Page 1 of 1

Denial of Service messages from MailScanner

Posted: 22 Jul 2015 18:34
by drewmorris
We recently had an issue where a bunch of our users got emails that said something like:

The mail system was attacked by a Denial Of Service attack, and has therefore \ deleted this part of the message. Please contact your e-mail providers \ for more information if you need it, giving them the whole of this report. Attack in: /var/spool/MailScanner/incoming/20408/B6DB6605DB.A6375/nmsg-20408-13594.html

When we went to the folder to investigate the issue... the path did not exist. Does anybody know:

a. why this happened (I don't think we actually had a DOS attack)
b. if I can change the behavior so it does not actually send this email in this instance and instead either drops the mail completely or sends it to an alternate mailbox.

Sending this sort of message to an end user that has no recourse is bad enough but when I try to hunt down the non-existent files and ultimately need to tell them the mail is lost... that is way worse.

Any help would be greatly appreciated.

Thanks,

Drew

Re: Denial of Service messages from MailScanner

Posted: 23 Jul 2015 06:46
by DaN
What does /var/log/maillog show?

Re: Denial of Service messages from MailScanner

Posted: 23 Jul 2015 13:41
by drewmorris
Can you be more specific... there is nothing in there that I can see that gives me much info

Re: Denial of Service messages from MailScanner

Posted: 23 Jul 2015 14:49
by DaN
a bunch of our users got emails
the log at this point of time would for now help us to help you. Of course you should replace private data first.

Re: Denial of Service messages from MailScanner

Posted: 23 Jul 2015 16:45
by shawniverson
drewmorris,

Here's some links that may help. This could be a resource issue. Something may be timing out during virus scanning.
Or the Processing Attempts Database may be having issues.

http://lists.mailscanner.info/pipermail ... 71518.html
http://lists.mailscanner.info/pipermail ... 01246.html