1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
|
--- ../MailScanner-4.28.5.orig/docs/man/MailScanner.conf.5.html Mon Mar 8 10:41:05 2004
+++ docs/man/MailScanner.conf.5.html Mon Mar 8 10:42:01 2004
@@ -1,5 +1,5 @@
<!-- Creator : groff version 1.19 -->
-<!-- CreationDate: Mon Feb 23 12:00:39 2004 -->
+<!-- CreationDate: Mon Mar 8 10:33:06 2004 -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
@@ -1048,6 +1048,29 @@
<tr valign="top" align="left">
<td width="11%"></td>
<td width="89%">
+<p><b>Allow Password−Protected Archives</b></p></td>
+</table>
+<!-- INDENTATION -->
+<table width="100%" border=0 rules="none" frame="void"
+ cols="2" cellspacing="0" cellpadding="0">
+<tr valign="top" align="left">
+<td width="22%"></td>
+<td width="78%">
+<p>Default: no</p>
+<!-- INDENTATION -->
+<p>Should archives which contain any
+password−protected files be allowed? Leaving this set
+to "no" is a good way of protecting against all
+the protected zip files used by viruses at the moment. This
+can also be the filename of a ruleset.</p>
+</td>
+</table>
+<!-- INDENTATION -->
+<table width="100%" border=0 rules="none" frame="void"
+ cols="2" cellspacing="0" cellpadding="0">
+<tr valign="top" align="left">
+<td width="11%"></td>
+<td width="89%">
<p><b>Maximum Message Size</b></p></td>
</table>
<!-- INDENTATION -->
@@ -1093,6 +1116,29 @@
attachments.</p>
</td>
</table>
+<!-- INDENTATION -->
+<table width="100%" border=0 rules="none" frame="void"
+ cols="2" cellspacing="0" cellpadding="0">
+<tr valign="top" align="left">
+<td width="11%"></td>
+<td width="89%">
+<p><b>Maximum Archive Depth</b></p></td>
+</table>
+<!-- INDENTATION -->
+<table width="100%" border=0 rules="none" frame="void"
+ cols="2" cellspacing="0" cellpadding="0">
+<tr valign="top" align="left">
+<td width="22%"></td>
+<td width="78%">
+<p>Default: 3</p>
+<!-- INDENTATION -->
+<p>The maximum depth to which zip archives will be unpacked
+to allow for checking filenames and filetypes within zip
+archives. Setting this to 0 will disable
+filename/−type checks within zip files while still
+allowing to block password protected zip files.</p>
+</td>
+</table>
<a name="Options specific to Sophos Anti-Virus"></a>
<h2>Options specific to Sophos Anti-Virus</h2>
<!-- INDENTATION -->
@@ -1247,7 +1293,7 @@
kaspersky−4.5, kavdaemonclient, inoculate, inoculan,
onoculan, nod32, nod32−1.99, f−secure,
f−prot, panda, rav, antivir, clamav, clamavmodule,
-trend, bitdefender, none (no virus scanning at all)</p>
+css, trend, bitdefender, none (no virus scanning at all)</p>
<!-- INDENTATION -->
<p>Note for McAfee users: Do NOT use any symlinks with
McAfee at all. It is very strange but McAfee may not detect
@@ -1329,16 +1375,22 @@
fake addresses on messages they send, so there is no point
informing the sender of the message, as it won’t
actually be them who sent it anyway. Other words that can be
-put in this list are the 3 special keywords<br>
+put in this list are the 5 special keywords<br>
HTML−IFrame: inserting this will stop senders being
warned about HTML Iframe tags, when they are not
allowed.<br>
HTML−Codebase: inserting this will stop senders being
warned about HTML Object Codebase tags, when they are not
allowed.<br>
+Zip−Password: inserting this will stop senders being
+warned about password−protected zip files when they
+are not allowd. This keyword is not needed if you include
+All−Viruses.<br>
All−Viruses: inserting this will stop senders being
warned about any virus, while still allowing you to warn
-senders about HTML−based attacks.</p>
+senders about HTML−based attacks. This includes
+Zip−Password so you don’t need to include
+both.</p>
<!-- INDENTATION -->
<p>The default of "All−Viruses" means that
no senders of viruses will be notified (as the sender
@@ -1400,8 +1452,11 @@
non−forging status will override the silent status. In
simple terms, you should list virus names (or parts of them)
that you know do *not* forge the From address. A good
-example of this is a document macro virus or a Joke
-program.</p>
+example of this is a document macro virus or a Joke program.
+Another word that can be put in this list is the special
+keyword "Zip−.Password". Inserting this will
+cause senders to be warned about password−protected
+zip files, whey they are not allowed.</p>
</td>
</table>
<a name="Options specific to ClamAV Anti-Virus"></a>
|