Some dangerous files can go trought

Report bugs and workarounds
Post Reply
wines
Posts: 4
Joined: 17 Oct 2017 15:33

Some dangerous files can go trought

Post by wines » 17 Oct 2017 15:45

Hello,

Today I found 2 issues and I hope that you can help me to solve it.

1) If MailScanner gets file with spaces in filename e.g. “Purchase Order.rar” it thinks that file name is just "Purchase" and do not unpack it. Today one of my users got virus on his PC in this way.

2) If you have 2 identical exe files in to separate archives, MailScanner will block only one of them, the rest will get to your network.

I hope that you know how to deal with it, because I could not find any useful in Google.

Thank you

wines
Posts: 4
Joined: 17 Oct 2017 15:33

Re: Some dangerous files can go trought

Post by wines » 17 Oct 2017 16:08

I found solution how to block files without extension, but it also block files with spaces in filename. So it's not very good.

User avatar
shawniverson
Posts: 2769
Joined: 13 Jan 2014 23:30
Location: Rushville, Indiana, USA
Contact:

Re: Some dangerous files can go trought

Post by shawniverson » 17 Oct 2017 22:21

1) Is fixed in the latest MailScanner 5.0.6-5 (eFa 3.0.2.5)

2) Try the latest version and report back whether this issue still exists.
Version eFa 4.0.0 RC3 now available in testing repo. Come join us in advancing eFa!

wines
Posts: 4
Joined: 17 Oct 2017 15:33

Re: Some dangerous files can go trought

Post by wines » 18 Oct 2017 06:58

Thank you for replay. Latest MailScanner installation fixed my first problem.
But the 2nd problem is still actual.

User avatar
shawniverson
Posts: 2769
Joined: 13 Jan 2014 23:30
Location: Rushville, Indiana, USA
Contact:

Re: Some dangerous files can go trought

Post by shawniverson » 18 Oct 2017 13:15

Thank you. Can you provide me some steps? I want to reproduce this exact problem and inform MailScanner devs about this one.
Version eFa 4.0.0 RC3 now available in testing repo. Come join us in advancing eFa!

wines
Posts: 4
Joined: 17 Oct 2017 15:33

Re: Some dangerous files can go trought

Post by wines » 18 Oct 2017 16:47

I've put notepad.exe in archive named "notepad.rar" using winrar 5.50 and made a copy of this archive "notepad - Copy.rar". Then I send this 2 archives in one mail trough my mail gateway. "notepad.rar" was blocked and "notepad - Copy.rar" was not.

User avatar
shawniverson
Posts: 2769
Joined: 13 Jan 2014 23:30
Location: Rushville, Indiana, USA
Contact:

Re: Some dangerous files can go trought

Post by shawniverson » 18 Oct 2017 18:05

Got it, thanks, I will see about escalating this.
Version eFa 4.0.0 RC3 now available in testing repo. Come join us in advancing eFa!

User avatar
shawniverson
Posts: 2769
Joined: 13 Jan 2014 23:30
Location: Rushville, Indiana, USA
Contact:

Re: Some dangerous files can go trought

Post by shawniverson » 18 Oct 2017 18:06

Version eFa 4.0.0 RC3 now available in testing repo. Come join us in advancing eFa!

daemon2k
Posts: 2
Joined: 22 Nov 2018 12:55

Re: Some dangerous files can go trought

Post by daemon2k » 22 Nov 2018 13:14

Hello. Any news?
eFa 3.0.2.6 have same problems with rar attachement with spaces inside name of file. Exe files in such rar files doesn't check clamav ((
Please need fix ASAP.

endokard
Posts: 4
Joined: 28 Nov 2018 06:35

Re: Some dangerous files can go trought

Post by endokard » 28 Nov 2018 06:51

The same problem. I've created new post.

endokard
Posts: 4
Joined: 28 Nov 2018 06:35

Re: Some dangerous files can go trought

Post by endokard » 03 Dec 2018 12:28

Problem solved with MailScanner update

Post Reply