Re: Notification, part II

Rich at Whidbey Telecom <[email protected]> Tue, 21 Dec 2004 08:31:21 -0800
Newsgroups gmane.mail.exim.exiscan.user
Message-ID <[email protected]>
If you quarantine the messages, you can audit them and generate custom  
reports. :)

In our case, we generate summary reports and graphs, at the same time  
we purge older, expired messages:

	http://www.whidbey.com/mailcenter/stats/stats-virus-7.jpg

We tried using a per-virus notification for a while, but users disliked  
the idea, especially when some were being sent 30+ viruses a day.   
Instead, feedback told us to either quietly take care of the messages,  
or, to send users a summary report.

On a side note, many providers block outbound port 25 connections from  
their dynamic pools. Here are some that do so:

MindSpring, BellSouth, MSN, NetZero, People PC, Comcast, Sprynet, Cox,  
Sympatico.ca, EarthLink, Verio, Flashnet, Verizon, MediaOne

As this practice gains popularity, to cut spam-relay trojans and  
viruses, one expects that new variants will rely less on their own SMTP  
engines.

Rich Sandberg
[email protected]
Whidbey Telecom Network Operations

On Dec 21, 2004, at 3:33 AM, Manuel Giorgini wrote:

>
> Well first of all I would like to thank everyone so kind to reply to my
> message. I didn't notice that my replies would not be forwarded to the
> list, and that I should manually insert the list address for that to
> happen, so I apologize for having started private threads out of your
> replies...
>
> Secondly I didn't know that audit and receipt requests would be  
> broadcast
> to each list member. Again I am sorry for any inconvenience. I turned  
> them
> off.
>
>
> As for the message topic, I think I haven't made myself clear enough  
> about
> my intent. I am quite aware of the fact that sending notifications to
> senders of infected mail is very close to useless, mostly because  
> nowadays
> sender addresses are forged. If I mentioned that, it was just to give a
> correct image of amavis' capabilities. However I still find some  
> usefulness
> on admin and recipient notifications and I would like to know if this  
> can
> be arranged with exiscan.
>
> To be even clearer, this is my scenario.
>
> 1. A message comes, from wherever, to one of our local users.
>
> 2. This message has a virus.
>
> 3. Exiscan/clamd/exim intercept it and block further delivery,  
> however, the
> local user and I would like to be notified about it.
>
> Amavis allows such notifications, and one of our customers explicitly  
> asked
> us to use them for their company.
>
> Can I arrange something of this sort with exiscan?
>
>
> Thanks in advance for your attention.
>
>
> Cordialità / Best regards / Gxis la
> ----------------------------------------------------------------------- 
> -
> Manuel Giorgini <[email protected]>, Programmatore
> INTERLOGICA e-business solutions -  http://www.interlogica.net
> Via Fusinato, 27 - IT 30171 Mestre VE - Italia - Unione Europea
> Tel +39 041 099 30 00 (6 linee r.a.) - Fax +39 041 504 11 72
> ----------------------------------------------------------------------- 
> -
>
>
>