Spam Filter ISP Support Forum

  New Posts New Posts RSS Feed: Embarrassed by new client
  FAQ FAQ  Forum Search   Register Register  Login Login

Embarrassed by new client

 Post Reply Post Reply
Author
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Online Status: Offline
Posts: 146
Post Options Post Options   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Topic: Embarrassed by new client
    Posted: 31 July 2009 at 8:53am
I had a new client sign up today.  First thing they did was use this free e-mail security check.  I will not post the name of the company, since I don't want to promote them.  Google it, and you will find it if you want to run the test.

Anyway, they send 7 messages to any email address you want.

They test several things:

- Ability to stop SPAM, based on GTUBE signature.
- Ability to stop VIRUSES, based on EICAR signature.

- Ability to block a series of 5 different attachments, which is basically a BAT file I think.

Unfortunately, Spam Filter does not perform so well out of the box.  In order to pass any of the tests you need to:

1) Add a keyword filter on the GTUBE signature (we have done that now)
2) Have antivirus feature enabled (the only test of 7 that worked for us)
3) Add file attachment blacklists (will only help slightly)

Now, not everyone needs or wants to block file attachments - so the test just assumes you want to be doing that.  Fare enough.

What is interesting is they send the batch file as a 'normal' attachment.  If you have a filter on *.bat it gets blocked.

However they also send the same file in four additional messages containing the attachment disguised in different ways.  Even if you have *.bat or *.exe, Spam Filter fails to stop the attachments.

They got through to my inbox, and my email client does recognize the attachments as .bat files and throws up a warning message.

I certainly got embarrassed when the new client contacted me, with 6 of 7 email security tests failing through our system.
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Online Status: Offline
Posts: 3659
Post Options Post Options   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 31 July 2009 at 5:59pm
yapadu,

Thank you for the report.
The GTUBE signature is very specific to Spamassassin, and as we do not use that software in SpamFilter, the test will of course fail. Users are free to add that string in their keywords if they wish, but SpamFilter does not block it by default.

In regards to the emails with attachments that made it thru however, you are perfectly right. They should have been stopped. The filename was obfuscated in such a way that SpamFilter did not recognize it as a valid name and allowed it. This was wrong and we are considering it a serious bug.

We are currently beta-testing SpamFilter v4.1.2.813, which addresses all the tricks used in the above obfuscation, with the exception (so far) of one - the one used in "Test mail 4/7". That will take a bit longer to address.

If you wish to receive the beta before we pre-release it on our website please contact us via email.


Edited by LogSat - 31 July 2009 at 5:59pm
Roberto Franceschetti
LogSat Software
Spam Filter ISP
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Online Status: Offline
Posts: 146
Post Options Post Options   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 11 March 2010 at 8:24pm
Was the issue of these messages getting past spamfilter ever resolved?  I continue to see new clients testing our system and the virus messages still go through from the looks of it.
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Online Status: Offline
Posts: 146
Post Options Post Options   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 11 March 2010 at 11:40pm
I see GFI now has a tester as well (not sure how long they have had it).  They send a bunch of tests, a lot of which are tests against the email client.

But they do send 5 copies of eicar test virus.  Spamfilter fails on all of them Cry
Back to Top
jerbo128 View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 March 2006
Online Status: Offline
Posts: 175
Post Options Post Options   Quote jerbo128 Quote  Post ReplyReply Direct Link To This Post Posted: 24 March 2010 at 9:36am
I recently had a customer bring the same concerns...
Our setup allowed 5 of the 7 emails, including the one with the virus attached. (and we use the virus filtering plugin Confused )
 
Of the others, the .bat attachment was blocked, a couple came in without any attachment showing in outlook, and a couple came in with an attachment named to another extension.
 
So Roberto, can you please provide some input here?
 
Cheers,
 
Jeremy
 
 
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Online Status: Offline
Posts: 3659
Post Options Post Options   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 24 March 2010 at 5:49pm
The original post regarded issues with SpamFilter's inability to match filenames/extensions specified in the "Attachment filter" when the filename is obfuscated in the email's mime extensions. We addressed all the obfuscations except one type which is still pending. This however should not have anything to do with the antivirus plugin. Infected files (including of course the eicar test signature) should be stopped regardless of what the filename is.

If this is not occurring, can you please (both Jerbo and Yapadu) zip and email us SpamFilter's activity logfile for a day this happened, also including your SpamFilter.ini file, and the to/from email addresses used for the test, so we can locate them in the logs? I'll send you both a PM with our FTP site login for you to upload the files if they are over 8MB in size.
Roberto Franceschetti
LogSat Software
Spam Filter ISP
Back to Top
yapadu View Drop Down
Senior Member
Senior Member


Joined: 12 May 2005
Online Status: Offline
Posts: 146
Post Options Post Options   Quote yapadu Quote  Post ReplyReply Direct Link To This Post Posted: 26 March 2010 at 3:19am
I was the original poster of this last year.  I just ran the test again, against a domain protected by spamfilter and to a gmail account.

The testing service sends 7 messages, just like they did last year.  I tested gmail first.

gmail allowed 3/7, 6/7 and 7/7 through.

My spamfilter did better than a year ago, but strangely the virus test got through to my outlook client.

So spamfilter did not stop 2/7 and 4/7.  2/7 is the test virus, which my system should be stopping as I have the virus module.  I will do some more testing, and as Roberto mentioned above 4/7 is still a known issue.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.063 seconds.

Spam Filter ISP - Copyright © 2002-2010 LogSat Software LLC - PO BOX 916340 Longwood, FL 32791 USA

 Sales: sales@LogSat.com - Support: support@LogSat.com - Tel. (sales only): +1 407-650-3008