Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default Getting hit with email virus attachments of 75K, how can I block this?

    Getting hit with email virus attachments of 75K, how can I block this?

  2. #2
    Member PWSowner's Avatar
    Join Date
    Nov 2001
    Location
    ON, Canada
    Posts
    2,994

    Default

    Other than having your default address set to fail, you can't do much. Between my many different POP accounts I've gotten around 100 of them today. I've even gotten a couple of bounce messages from ones I supposedly sent.

    Some idiot out there is having fun seeing how many people will launch his attachments. They contain W32.Sober.X@mm.
    Mike
    WHM and cPanel Scripts (join our "Scripts Club")
    D/A Photography

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The most obvious solution is to install a server-side email virus scanner - I never get any viruses into my mailbox.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    Chirpy, which Server-side eMail Virus scanner worked best for you?
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Well, ClamAV works fine for me as a freely available scanner. Others like fprot and nod32. TBH, I find that the additional file type and file name filters in MailScanner block nearly everything anyway regardless of virus scanning.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    Member PWSowner's Avatar
    Join Date
    Nov 2001
    Location
    ON, Canada
    Posts
    2,994

    Default

    One thing about these emails that has me puzzled.

    I have several email addresses I use that are set as forwarders to one POP account and the default is set to fail, but somehow I'm getting these emails to all different variations. The most recent one is x_mail-list@premierwebsitesolutions.com but I can't even send email to that. I view the raw file and there are no other addresses in the headers. How can they send emails to something that should fail and get it to me? Chirpy???
    Mike
    WHM and cPanel Scripts (join our "Scripts Club")
    D/A Photography

  7. #7
    Registered User
    Join Date
    Oct 2003
    Posts
    38

    Default

    Quote Originally Posted by PWSowner
    One thing about these emails that has me puzzled.

    How can they send emails to something that should fail and get it to me? Chirpy???
    Even I'm having the same problem, lotsa domains on which default account is set to fail are still receving mails on addresses like XFreeMail@domain.com while these kinda email doesn't exist at all.

  8. #8
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    There's a subtle difference in the way emails are routed by the SMTP protocol that you do have to be careful about. Exim does its account checking on the email address using the SMTP protocol exchange at the beginning of delivery using the results from the "RCPT TO: address@domain.com" command. That email address does not have to be the same as what appears in the email header for the To: (or other recipient) fields. I would suspect that that's where the confusion/problem is.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  9. #9
    Member PWSowner's Avatar
    Join Date
    Nov 2001
    Location
    ON, Canada
    Posts
    2,994

    Default

    Thanks for the explanation.

    It's a good thing some people out there have nothing better to do with life or the rest of us might get bored.
    Mike
    WHM and cPanel Scripts (join our "Scripts Club")
    D/A Photography

Similar Threads & Tags
Similar threads

  1. Block email attachments by domain by SpammAssassin
    By cPanelDavidG in forum Feature Requests for cPanel/WHM
    Replies: 7
    Last Post: 07-30-2010, 02:09 PM
  2. Block Outgoing attachments !!!
    By furquan in forum E-mail Discussions
    Replies: 0
    Last Post: 02-20-2010, 12:20 AM
  3. Replies: 1
    Last Post: 06-29-2009, 08:36 AM
  4. My customers are getting hit with tons of emails virus, what can I do?
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 08-20-2003, 01:16 PM
  5. virus attachments in mail
    By rodeto in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-23-2003, 05:43 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube