[Mimedefang] ClamAV's Worm/Trojan/Joke/W97M classifications

James Ebright jebright at esisnet.com
Thu Jun 30 09:59:48 EDT 2005


On Thu, 30 Jun 2005 08:42:58 -0400 (EDT), Matt Cuttitta wrote

> What if i have mail forwarded from mcut at blah.com to my address and 
> blah.com doesn't do virus scanning?  Then the message gets forwarded,
>  rejected because it has a virus, and blah.com generates a bounce 
> message even though the virus had its own SMTP engine.

I would disconintue forwarding of mail from a MTA that didn't scan at the
network edge is what I would do. Again, this is only your issue because you
have made it so. Also, in the case of Sober, it used its own SMTP engine thus
90% or of those messages if rejected  would have simply been discarded/ignored
by the zombie pc. 

Also, if you implement a good SPF policy on your OWN domain then the forgeing
blow-back is nullified as well in other scenarios. Just my own thoughts here,
we can do what ifs all day.....

Jim
--
EsisNet.com Webmail Client




More information about the MIMEDefang mailing list