Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > News and Announcements
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News and Announcements This is where you can read announcements regarding Vortech Inc.

Reply
 
Thread Tools Display Modes
  #1  
Old 02-17-2004, 06:00 PM
Bladesnitz
Guest
 
WOOT! - Virus Scanning

After much blood, tears, and extreme frustration, I have created a sweet little virus scanning package for the mail servers. Took only four days of pretty constant work, reading page after man page. My own little (simple) custom program written in C. This avoids the load that perl or shell scripts place on the machine. It integrates quickly with clamav and qmail.

The program simply uses clamdscan to check to see if a message is a virus... If it is, it silently drops it - Noone wants to know you sent a message to them or they missed out on receiving one of those gems - and 99% of the time, its spoofed anyway, causing panic and confusion to the masses of the mail world.

It seems pretty foolproof, load on the server wasn't harmed, and I've tried to break it in many ways, without success (which is good that I couldn't break it...).

Also, we've reenable the RBL after last week's debacle. We're hoping to have our own inhouse DNSBL server soon to avoid sending 2 million queries away.
Reply With Quote
  #2  
Old 02-17-2004, 06:09 PM
somereseller's Avatar
somereseller somereseller is offline
Usability everywhere
Vortech Inc. Customer
 
Location: mars
do you have more details on the type of files that are blocked and the ones that are scanned?
Reply With Quote
  #3  
Old 02-17-2004, 06:14 PM
Bladesnitz
Guest
 
Its scans all messages. If there is a virus, its dropped. Pretty simple?
Reply With Quote
  #4  
Old 02-17-2004, 06:17 PM
somereseller's Avatar
somereseller somereseller is offline
Usability everywhere
Vortech Inc. Customer
 
Location: mars
I should have said attachements instead of message...


goes inside zip, rar, ace, hqx,etc?
scans pif, exe, swf, etc?
Reply With Quote
  #5  
Old 02-17-2004, 06:20 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
Matt, let me guess...

on the weekends you like to build racing engines with duct tape and a grease pen, don't you?

"simply uses clamdscan..." - what a showoff

Nice work!
Reply With Quote
  #6  
Old 02-17-2004, 07:00 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Great stuff Matt, give yourself a big pat on the back ! ... Brad, give that boy a raise will ya !
Reply With Quote
  #7  
Old 02-17-2004, 07:18 PM
Bladesnitz
Guest
 
It will scan all attachments that are valid, and go a layer deep into a zip ... so maybe a zip in zip if there is one. won't scan overly large messages (>1M) until we see viruses that big (I hope not!)
Reply With Quote
  #8  
Old 02-17-2004, 07:52 PM
logic404's Avatar
logic404 logic404 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Melbourne, Australia
Go Matt!!!!!!!
Reply With Quote
  #9  
Old 02-17-2004, 08:05 PM
logic404's Avatar
logic404 logic404 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Melbourne, Australia
Hang on a tick - is this already active? And if so, would it account for an email that I was expecting from a client disappearing without a trace?
Reply With Quote
  #10  
Old 02-17-2004, 09:03 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
I know most people would be screaming praise for this (im one of them), but are we able to disable it on individual accounts? Or is it just a server wide thing? I have a few clients who really dont like the idea of their email being deleted, even if it is a virus. (and no i dont agree with them, but hey what can i do, they pay my bills)
__________________
Paul Foley
Sniper Systems Ltd


Last edited by Silverbug : 02-18-2004 at 12:15 AM.
Reply With Quote
  #11  
Old 02-17-2004, 09:07 PM
logic404's Avatar
logic404 logic404 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Melbourne, Australia
I know what you mean. Virus scanning is FANTASTIC (and kudos to Matt). However it would be nice (there's always a "would be nice", with clients!) if you could disable it, or have an option to have it quarentined and then you decide what to do with it, or just remove the offending attachment but still let the message text go thru. That way, you could at least say, "Yeah, I got your email, but it seems your computer might have a virus as an attachment you sent was infected.". Because you could have "legitimate" email that is infected.

Just a thought, but again, FANTASTIC EFFORT GUYS!!!
Reply With Quote
  #12  
Old 02-17-2004, 09:28 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Any chance instead of drop, it could be setup to bounce with a little message saying "undelivered contained virus" or something like that ? that would I think keep most people pretty happy.
Reply With Quote
  #13  
Old 02-17-2004, 11:55 PM
Bladesnitz
Guest
 
No No No. There is NO reason to preserve viruses EVER. We had so many complaints with MyDoom of people wanting this, and this will NOT be made into a per domain basis, simply due to the fact that we are doing our part to prevent the spread of such things.

And about bounces, quartine, etc. Think about it... How many bounce message did YOU get from MyDoom ... 100% from your email address being spoofed by the virus sender.

So by creating bounces or informing people that we "blocked" a virus, we are simply creating more traffic and causing extra confusion.
Reply With Quote
  #14  
Old 02-17-2004, 11:56 PM
Bladesnitz
Guest
 
Quote:
Originally Posted by logic404
Hang on a tick - is this already active? And if so, would it account for an email that I was expecting from a client disappearing without a trace?

Submit a ticket, chances are something else got it. Only virii have problems going through. Unless they have a virus that piggybacked... hah
Reply With Quote
  #15  
Old 02-18-2004, 12:08 AM
logic404's Avatar
logic404 logic404 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Melbourne, Australia
What if (although I'm pretty sure this isn't the case in this case, because I had the guy send it to a Hotmail account, then used a virus scanner to check that it wasn't infected), someone sent you an email, with an attached word doc, or something, and that person happened to have a virus, which happened to have infected the word document, so - they sent you a pricing enquiry, or a screen dump of an error (why people put these into word is beyond me, but they do), and you never know that they tried to send such a thing, because it got dropped?

How likely is a virus to hang around and infect files like that? I.e - what's the chance that we'll miss a legit email because some part of it was "unintenionally infected" (the message itself wasn't sent by a virus, but did contain a virus)?

Last edited by logic404 : 02-18-2004 at 12:11 AM.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bedtimes Virus dpyers Chit Chat Public 2 10-23-2005 05:35 AM
Virus scanning for e-mail gconspiracy H-Sphere Pre-Sales 7 12-26-2003 11:11 PM


All times are GMT -5. The time now is 07:37 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.73273 seconds with 20 queries
[Output: 104.49 Kb. compressed to 95.71 Kb. by saving 8.78 Kb. (8.40%)]