Email.Phishing.Blackhole

tejas sarade via amavis-users amavis-users at amavis.org
Fri Dec 13 11:31:15 CET 2013


>
> Even clamav detect the email as virus, amavis consider it as “Passed
CLEAN”, and deliver the message.
>

Probably clamd is removing the infected part from email. Check the clamd
daemon setting.

>
> How can I check it?
>
I found this to check on access setting on OS X server.
http://www.clamav.net/lang/en/2012/03/21/on-access-scanning-for-os-x/

> Amavis receives the email from Postfix, use amavis as unix socket to
evaluate it, clamav found a virus on it but no more lines are logged, so I
don’t know If the email has been discarded or not
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.amavis.org/pipermail/amavis-users/attachments/20131213/1a4f69f5/attachment.html>


More information about the amavis-users mailing list