[Mimedefang] Missing virus name in bounce/discard messages

Jon R. Kibler Jon.Kibler at aset.com
Fri Aug 22 14:02:01 EDT 2003


Greetings:

For some reason, the virus name is missing in some bounced and/or discarded messages. I have one place in the filter code, that generates the message, and "$VirusName" appears in the code where I want the name of the virus -- as illustrated by the example below that works.

> Aug 21 02:47:13 mail sendmail[17394]: h7L6l5FV017394: Milter: data, reject=554 5.7.1 Sorry, but your message is undeliverable. Reason: Virus W32/Sobig.f at MM found in message.
> Aug 21 02:47:13 mail sendmail[17394]: h7L6l5FV017394: to=<x>, delay=00:00:07, pri=30606, stat=Sorry, but your message is undeliverable. Reason: Virus W32/Sobig.f at MM found in message.


However, in some messages, such as yesterday's bugtraq digest, it bounced the message with no indication of which virus it found.
 
> Aug 21 19:58:13 mail sendmail[26028]: h7LNwCuw026028: DEBUG SUBJECT: bugtraq Digest 21 Aug 2003 14:26:15 -0000 Issue 620
> Aug 21 19:58:15 mail sendmail[26028]: h7LNwCuw026028:from=<bugtraq-digest-return-10711-x at securityfocus.com>, size=78411, class=-60, nrcpts=1, msgid=<1061475975.19333.ezmlm at securityfocus.com>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=outgoing2.securityfocus.com [205.206.231.26]
> Aug 21 19:58:19 mail sendmail[26028]: h7LNwCuw026028: Milter: data, reject=554 5.7.1 Sorry, but your message is undeliverable. Reason: Virus  found in message.
> Aug 21 19:58:19 mail sendmail[26028]: h7LNwCuw026028: to=<x>, delay=00:00:06, pri=138926, stat=Sorry, but your message is undeliverable. Reason: Virus  found in message.


Why do we not always see the virus name in the message? We are running the latest rev of McAfee AV for Unix.

Thanks!
Jon R. Kibler
A.S.E.T., Inc.
Charleston, SC  USA



More information about the MIMEDefang mailing list