Re: What does "UNCHECKED" really mean?
Nick Tait <[email protected]> Tue, 17 Jun 2025 19:08:44 +1200
| Newsgroups | gmane.mail.virus.amavis.user |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------Ny8BrNllEUVAfHdF01p9jBDU Content-Type: multipart/alternative; boundary="------------4OULKLkrLVr0vpZxvWon00LM" --------------4OULKLkrLVr0vpZxvWon00LM Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 16/06/2025 21:41, Martin Kellermann wrote: > > Hi, > > It could be a password-protected zip attachment that prevents the > virus scanner from opening and scanning the contents… > > regards > > MK > Thanks for the info. I've managed to work it out by taking a copy of one of the problematic messages and progressively simplifying it and testing. What I've found is that the problem is triggered by having a multi-part message, where one or more parts contains multiple Content-Transfer-Encoding headers... I've attached two files. If you compare them you'll see that the only difference between good.txt and bad.txt, is that bad.txt has an extra Content-Transfer-Encoding header within the first part of the multi-part message. If you want to replicate my test, please run the following command on the server with Amavis, but replace [email protected] with your own email address: [email protected] < bad.txt You should find bad.txt arrives with a subject of "***UNCHECKED*** Testing" (whereas good.txt has the unmodified subject of "Testing"). Is this a bug that should be fixed in Amavis? Or ClamAV? Or is it expected that having an extra header like this makes the message invalid and therefore shouldn't be virus scanned? Thanks, Nick. --------------4OULKLkrLVr0vpZxvWon00LM Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> <div class="moz-cite-prefix">On 16/06/2025 21:41, Martin Kellermann wrote:<br> </div> <blockquote type="cite" cite="mid:[email protected]"> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <meta name="Generator" content="Microsoft Word 15 (filtered medium)"> <style>@font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face {font-family:Consolas; panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri",sans-serif;}a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;}a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;}pre {mso-style-priority:99; mso-style-link:"HTML Vorformatiert Zchn"; margin:0cm; margin-bottom:.0001pt; font-size:10.0pt; font-family:"Courier New";}p.msonormal0, li.msonormal0, div.msonormal0 {mso-style-name:msonormal; mso-margin-top-alt:auto; margin-right:0cm; mso-margin-bottom-alt:auto; margin-left:0cm; font-size:11.0pt; font-family:"Calibri",sans-serif;}span.HTMLVorformatiertZchn {mso-style-name:"HTML Vorformatiert Zchn"; mso-style-priority:99; mso-style-link:"HTML Vorformatiert"; font-family:Consolas;}span.E-MailFormatvorlage22 {mso-style-type:personal-reply; font-family:"Calibri",sans-serif; color:windowtext;}.MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;}div.WordSection1 {page:WordSection1;}</style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext="edit" spidmax="1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext="edit"> <o:idmap v:ext="edit" data="1" /> </o:shapelayout></xml><![endif]--> <div class="WordSection1"> <p class="MsoNormal"><span style="mso-fareast-language:EN-US">Hi,<o:p></o:p></span></p> <p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p> <p