ORF反垃圾邮件系统

邮件服务器-邮件系统-邮件技术论坛(BBS)

 找回密码
 会员注册
查看: 21043|回复: 24
打印 上一主题 下一主题

Imail 过滤 Mydoom/Novarg方法

[复制链接]
跳转到指定楼层
顶楼
发表于 2004-2-3 15:39:31 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
随着Mydoom/Novarg危害的升级,Ipswitch于昨日(02/02/04) 发布了"IMail - How to protect against the Novarg.A virus"为题的KB,请大家注意,原文全文如下:<br>
<br>
-------------------------------------------------------------------------------<br>
IMail - How to protect against the Novarg.A virus <br>
Product: Version: Platform: <br>
IMail All NT,Win2000,XP,Win2003 <br>
<br>
--------------------------------------------------------------------------------<br><br>
Question/Problem: How do I protect against the Novarg.A virus?<br>
<br>
Answer/Solution: You will want Rules to block attachments. You want to make sure your anti-virus scanner has up to date virus definitions.<br>
<br>
Blocking attachments<br>
<br>
THESE STEPS SHOULD BLOCK ALL FILE ATTACHMENTS.<br>
**YOU WILL WANT TO CREATE RULES TO LOOK AT BOTH THE HEADER AND BODY OF MESSAGES.**<br>
<br>
1. Click on the hostname in IMail Administrator and select the Inbound Rules tab.<br>
2. Click Add<br>
3. From the dropdown box, select "If the Body text". You will also want to create the same rules to say "If the Header text".<br>
4. In the text box, paste the following: name=.*\.scr<br>
5. Click Add Condition<br>
6. Click insert OR<br>
7. In the text box, paste the following: name=.*\.pif<br>
8. Click Add Condition<br>
9. Click insert OR<br>
10. In the text box, paste the following: name=.*\.exe<br>
11. Click Add Condition<br>
12. Click insert OR<br>
13. In the text box, paste the following: name=.*\.zip<br>
14. Click Add Condition<br>
15. Click insert OR<br>
16. In the text box, paste the following: name=.*\.bat<br>
17. Click Add Condition<br>
18. Select the action to be taken.<br>
<br>
For more information on Rules creation see:<br>
IMail - Rules to filter all file attachments<br>
<br>
Use Current Virus Definitions<br>
Verify that your IMail Anti-Virus (or any desktop anti-virus scanner) has the current definitions. They should not be older than 1/28/2004.<br>
<br>
See also:<br>
IMail Anti-Virus - How to automatically update the Virus Definition File<br>
<br>
Disable User Notifications<br>
To stop the influx of notifications being sent to the users and administrator you should add an Inbound Rule to block "Virus Caught" notifications.<br>
<br>
1. Click on the hostname in IMail Administrator and select the Inbound Rules tab.<br>
2. Click Add<br>
3. From the dropdown menu select "If the Subject text"<br>
4. In the text box, enter Virus Detected<br>
5. Click Add Condition<br>
6. Click Insert And<br>
7. From the dropdown menu select "if the Body text" 8. In the text box, enter novarg<br>
8. Click Add Condition<br>
9. Click OK<br>
10. Select the action to be taken.<br>
<br>
Additional Information on Novarg.A<br>
<br>
<a target=_blank href=http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html>http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html</a><br>
<br>
<br>
--------------------------------------------------------------------------------<br>
<br>
A customer suggests: as there is a strain of the novarg virus which forwards itself, but fails to attach itself as a virus. You can add the following line to rules.ima to delete these annoying virus-created spam messages as they come in:<br>
<br>
S~(test|\shi\s|hello|Mail Delivery System|Mail Transaction Failed|Server Report|Status|Error):NUL<br><br>
Document #: Revision Date: <br>
IM-20040130-DM01 02/02/04 <br>
<br>
--------------------------------------------------------------------------------<br><br>
<a target=_blank href=http://support.ipswitch.com/kb/IM-20040130-DM01.htm>http://support.ipswitch.com/kb/IM-20040130-DM01.htm</a>
25
发表于 2004-4-6 12:57:45 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

我做的规则TEST为TRUE,邮件还是不能过滤,不知为何?是否还有其他地方需要注意的呢?请指教!
24
发表于 2004-4-1 12:31:24 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

你不用信纸能发出去吗?、<br>
23
发表于 2004-3-13 00:22:37 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

虽然有点不明白,但还是谢谢版主热心的回答.
22
发表于 2004-3-11 12:04:31 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

邮件头详细信息啊
21
发表于 2004-3-9 14:59:21 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

2 这个语句就可以,但是会误过滤<br>
<br>
过滤EXE的时候以什么做判断?我想应该不能排除所有EXE的文件都是病毒啊.<br>
<br>
20
发表于 2004-3-9 12:27:21 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

1 是符合条件的邮件都被过滤,不是过滤某些字符或者内容<br>
<br>
2 这个语句就可以,但是会误过滤<br>
<br>
3 要检查邮件头信息
19
发表于 2004-3-8 15:32:47 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

这样说,不是整个邮件被过滤掉,而是里面的字符被过滤了???是吗?<br>
<br>
那把附件里包含exe的过滤掉,应该用什么语句??<br>
<br>
而且最近有些用户收到其它用户给他发的垃圾邮件,但问了这些用户之后,都说没有发.请问有遇到过吗?<br>
<br>
<br>
<br>
18
发表于 2004-3-8 14:33:33 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

在邮件体中包含 <br>
name=XXXXXXXXXXX.exe 语句的都被过滤,XXXX(表示任意个数,任意字符)<br>
你可以用ultraedit打开那个没有被过滤掉的邮件,分析一下~<br>
<br>
mailall好像不支持html~
17
发表于 2004-3-8 13:32:05 | 只看该作者

Re:Imail 过滤 Mydoom/Novarg方法

这是rules.ima文件,是不是只要邮件内容有exe字符都会被发到<br>
virus@tomore.com<br>
<br>
B~name=.*\.scr!OR!B~name=.*\.exe!OR!B~name=.*\.bat!OR!B~name<br>
<br>
=.*\.com!OR!B~name=.*\.pif!OR!B~name=.*\.vbs!OR!B~name=.*\.sh<br>
<br>
s!OR!B~name=.*\.sys!OR!B~name="doc.zip"!OR!B~name="document.zi<br>
<br>
p"!OR!B~name="test.zip"!OR!B~name="readme.zip"!OR!B~name="your<br>
<br>
_detailes.zip"!OR!B~name="file.zip"!OR!B~name="data.zip"!OR!B~name<br>
<br>
=".zip":virus@tomore.com<br>
<br>
mailall可以发送html文件吗?
您需要登录后才可以回帖 登录 | 会员注册

本版积分规则

小黑屋|手机版|Archiver|邮件技术资讯网

GMT+8, 2026-7-28 16:37

Powered by Discuz! X3.2

© 2001-2016 Comsenz Inc.

本论坛为非盈利中立机构,所有言论属发表者个人意见,不代表本论坛立场。内容所涉及版权和法律相关事宜请参考各自所有者的条款。
如认定侵犯了您权利,请联系我们。本论坛原创内容请联系后再行转载并务必保留我站信息。此声明修改不另行通知,保留最终解释权。
*本论坛会员专属QQ群:邮件技术资讯网会员QQ群
*本论坛会员备用QQ群:邮件技术资讯网备用群

快速回复 返回顶部 返回列表