I'm running version 3.0.0.6 and added the following line in the /etc/Mailscanner/archives.filetype.rules.conf to block screen-saver files in zip files.
# The maximum depth to which zip archives, rar archives and Microsoft Office
# documents will be unpacked, to allow for checking filenames and filetypes
# within zip and rar archives and embedded within Office documents.
#
# Note: This setting does *not* affect virus scanning in archives at all.
#
# To disable this feature set this to 0.
# A common useful setting is this option = 0, and Allow Password-Protected
# Archives = no. That block password-protected archives but does not do
# any filename/filetype checks on the files within the archive.
# This can also be the filename of a ruleset.
Maximum Archive Depth = 0
You need to set this to a value greater than zero and then restart MailScanner
# The maximum depth to which zip archives, rar archives and Microsoft Office
# documents will be unpacked, to allow for checking filenames and filetypes
# within zip and rar archives and embedded within Office documents.
#
# Note: This setting does *not* affect virus scanning in archives at all.
#
# To disable this feature set this to 0.
# A common useful setting is this option = 0, and Allow Password-Protected
# Archives = no. That block password-protected archives but does not do
# any filename/filetype checks on the files within the archive.
# This can also be the filename of a ruleset.
Maximum Archive Depth = 0
This setting just works for filename and filetype scanning rulesets.
Thank you so much. Sender says that Lotus notes automatically zips the attachments and the attachments are named quote 4-14-15.zip The zip file contains a .doc file created by MS word 97-2003.
Same as the zip file name except it has .doc Sender says they use lotous notes. Lotous notes automatically zips attachments. These zips attachments are very low in size. Less than 200KB.
I just set this settings to prevent all those .zip file related viruses/Trojans. Everything is working except that one client (big company) who uses a old version of MS office and zips every single file with lotus notes before sending out as an email attachment.
- Not folder inside a folder and zipped
- Not a zip inside a zip.
- Its simply a .doc file and its zipped. Is that 2 levels deep?