Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    May 2004
    Location
    PL
    Posts
    40

    Smile [Exim] Bounce message, but without attachment

    Hello!

    For the last two days, someone was trying to send lots and lots of emails with virus attachments to many email accounts located on our server. But the messages do not get delivered, because clamav is configured to not deliver messages, which have suspicious attachments (.pif, .cpl, .scr and so on). Clamav "catches" these messages, and bounces them back, saying that the attachment may contain a virus, blah blah blah. Ok, that's fine, but I want Exim to send these "bounced messages" without the attachement. How do I configure Exim so he drops the attachment before sending the bounce?

  2. #2
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    Sending any bounce message back to the from address in spam or viruses is a bad idea... I'd completely block your server if you were sending such bounces to me (I've been DDOS'ed by the bounces sent from both an open relay and the servers the spam was sent to, coming back to a domain I hosted that had several fake addresses forged as the spam's From address) and and many other mail admins would block you as well. It's also a quick and easy way to get on several email blacklists, since you can trigger a spamtrap address with them.

    Read this page for more info:
    http://www.spamcop.net/fom-serve/cache/329.html

    Better to configure your software to reject such unwanted emails during the smtp transaction (with an smtp error code ie 5xx) and let the sending server deal with them.

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Actually, it's most likely the system_filter /etc/antivirus.exim if you don't want to use it, disable it. Search on the forums on ways to do that.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    May 2004
    Location
    PL
    Posts
    40

    Thumbs up

    Quote Originally Posted by dezignguy
    [...] Better to configure your software to reject such unwanted emails during the smtp transaction (with an smtp error code ie 5xx) and let the sending server deal with them.
    OK... How do I do it? Some directions would be useful.

  5. #5
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    well, you haven't really told me what you're running and how you have your system setup...

    But I've been using ASSP (http://assp.sourceforge.net) as my spam/virus filter for a couple years now and when I moved over to using a Cpanel server, I brought it along and integrated it into my cpanel setup. And I didn't bother to check out any alternate way of doing this.

    My observation of exim's antivirus.exim filter (on my server at least) is that it rejects matching emails in the smtp conversation like it should. However, I don't use a separate clamav filter, or any of the clamavconector stuff that cpanel does (ASSP uses the clamav signatures internally). So Clamav is probably what's messing up what it should be doing.

    So, I can't really help you with any further info unless you want to go with ASSP, or drop ClamAV and go back to a vanilla cpanel setup. Read the docx for clamav and see if they have a config setting to help you out... and check out their forums/mailing lists and see if someone can help you.

  6. #6
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Anyone else can give some directions on howto disable dangerous attachments returning to sender on a default cpanel exim setup?

  7. #7
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The answer is still likely to be with my post a couple above.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Bounce message alerts
    By moonsoftsystems in forum Feature Requests for cPanel/WHM
    Replies: 3
    Last Post: 02-21-2011, 06:22 AM
  2. Question about returning (bounce) a message back to sender...
    By guldvog in forum E-mail Discussions
    Replies: 8
    Last Post: 10-21-2007, 02:40 AM
  3. Email Pipe: Bounce Back Message makes no sense
    By doni49 in forum E-mail Discussions
    Replies: 2
    Last Post: 03-26-2007, 09:46 PM
  4. Horde Errors When Forwarding Message With Attachment
    By appcomm in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-18-2005, 10:15 AM
  5. Autoresponder and bounce message
    By The Prince in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-16-2004, 09:08 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube