Embarrassed by new client |
Post Reply |
Author | |
yapadu
Senior Member Joined: 12 May 2005 Status: Offline Points: 297 |
Post Options
Thanks(0)
Posted: 31 July 2009 at 8:53am |
I had a new client sign up today. First thing they did was use this free e-mail security check. I will not post the name of the company, since I don't want to promote them. Google it, and you will find it if you want to run the test.
Anyway, they send 7 messages to any email address you want. They test several things: - Ability to stop SPAM, based on GTUBE signature. - Ability to stop VIRUSES, based on EICAR signature. - Ability to block a series of 5 different attachments, which is basically a BAT file I think. Unfortunately, Spam Filter does not perform so well out of the box. In order to pass any of the tests you need to: 1) Add a keyword filter on the GTUBE signature (we have done that now) 2) Have antivirus feature enabled (the only test of 7 that worked for us) 3) Add file attachment blacklists (will only help slightly) Now, not everyone needs or wants to block file attachments - so the test just assumes you want to be doing that. Fare enough. What is interesting is they send the batch file as a 'normal' attachment. If you have a filter on *.bat it gets blocked. However they also send the same file in four additional messages containing the attachment disguised in different ways. Even if you have *.bat or *.exe, Spam Filter fails to stop the attachments. They got through to my inbox, and my email client does recognize the attachments as .bat files and throws up a warning message. I certainly got embarrassed when the new client contacted me, with 6 of 7 email security tests failing through our system. |
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
yapadu,
Thank you for the report. The GTUBE signature is very specific to Spamassassin, and as we do not use that software in SpamFilter, the test will of course fail. Users are free to add that string in their keywords if they wish, but SpamFilter does not block it by default. In regards to the emails with attachments that made it thru however, you are perfectly right. They should have been stopped. The filename was obfuscated in such a way that SpamFilter did not recognize it as a valid name and allowed it. This was wrong and we are considering it a serious bug. We are currently beta-testing SpamFilter v4.1.2.813, which addresses all the tricks used in the above obfuscation, with the exception (so far) of one - the one used in "Test mail 4/7". That will take a bit longer to address. If you wish to receive the beta before we pre-release it on our website please contact us via email.
Edited by LogSat - 31 July 2009 at 5:59pm |
|
yapadu
Senior Member Joined: 12 May 2005 Status: Offline Points: 297 |
Post Options
Thanks(0)
|
Was the issue of these messages getting past spamfilter ever resolved? I continue to see new clients testing our system and the virus messages still go through from the looks of it.
|
|
yapadu
Senior Member Joined: 12 May 2005 Status: Offline Points: 297 |
Post Options
Thanks(0)
|
I see GFI now has a tester as well (not sure how long they have had it). They send a bunch of tests, a lot of which are tests against the email client.
But they do send 5 copies of eicar test virus. Spamfilter fails on all of them |
|
jerbo128
Senior Member Joined: 06 March 2006 Status: Offline Points: 178 |
Post Options
Thanks(0)
|
I recently had a customer bring the same concerns...
Our setup allowed 5 of the 7 emails, including the one with the virus attached. (and we use the virus filtering plugin )
Of the others, the .bat attachment was blocked, a couple came in without any attachment showing in outlook, and a couple came in with an attachment named to another extension.
So Roberto, can you please provide some input here?
Cheers,
Jeremy
|
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
The original post regarded issues with SpamFilter's inability to match filenames/extensions specified in the "Attachment filter" when the filename is obfuscated in the email's mime extensions. We addressed all the obfuscations except one type which is still pending. This however should not have anything to do with the antivirus plugin. Infected files (including of course the eicar test signature) should be stopped regardless of what the filename is.
If this is not occurring, can you please (both Jerbo and Yapadu) zip and email us SpamFilter's activity logfile for a day this happened, also including your SpamFilter.ini file, and the to/from email addresses used for the test, so we can locate them in the logs? I'll send you both a PM with our FTP site login for you to upload the files if they are over 8MB in size.
|
|
yapadu
Senior Member Joined: 12 May 2005 Status: Offline Points: 297 |
Post Options
Thanks(0)
|
I was the original poster of this last year. I just ran the test again, against a domain protected by spamfilter and to a gmail account.
The testing service sends 7 messages, just like they did last year. I tested gmail first. gmail allowed 3/7, 6/7 and 7/7 through. My spamfilter did better than a year ago, but strangely the virus test got through to my outlook client. So spamfilter did not stop 2/7 and 4/7. 2/7 is the test virus, which my system should be stopping as I have the virus module. I will do some more testing, and as Roberto mentioned above 4/7 is still a known issue. |
|
RBarrow
Groupie Joined: 22 September 2005 Status: Offline Points: 45 |
Post Options
Thanks(0)
|
We are running 4.50.31 and these 7 messages are still getting through the system. Are there settings I need to change to get this addressed?
Seems the last activity on the thread was > 2 yrs...but still passing same test emails Roy
|
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
We were able to duplicate this issue. There appears to have been a regression error with the new SpamFilter v4.5.x that removed the fix that was added in SpamFilter v4.1.2.813. We'll have this re-fixed shortly.
Please note that the fix did not handle the specific trick employed in the "Test mail 4/7", and that the fake spam in "Test mail 3/7" will also not be blocked by SpamFilter as it is not a real spam email. We do not use SpamAssassin and thus that specific signature is meaningless to SpamFilter.
|
|
RBarrow
Groupie Joined: 22 September 2005 Status: Offline Points: 45 |
Post Options
Thanks(0)
|
Thanks for checking! We will look for the next build.
Roy
|
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
RBarrow,
As the fix was already prepared and was very straightforward, we've already re-patched the previous SpamFilter v4.5.0.62 with it. The fixed version (v4.5.0.63) is now available in the registered user area. Thanks for re-reporting this!
|
|
Post Reply | |
Tweet
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.160 seconds.