Hello,
I'm having trouble getting Amavisd-New to scan for and discard .js files inside of zipped email attachments. Everything is working for blocking .exe files in .zip files but not .js files in .zip email attachments.
I’ve added this in the "### BLOCKED ANYWHERE" section of /etc/amavisd.conf, but zipped .js file attachments are still making their way through:
qr'^\.(exe|js|lha|cab|dll)$',
I also tried adding both of these to the "### BLOCKED ANYWHERE" section and restarting the service but they didn’t help:
qr'^application/x-javascript$'i,
qr'^text/javascript$'i,
An infected .js file in a .zip file that made its way through the email server was luckily blocked by antivirus on my wife’s Mac, so I’d really like to be able to block such files. I can provide an sample of one of the .js files if it would be helpful.
Thanks,
Patrick.
Thanks Mickaël. If a .zip file is corrupt though, would it also be un-zip-able? And would therefore not pose a threat?
Could you share the unzip/Unpackers line with us that you use in your amavisd.conf file please?
Thanks,
Patrick.
From: Mickaël Maillot [mailto:mickael...@gmail.com]
Sent: Friday, May 13, 2016 5:17 AM
To: Maurizio Marini <mau...@datalogica.com>
Cc: Kirchner, Patrick <Kirch...@lakeland.edu>; amavis...@amavis.org
Subject: Re: Can't Block .js files inside of .zip Email Attachments
I just want to warn you because 7zip cannot decode corruption zip and will not even list files in it.