domino
20th August 2005, 02:42
I went over to http://www.webmail.us/testvirus and sent myself some eicar. I received the tests but some tests may have gotten though and some derivery errors also occured which i would like to resolve.
Mail Delivery error:
From: Mail Delivery System
Subject: Undelivered Mail Returned to Sender
This is the Postfix program at host linux.domain.com.
I'm sorry to have to inform you that your message could not be be delivered to one or more recipients. It's attached below.
For further assistance, please send mail to <postmaster>
If you do so, please include this problem report. You can delete your own text from the attached returned message.
The Postfix program
<tester@testvirus.org>: host mx1.emailsrvr.com[207.xxx.xxx.xxx] said: 554 5.1.8
<domain_username@linux.domain.com>: Sender address
rejected: Domain not found (in reply to RCPT TO command)
Tests that went undetected:
Test #5: EICAR virus sent using BinHex encoding (this is a rarely used Macintosh mail format)
Test #15: No information because a resident AV (NOD32) caught it even though I turn it off.
Test #16: EICAR virus hidden using the "CR Vulnerability" *
Test #18: EICAR virus within ZIP file hidden using the "Blank Folding Vulnerability"
Test #23: (Non-Virus): Test for the "Partial (Fragmented) Vulnerability". This does not include the EICAR virus, however your mail server should still block this since a virus can use this technique to break itself into multiple emails, bypassing virus scanners, and reassembling itself in your inbox. **
Test #24: (Non-Virus): Attachment with a CLSID extension which may hide the real file extension. This does not include the EICAR virus, however your mail server should still block this since the CLSID technique can be used to hide the true extension of a malicious file. ***
The "Undelivered Mail" is most important to me since it uses alot of resources and it will also solve some Undelivered Mail errors not related to the above tests. However i'm a bit conserned about the other tests that got though.
Mail Delivery error:
From: Mail Delivery System
Subject: Undelivered Mail Returned to Sender
This is the Postfix program at host linux.domain.com.
I'm sorry to have to inform you that your message could not be be delivered to one or more recipients. It's attached below.
For further assistance, please send mail to <postmaster>
If you do so, please include this problem report. You can delete your own text from the attached returned message.
The Postfix program
<tester@testvirus.org>: host mx1.emailsrvr.com[207.xxx.xxx.xxx] said: 554 5.1.8
<domain_username@linux.domain.com>: Sender address
rejected: Domain not found (in reply to RCPT TO command)
Tests that went undetected:
Test #5: EICAR virus sent using BinHex encoding (this is a rarely used Macintosh mail format)
Test #15: No information because a resident AV (NOD32) caught it even though I turn it off.
Test #16: EICAR virus hidden using the "CR Vulnerability" *
Test #18: EICAR virus within ZIP file hidden using the "Blank Folding Vulnerability"
Test #23: (Non-Virus): Test for the "Partial (Fragmented) Vulnerability". This does not include the EICAR virus, however your mail server should still block this since a virus can use this technique to break itself into multiple emails, bypassing virus scanners, and reassembling itself in your inbox. **
Test #24: (Non-Virus): Attachment with a CLSID extension which may hide the real file extension. This does not include the EICAR virus, however your mail server should still block this since the CLSID technique can be used to hide the true extension of a malicious file. ***
The "Undelivered Mail" is most important to me since it uses alot of resources and it will also solve some Undelivered Mail errors not related to the above tests. However i'm a bit conserned about the other tests that got though.