EFA corrupting pdf files with extension .PDF and .PDF.pdf
Posted: 21 May 2018 08:07
Hi there,
we have been using EFA from past few years and came to conclusion that it is very effective product. However, few days back we came across a problem that PDF attachments from some domains were getting corrupted. We have checked logs and found that Mailscanner is not blocking these attachments but corrupting it some how.Logs is pasted for reference:
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 1289.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 911.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 900.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E image001.jpg
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E msg-32058-185.html (no rule matched)
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E msg-32058-184.txt
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E msg-32058-185.html
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E msg-32058-184.txt
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 900.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 911.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 1289.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E image001.jpg (no match found)
May 21 10:58:16 MailScanner[32058]: HTML Img tag found in message 5AC74120DA7.AF17E from ******@domain.com
May 21 10:58:21 MailScanner[32058]: Requeue: 5AC74120DA7.AF17E to 09C57120DAA
May 21 10:58:21 MailScanner[32058]: MailWatch: Logging message 5AC74120DA7.AF17E to SQL
May 21 10:58:21 MailScanner[5848]: MailWatch: 5AC74120DA7.AF17E: Logged to MailWatch SQL
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-210.txt
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-209.txt
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 120377_BROKRAGE BILL.PDF.pdf
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-208.html (no rule matched)
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-207.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-210.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-209.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-207.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-208.html
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 120377_BROKRAGE BILL.PDF.pdf (no match found)
May 16 10:22:49 MailScanner[9386]: Requeue: 90606120D9E.A9951 to 35926120DA7
May 16 10:22:49 MailScanner[9386]: MailWatch: Logging message 90606120D9E.A9951 to SQL
May 16 10:22:49 MailScanner[10606]: MailWatch: 90606120D9E.A9951: Logged to MailWatch SQL
We have also checked by allowing .PDF and .PDF.pdf extensions in filename.rules.conf and whitelisting those domains from which we were having problem but all in vain.
Also to confirm that EFA is causing this corruption in files , we have bypassed EFA and all attachments received successfully. We are using EFA version 3.0.2.6
It has also been observed that these blocked pdf files have .PDF or .PDF.pdf extensions. Files with extension *.pdf(in small letters) received successfully.
Kindly suggest how to identify the root cause of this issue.
we have been using EFA from past few years and came to conclusion that it is very effective product. However, few days back we came across a problem that PDF attachments from some domains were getting corrupted. We have checked logs and found that Mailscanner is not blocking these attachments but corrupting it some how.Logs is pasted for reference:
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 1289.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 911.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E 900.PDF
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E image001.jpg
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E msg-32058-185.html (no rule matched)
May 21 10:58:16 MailScanner[32058]: Filename Checks: Allowing 5AC74120DA7.AF17E msg-32058-184.txt
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E msg-32058-185.html
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E msg-32058-184.txt
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 900.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 911.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E 1289.PDF (no match found)
May 21 10:58:16 MailScanner[32058]: Filetype Checks: Allowing 5AC74120DA7.AF17E image001.jpg (no match found)
May 21 10:58:16 MailScanner[32058]: HTML Img tag found in message 5AC74120DA7.AF17E from ******@domain.com
May 21 10:58:21 MailScanner[32058]: Requeue: 5AC74120DA7.AF17E to 09C57120DAA
May 21 10:58:21 MailScanner[32058]: MailWatch: Logging message 5AC74120DA7.AF17E to SQL
May 21 10:58:21 MailScanner[5848]: MailWatch: 5AC74120DA7.AF17E: Logged to MailWatch SQL
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-210.txt
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-209.txt
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 120377_BROKRAGE BILL.PDF.pdf
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-208.html (no rule matched)
May 16 10:22:44 MailScanner[9386]: Filename Checks: Allowing 90606120D9E.A9951 msg-9386-207.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-210.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-209.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-207.txt
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 msg-9386-208.html
May 16 10:22:44 MailScanner[9386]: Filetype Checks: Allowing 90606120D9E.A9951 120377_BROKRAGE BILL.PDF.pdf (no match found)
May 16 10:22:49 MailScanner[9386]: Requeue: 90606120D9E.A9951 to 35926120DA7
May 16 10:22:49 MailScanner[9386]: MailWatch: Logging message 90606120D9E.A9951 to SQL
May 16 10:22:49 MailScanner[10606]: MailWatch: 90606120D9E.A9951: Logged to MailWatch SQL
We have also checked by allowing .PDF and .PDF.pdf extensions in filename.rules.conf and whitelisting those domains from which we were having problem but all in vain.
Also to confirm that EFA is causing this corruption in files , we have bypassed EFA and all attachments received successfully. We are using EFA version 3.0.2.6
It has also been observed that these blocked pdf files have .PDF or .PDF.pdf extensions. Files with extension *.pdf(in small letters) received successfully.
Kindly suggest how to identify the root cause of this issue.