[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] Re: Filtering sobig with postfix



also sprach vogt@hansenet.com <vogt@hansenet.com> [2003.08.20.1017 +0200]:
> in main.cf, enable "body_checks = (filename)". In that (filename)
> file, write a regular expression matching sobig, e.g. something
> like
> 
> /see attached file for details/	REJECT

this incurs a factor 2-4 performance drop, and it could also elicit
false positives. you should definitely do more than just REJECT
(i.e. write out a message: s/REJECT/554 Suspected virus/).

also, this is more the job of a content filter than of an MTA.

-- 
martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:"; net@madduck
 
invalid/expired pgp subkeys? use subkeys.pgp.net as keyserver!
 
no micro$oft components were used
in the creation or posting of this email.
therefore, it is 100% virus free
and does not use html by default (yuck!).

PGP signature