Re: SOLVED: Sophie not detecting some viruses
Alan Thew <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
--On 03 February 2004 13:25 +0100 Andrzej Kukula <[email protected]> wrote: > Hello, > > I have managed to find why Sophie lets some viruses through. > > This actually seems to be a problem with MIME handling in some versions > of Amavis, maybe Sophie, and/or SAVI itself. > > The messages that pass undetected are bounces. If a mail containing > virus is sent to some server that rejects it, the originating mail > server produces a bounce, appends whole original contents (with virus) > and sends it to original sender. > > The bounces are often _not_ MIME messages - for example those generated > by Exim 3. Instead, body of the bounce _is_ MIME-encoded (it has an > attachment with virus). > > The problem is that neither Amavis nor SAVI bothers decapsulating MIME > contents from messages that doesn't have MIME headers in the first > portion of headers (the proper headers of the message). The problem is > that Outlook decapsulates this MIME content and luser is able to > doubleclick the file and run virus. > > I've prepared a message with virus and passed it to sock.pl. The result > was "CLEAN". Then I removed first portion of headers and the body > informing about the reason of bouncing. This way I've got original > e-mail. I ran sock.pl again - this time result was "INFECTED". > Just out of interest, are you able to do this with Sophos 3.76 since I believe, based on what I saw last week with exim 4.24/exiscan/sophos 3.77, this may be OK with sophos 3.76 -- Alan Thew [email protected] Computing Services,University of Liverpool Fax: +44 151 794-4442