[Mimedefang] ClamAV's Worm/Trojan/Joke/W97M classifications
Chris Gauch
cgauch at digicon.net
Thu Jun 30 14:11:31 EDT 2005
Matthew.van.Erde wrote:
> I'd have to say, in this case there is no choice but to create a bounce
> message. I wonder, though, if there's a way to do it that wouldn't
> include the virus?
This is a great idea, but let's not forget about the dimwit with the
trigger-happy motivation to open up every attachment regardless of warnings.
Sure, customize your 5xx error codes, but it's just more work, and might not
help too much in the long run. Additionally, don't forget that some
non-conforming MTA's don't even bother to include the 5xx error code in the
NDN. You've already dealt with the entire message and its data, your AV
scanner has already classified it as infected, so why push it off for
someone else to deal with?
- Chris
------------------------------------------
Chris Gauch
Systems Administrator
Digicon Communications, Inc.
http://www.digiconcommunications.com
cgauch at digicon.net
More information about the MIMEDefang
mailing list