[Mimedefang] MIME type message/partial

David F. Skoll dfs at roaringpenguin.com
Tue Nov 9 09:33:08 EST 2004

On Tue, 9 Nov 2004, Keith Patton wrote:

>  I am getting compaints of email not being delivered.  I look in the
> logs and they are being bounced with "MIME type message/partial not
> accepted here".  Sure enough the filter blocks this type of message.  So
> like any good computer is does exactly what you tell it.

message/partial is a huge, gaping, enormous, cavernous, overwhelming
security risk.  (Was I clear about my feelings?)

message/partial lets you slip malware under the radar of scanners.  It
lets you evade any kind of sensible filtering policy.  The
message/partial MIME type is an abomination that cements in my mind
the belief that MIME was a mistake.

More concretely: message/partial lets you split up a virus so that it
can evade server-side virus scanners.  It will then be reconstructed
by the mail reader and do its damage.

>  I need something because mgmt is likely to tell me just not to block
> and I would like to have some valid reasons as to why they are being
> blocked.

Tell mgmt that if they permit message/partial, they might as well throw
away server-side scanning and turn off their anti-virus software.