class="MsoNormal"><span lang="EN-GB" style="mso-fareast-language:EN-US">It could be a password-protected zip attachment that prevents the virus scanner from opening and scanning the contents…<o:p></o:p></span></p> <p class="MsoNormal"><span lang="EN-GB" style="mso-fareast-language:EN-US"><o:p> </o:p></span></p> <p class="MsoNormal"><span lang="EN-GB" style="mso-fareast-language:EN-US">regards<o:p></o:p></span></p> <p class="MsoNormal"><span lang="EN-GB" style="mso-fareast-language:EN-US"><o:p> </o:p></span></p> <p class="MsoNormal"><span lang="EN-GB" style="mso-fareast-language:EN-US">MK</span></p> </div> </blockquote> <p>Thanks for the info.<br> </p> <p>I've managed to work it out by taking a copy of one of the problematic messages and progressively simplifying it and testing. What I've found is that the problem is triggered by having a multi-part message, where one or more parts contains multiple Content-Transfer-Encoding headers...<br> </p> <p>I've attached two files. If you compare them you'll see that the only difference between good.txt and bad.txt, is that bad.txt has an extra Content-Transfer-Encoding header within the first part of the multi-part message.<br> </p> <p>If you want to replicate my test, please run the following command on the server with Amavis, but replace <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> with your own email address:</p> <pre>sendmail <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> < bad.txt </pre> <p>You should find bad.txt arrives with a subject of "***UNCHECKED*** Testing" (whereas good.txt has the unmodified subject of "Testing").</p> <p>Is this a bug that should be fixed in Amavis? Or ClamAV? Or is it expected that having an extra header like this makes the message invalid and therefore shouldn't be virus scanned?<br> </p> <p>Thanks,<br> </p> <p>Nick.</p> <p></p> </body> </html> --------------4OULKLkrLVr0vpZxvWon00LM-- --------------Ny8BrNllEUVAfHdF01p9jBDU Content-Type: text/plain; charset=UTF-8; name="good.txt" Content-Disposition: attachment; filename="good.txt" Content-Transfer-Encoding: base64 U3ViamVjdDogVGVzdGluZwpNSU1FLVZlcnNpb246IDEuMApDb250ZW50LVR5cGU6IG11bHRp cGFydC9taXhlZDsgYm91bmRhcnk9Ij09Qk9VTkRBUlk9PSIKCi0tPT1CT1VOREFSWT09Ck1J TUUtVmVyc2lvbjogMS4wCkNvbnRlbnQtVHlwZTogdGV4dC9wbGFpbjsgY2hhcnNldD0idXRm LTgiCkNvbnRlbnQtVHJhbnNmZXItRW5jb2Rpbmc6IHF1b3RlZC1wcmludGFibGUKClRlc3Qg MS4KLS09PUJPVU5EQVJZPT0KTUlNRS1WZXJzaW9uOiAxLjAKQ29udGVudC1UeXBlOiB0ZXh0 L3BsYWluOyBjaGFyc2V0PSJ1dGYtOCIKQ29udGVudC1UcmFuc2Zlci1FbmNvZGluZzogcXVv dGVkLXByaW50YWJsZQoKVGVzdCAyLgotLT09Qk9VTkRBUlk9PS0tCgo= --------------Ny8BrNllEUVAfHdF01p9jBDU Content-Type: text/plain; charset=UTF-8; name="bad.txt" Content-Disposition: attachment; filename="bad.txt" Content-Transfer-Encoding: base64 U3ViamVjdDogVGVzdGluZwpNSU1FLVZlcnNpb246IDEuMApDb250ZW50LVR5cGU6IG11bHRp cGFydC9taXhlZDsgYm91bmRhcnk9Ij09Qk9VTkRBUlk9PSIKCi0tPT1CT1VOREFSWT09Ck1J TUUtVmVyc2lvbjogMS4wCkNvbnRlbnQtVHlwZTogdGV4dC9wbGFpbjsgY2hhcnNldD0idXRm LTgiCkNvbnRlbnQtVHJhbnNmZXItRW5jb2Rpbmc6IHF1b3RlZC1wcmludGFibGUKQ29udGVu dC1UcmFuc2Zlci1FbmNvZGluZzogcXVvdGVkLXByaW50YWJsZQoKVGVzdCAxLgotLT09Qk9V TkRBUlk9PQpNSU1FLVZlcnNpb246IDEuMApDb250ZW50LVR5cGU6IHRleHQvcGxhaW47IGNo YXJzZXQ9InV0Zi04IgpDb250ZW50LVRyYW5zZmVyLUVuY29kaW5nOiBxdW90ZWQtcHJpbnRh YmxlCgpUZXN0IDIuCi0tPT1CT1VOREFSWT09LS0KCg== --------------Ny8BrNllEUVAfHdF01p9jBDU--