the values. If your site is in the safe sites, the bad sites will not fire if the same host (domain) is present in both files. Wildcards do not work and from a security standpoint would be a bad idea anyway. If you are using MailScanner v4, then you need to update to MailScanner v5.
Read this to get a general idea of how the phishing sites is built: http://phishing.mailscanner.info/
Read this to get a general idea of how the safe sites is built: http://phishing.mailscanner.info/update_phishing_sites
Read line 7315: https://github.com/MailScanner/v5/blob/ ... Message.pm
Posting bug reports on github is for ... well .... bugs. If you have a MailScanner question, please use the MailScanner mailing list.
Jerry Benton
- shawniverson
- Posts: 3783
- Joined: 13 Jan 2014 23:30
- Location: Indianapolis, Indiana USA
- Contact:
Re: MailScanner not working properly
Milestone 3.0.1.2 Status (includes MailScanner v5):
https://github.com/E-F-A/v3/milestone/15
I'll try to wrap up commits this weekend and get this out to beta.
https://github.com/E-F-A/v3/milestone/15
I'll try to wrap up commits this weekend and get this out to beta.
Re: MailScanner not working properly
thanks. keep up the good work!
Re: MailScanner not working properly
shawniverson any news on new build yet?
with best regards
with best regards
- shawniverson
- Posts: 3783
- Joined: 13 Jan 2014 23:30
- Location: Indianapolis, Indiana USA
- Contact: