Re: SOLVED: Sophie not detecting some viruses

Alan Thew <[email protected]>
Newsgroups gmane.comp.security.virus.vtools
Message-ID <[email protected]>
--On 03 February 2004 13:25 +0100 Andrzej Kukula <[email protected]>
wrote:

> Hello,
> 
> I have managed to find why Sophie lets some viruses through.
> 
> This actually seems to be a problem with MIME handling in some versions
> of Amavis, maybe Sophie, and/or SAVI itself.
> 
> The messages that pass undetected are bounces. If a mail containing
> virus is sent to some server that rejects it, the originating mail
> server produces a bounce, appends whole original contents (with virus)
> and sends it to original sender.
> 
> The bounces are often _not_ MIME messages - for example those generated
> by Exim 3. Instead, body of the bounce _is_ MIME-encoded (it has an
> attachment with virus).
> 
> The problem is that neither Amavis nor SAVI bothers decapsulating MIME
> contents from messages that doesn't have MIME headers in the first
> portion of headers (the proper headers of the message). The problem is
> that Outlook decapsulates this MIME content and luser is able to
> doubleclick the file and run virus.
> 
> I've prepared a message with virus and passed it to sock.pl. The result
> was "CLEAN". Then I removed first portion of headers and the body
> informing about the reason of bouncing. This way I've got original
> e-mail. I ran sock.pl again - this time result was "INFECTED".
> 
Just out of interest, are you able to do this with Sophos 3.76 since I
believe, based on what I saw last week with exim 4.24/exiscan/sophos 3.77,
this may be OK with sophos 3.76

--
Alan Thew                                       [email protected]
Computing Services,University of Liverpool      Fax: +44 151 794-4442
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.