[Mimedefang] ClamAV's Worm/Trojan/Joke/W97M classifications

Chris Gauch cgauch at digicon.net
Thu Jun 30 14:11:31 EDT 2005


Matthew.van.Erde wrote:

> I'd have to say, in this case there is no choice but to create a bounce
> message.  I wonder, though, if there's a way to do it that wouldn't
> include the virus?

This is a great idea, but let's not forget about the dimwit with the
trigger-happy motivation to open up every attachment regardless of warnings.
Sure, customize your 5xx error codes, but it's just more work, and might not
help too much in the long run.  Additionally, don't forget that some
non-conforming MTA's don't even bother to include the 5xx error code in the
NDN.  You've already dealt with the entire message and its data, your AV
scanner has already classified it as infected, so why push it off for
someone else to deal with?  

- Chris

------------------------------------------
Chris Gauch
Systems Administrator
Digicon Communications, Inc.
http://www.digiconcommunications.com
cgauch at digicon.net





More information about the MIMEDefang mailing list