Blocking cannibalized spam/virus mail with password-protected attachments

Nikolaos Milas nmilas at noa.gr
Tue Dec 22 11:37:08 CET 2020


On 22/12/2020 11:10 π.μ., Dominic Raferd wrote:

> If you are using a reasonably modern version of ClamAV then just turn 
> on one or more these options in clamd.conf to enable identification 
> (see man clamd.conf):
>
> AlertEncrypted yes
> AlertEncryptedArchive yes
> AlertEncryptedDoc yes
>
> and reload ClamAV. The normal amavis settings will then treat any 
> emails that are flagged as virus-laden. What happens in that case 
> depends on your other amavis settings, especially 
> $virus_quarantine_method.

Thank you Dominic,

I am afraid that our active mail gateway server is rather old...

We are preparing a new gateway server which is almost ready (with new 
software), but I don't feel it's fully production-ready, so it's not yet 
in production!

Thank you, I will definitely check the directives you advise!

Any and all assistance is very important to me!

Cheers,
Nick




More information about the amavis-users mailing list