Koozali.org: home of the SME Server

Executible attachments patterns used by the email file attachments blocker

Offline brianr

  • *
  • 990
  • +2/-0
Can someone point me to something I can read so that will tell me how the patterns in the Email Settings/Email Filters Server Manager page work and can be produced?

We recently had a "zip" file come through that turned out to be a scr file masquerading as a pdf file.  It left us with a small visitor on the PC!

Cheers  Brian
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........


Offline brianr

  • *
  • 990
  • +2/-0
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #3 on: February 03, 2015, 09:38:41 PM »
brianr

Some new zip signatures were added to the underlying code recently, perhaps you need to enable those in server manager Email panel.
If you find new signatures, please raise a bug report so they can be added to the mail patterns database.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #4 on: February 03, 2015, 10:07:49 PM »
an idea could be to share (we should study a way) signatures.. like AV ones

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #5 on: February 03, 2015, 10:18:31 PM »
Stefano

Quote
an idea could be to share (we should study a way) signatures.. like AV ones

Well lodging a new feature request in bugzilla & submitting a new signature would get those signatures into the mail patterns database.
File types do not change often, so it is not a situation like AV where daily signature updates are needed.
Those recent zip file signatures were the first ones I was aware of in many years.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #6 on: February 03, 2015, 10:22:55 PM »
I had a cryptolocker email last week.. attach was a .cab file

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #7 on: February 03, 2015, 10:47:43 PM »
Stefano

I am not sure of the point you are making.
If you do not want to receive .cab files, then block them by creating a mail pattern & add it to your servers database.

Quote
I had a cryptolocker email last week.. attach was a .cab file
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline brianr

  • *
  • 990
  • +2/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #8 on: February 03, 2015, 11:09:37 PM »
brianr

Some new zip signatures were added to the underlying code recently, perhaps you need to enable those in server manager Email panel.
If you find new signatures, please raise a bug report so they can be added to the mail patterns database.

I do have all the patterns enabled already on this system. I'll certainly do as you say if something useful emerges.
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline brianr

  • *
  • 990
  • +2/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #9 on: February 05, 2015, 01:15:38 PM »
Added bug as follows with new mail pattern.

http://bugs.contribs.org/show_bug.cgi?id=8833

Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline raem

  • *
  • 3,972
  • +4/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #10 on: February 06, 2015, 02:02:26 AM »
brianr

Quote
Added bug as follows with new mail pattern.
http://bugs.contribs.org/show_bug.cgi?id=8833

Well I just checked bug 8717 & bug 8718 and that signature (or a shorter version of it)
UEsDBBQDA
was already added to the mailpatterns database

Bug 8718 was verified & fixed in
e-smith-email-5_4_0-9_el6_sme sme9

It looks like that rpm is still sitting in smeupdates-testing repo
http://distro.ibiblio.org/smeserver/releases/9/smeupdates-testing/i386/RPMS/


Bug 8717 was verified & fixed in
e-smith-email-5_2_0-26_el5_sme sme8

It looks like that rpm is still sitting in smetest repo
http://distro.ibiblio.org/smeserver/releases/8/smetest/i386/RPMS/

Looks like the next step(s) to move these to the smeupdates repo never happened.

You could install the e-smith-email rpm from the repo mentioned above & see how you go, you will get an extra signature as well
UEsDBBQAC

For sme9 do
yum update e-smith-email --enablerepo=smeupdates-testing
signal-event email-update
...

Offline brianr

  • *
  • 990
  • +2/-0
Re: Executible attachments patterns used by the email file attachments blocker
« Reply #11 on: February 06, 2015, 10:45:36 AM »
For sme9 do
yum update e-smith-email --enablerepo=smeupdates-testing
signal-event email-update

and for SME8:

yum update --enablerepo=smetest e-smith-email
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........