Page 1 of 1
Virus delivered in a rar file
Posted: 01 Oct 2014 14:55
by mikemachin
We have the system setup to successfully scan zip files but we have had a number of viruses come through in rar files. These are executables so assume they are viruses or malicious.
Can the system be setup to scan rar files too? or block exes in rars?
Re: Virus delivered in a rar file
Posted: 01 Oct 2014 21:44
by shawniverson
Should be scanning rars already...
In /etc/MailScanner/MailScanner.conf...
Try placing the EICAR test inside a rar file and sending to your EFA...
If it detects, then this part is working.
Next step is to block exe inside of rar somehow....this is tricky because MailScanner unrars and hands off to clamav....clamav doesn't block files just detects viruses...so MailScanner never sees contents of the rar.
Much easier solution is to just block rar files....