LISTSERV mailing list manager LISTSERV 16.0

Help for LINUX-L Archives


LINUX-L Archives

LINUX-L Archives


LINUX-L@LISTS.UFL.EDU


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

LINUX-L Home

LINUX-L Home

LINUX-L  2010

LINUX-L 2010

Subject:

procmailrc quarantine rules, more harm than good?

From:

"Charles R. Tompkins" <[log in to unmask]>

Reply-To:

[log in to unmask]

Date:

Thu, 4 Feb 2010 00:42:14 -0500

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (28 lines)

My mailserver just quarantined a legit email with an attached pdf that 
matched the below procmail rules:

:0 B
* ^(UEsDBAoAAAAAA)
/spool/mail.quarantine/.

:0 B
* ^(UEsDBAoAA)
/spool/mail.quarantine/.

Here are lines grep'd out of the attachment, the string(s) appears 
several times:

hxQeZJ9j3wwcODPwP7pKuPvQu/HbAAAAAElFTkSuQmCCUEsDBAoAAAAAAAAAIQAS0co8siEAALIh
UEsDBAoAAAAAAAAAIQCaKHUY0gYAANIGAAAWAAAAd29yZC9tZWRpYS9pbWFnZTI2LnBuZ4lQTkcN
DvrNpygOxIEB6MB/AeIm1Hb+D6u+AAAAAElFTkSuQmCCUEsDBAoAAAAAAAAAIQAs1cAQs3kAALN5
QmCCUEsDBAoAAAAAAAAAIQAD4JZzPxQAAD8UAAAWAAAAd29yZC9tZWRpYS9pbWFnZTQyLnBuZ4lQ
LkoKB8KBcCAcCAfCgXAgHAgHwoFwIBwIB8KBlh34CwzG7V8nHCM/AAAAAElFTkSuQmCCUEsDBAoA

I am going to scan the stuffing out of the pdf tomorrow, but am 
wondering if these strings are still valid for catching malicious 
emails?  I inherited these rules and research on them looks antiquated. 
  They are redundant in security terms as the vast majority of mail 
sanitizing is done on other dedicated systems.

Thanks and apologies for cross-postings,
-Charles

Top of Message | Previous Page | Permalink

Advanced Options


Options

Log In

Log In

Get Password

Get Password


Search Archives

Search Archives


Subscribe or Unsubscribe

Subscribe or Unsubscribe


Archives

2022
2021
2020
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
1997

ATOM RSS1 RSS2



LISTS.UFL.EDU

CataList Email List Search Powered by the LISTSERV Email List Manager