MailScanner.conf denying zip files

General eFa discussion
Post Reply
DoubleD
Posts: 1
Joined: 22 Mar 2016 12:00

MailScanner.conf denying zip files

Post by DoubleD »

Hi

Please bear with me as i am new to E.F.A and Linux.
I have the efa 3.0.0.8 running 100% started playing around withe Centos and Red hat as to get use to the OS.
I have mainly worked on Windows. after running the server for 2 weeks requests started coming throe to allow zip files from clients.
Played around with /etc/MailScanner/MailScanner.conf made some changes to allow zip files.
Users were happy they were able to get the files.

About 4 days ago one user opened one of the zip files from a strange sender. After repetitively asking not to and waning them.
Users will do what they want. they were victim to .Locky Looks like the pc and all connections were traced when the virus took control.
Our network did not suffer any hacks. Spent 4 days round the clock making sure of that.
My efa server is taking hits our domain has been circulated and spam is leaking throe. I have some one on duty scanning mails and adding to lists ones they come in and warning users before they read the mail.

This is a manually intense poses. I have made the relevant changes to the MailScanner.conf file to deny the attached files. after making changes i get the following message.
An edit session for this file crashed
if this is the case, use ":recover" or "vim -r /etc/MailScanner/MailScanner.conf"
to recover the changes (see ":help recovery").
if you did this already, delete the swap file "/etc/MailScanner/MailScanner.conf.swp"
to avoid this message.
"/etc/MailScanner/MailScanner.conf" 3126I, 146670C

I have rolled back changes and efa server runs as normal
Normal spammers are blocked with no other spam coming in.
What i would relay need is the detailed steps to follow to get the files blocked
and please bear in mind i am new to E.F.A and Linux

I have managed to get by with RTFS (Read The Freaking Screen) but need some Urgent council
User avatar
shawniverson
Posts: 3649
Joined: 13 Jan 2014 23:30
Location: Indianapolis, Indiana USA
Contact:

Re: MailScanner.conf denying zip files

Post by shawniverson »

DoubleD wrote:I have mainly worked on Windows. after running the server for 2 weeks requests started coming throe to allow zip files from clients.
Played around with /etc/MailScanner/MailScanner.conf made some changes to allow zip files.
Users were happy they were able to get the files.
What i would relay need is the detailed steps to follow to get the files blocked
and please bear in mind i am new to E.F.A and Linux
I'm not sure I understand what you want. You allowed zip files, but now you want them blocked? Can you simply undo your change?
maxkmv
Posts: 53
Joined: 28 Apr 2015 14:40

Re: MailScanner.conf denying zip files

Post by maxkmv »

You need to configure Mailscanner to scan for viruses inside ZIP files, then it will work really well.

Also as a side note. I have antivirus on my primary mail server, and it ALSO scans inside ZIP attachments. That way whatever Mailscanner misses my primary Exchange server will block.
e-d-i-t
Posts: 94
Joined: 27 Apr 2016 19:28
Contact:

Re: MailScanner.conf denying zip files

Post by e-d-i-t »

Where do you alter the config to actually scan inside zip files?
skoppes
Posts: 33
Joined: 26 Aug 2015 19:29

Re: MailScanner.conf denying zip files

Post by skoppes »

I also ran into this previously - EFA doesn't look inside ZIP files by default?

My workaround is located here:
viewtopic.php?f=13&t=1210

Make the following config change (unless an update has changed it from 0 as default?):

Code: Select all

Edit: /etc/MailScanner/MailScanner.conf
Change: Maximum Archive Depth
From: 0
To: 2
Restart MailScanner

Good luck!
Post Reply