Spam Filter ISP Support Forum

  New Posts New Posts RSS Feed - Embarrassed by new client
  FAQ FAQ  Forum Search   Register Register  Login Login

Embarrassed by new client

 Post Reply Post Reply
Author
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Status: Offline
Points: 297
Post Options Post Options   Thanks (0) Thanks(0)   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Topic: Embarrassed by new client
    Posted: 31 July 2009 at 8:53am
I had a new client sign up today.  First thing they did was use this free e-mail security check.  I will not post the name of the company, since I don't want to promote them.  Google it, and you will find it if you want to run the test.

Anyway, they send 7 messages to any email address you want.

They test several things:

- Ability to stop SPAM, based on GTUBE signature.
- Ability to stop VIRUSES, based on EICAR signature.

- Ability to block a series of 5 different attachments, which is basically a BAT file I think.

Unfortunately, Spam Filter does not perform so well out of the box.  In order to pass any of the tests you need to:

1) Add a keyword filter on the GTUBE signature (we have done that now)
2) Have antivirus feature enabled (the only test of 7 that worked for us)
3) Add file attachment blacklists (will only help slightly)

Now, not everyone needs or wants to block file attachments - so the test just assumes you want to be doing that.  Fare enough.

What is interesting is they send the batch file as a 'normal' attachment.  If you have a filter on *.bat it gets blocked.

However they also send the same file in four additional messages containing the attachment disguised in different ways.  Even if you have *.bat or *.exe, Spam Filter fails to stop the attachments.

They got through to my inbox, and my email client does recognize the attachments as .bat files and throws up a warning message.

I certainly got embarrassed when the new client contacted me, with 6 of 7 email security tests failing through our system.
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 31 July 2009 at 5:59pm
yapadu,

Thank you for the report.
The GTUBE signature is very specific to Spamassassin, and as we do not use that software in SpamFilter, the test will of course fail. Users are free to add that string in their keywords if they wish, but SpamFilter does not block it by default.

In regards to the emails with attachments that made it thru however, you are perfectly right. They should have been stopped. The filename was obfuscated in such a way that SpamFilter did not recognize it as a valid name and allowed it. This was wrong and we are considering it a serious bug.

We are currently beta-testing SpamFilter v4.1.2.813, which addresses all the tricks used in the above obfuscation, with the exception (so far) of one - the one used in "Test mail 4/7". That will take a bit longer to address.

If you wish to receive the beta before we pre-release it on our website please contact us via email.


Edited by LogSat - 31 July 2009 at 5:59pm
Roberto Franceschetti

LogSat Software

Spam Filter ISP
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Status: Offline
Points: 297
Post Options Post Options   Thanks (0) Thanks(0)   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 11 March 2010 at 8:24pm
Was the issue of these messages getting past spamfilter ever resolved?  I continue to see new clients testing our system and the virus messages still go through from the looks of it.
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Status: Offline
Points: 297
Post Options Post Options   Thanks (0) Thanks(0)   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 11 March 2010 at 11:40pm
I see GFI now has a tester as well (not sure how long they have had it).  They send a bunch of tests, a lot of which are tests against the email client.

But they do send 5 copies of eicar test virus.  Spamfilter fails on all of them Cry
Back to Top
jerbo128 View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 March 2006
Status: Offline
Points: 178
Post Options Post Options   Thanks (0) Thanks(0)   Quote jerbo128 Quote  Post ReplyReply Direct Link To This Post Posted: 24 March 2010 at 9:36am
I recently had a customer bring the same concerns...
Our setup allowed 5 of the 7 emails, including the one with the virus attached. (and we use the virus filtering plugin Confused )
 
Of the others, the .bat attachment was blocked, a couple came in without any attachment showing in outlook, and a couple came in with an attachment named to another extension.
 
So Roberto, can you please provide some input here?
 
Cheers,
 
Jeremy
 
 
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 24 March 2010 at 5:49pm
The original post regarded issues with SpamFilter's inability to match filenames/extensions specified in the "Attachment filter" when the filename is obfuscated in the email's mime extensions. We addressed all the obfuscations except one type which is still pending. This however should not have anything to do with the antivirus plugin. Infected files (including of course the eicar test signature) should be stopped regardless of what the filename is.

If this is not occurring, can you please (both Jerbo and Yapadu) zip and email us SpamFilter's activity logfile for a day this happened, also including your SpamFilter.ini file, and the to/from email addresses used for the test, so we can locate them in the logs? I'll send you both a PM with our FTP site login for you to upload the files if they are over 8MB in size.
Roberto Franceschetti

LogSat Software

Spam Filter ISP
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Status: Offline
Points: 297
Post Options Post Options   Thanks (0) Thanks(0)   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 26 March 2010 at 3:19am
I was the original poster of this last year.  I just ran the test again, against a domain protected by spamfilter and to a gmail account.

The testing service sends 7 messages, just like they did last year.  I tested gmail first.

gmail allowed 3/7, 6/7 and 7/7 through.

My spamfilter did better than a year ago, but strangely the virus test got through to my outlook client.

So spamfilter did not stop 2/7 and 4/7.  2/7 is the test virus, which my system should be stopping as I have the virus module.  I will do some more testing, and as Roberto mentioned above 4/7 is still a known issue.
Back to Top
RBarrow View Drop Down
Groupie
Groupie
Avatar

Joined: 22 September 2005
Status: Offline
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote RBarrow Quote  Post ReplyReply Direct Link To This Post Posted: 28 December 2012 at 4:20pm
We are running 4.50.31 and these 7 messages are still getting through the system.  Are there settings I need to change to get this addressed?

Seems the last activity on the thread was > 2 yrs...but still passing same test emails

Roy
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 28 December 2012 at 11:01pm
We were able to duplicate this issue. There appears to have been a regression error with the new SpamFilter v4.5.x that removed the fix that was added in SpamFilter v4.1.2.813. We'll have this re-fixed shortly.

Please note that the fix did not handle the specific trick employed in the "Test mail 4/7", and that the fake spam in "Test mail 3/7" will also not be blocked by SpamFilter as it is not a real spam email. We do not use SpamAssassin and thus that specific signature is meaningless to SpamFilter.
Roberto Franceschetti

LogSat Software

Spam Filter ISP
Back to Top
RBarrow View Drop Down
Groupie
Groupie
Avatar

Joined: 22 September 2005
Status: Offline
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote RBarrow Quote  Post ReplyReply Direct Link To This Post Posted: 28 December 2012 at 11:23pm
Thanks for checking! We will look for the next build.
 
Roy
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 29 December 2012 at 11:57am
RBarrow,

As the fix was already prepared and was very straightforward, we've already re-patched the previous SpamFilter v4.5.0.62 with it. The fixed version (v4.5.0.63) is now available in the registered user area.

Thanks for re-reporting this!
Roberto Franceschetti

LogSat Software

Spam Filter ISP
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.160 seconds.