Mailinglist Archive: opensuse-security (465 mails)

< Previous Next >
AvMailGate does not find Eicar
  • From: Jochen Kaechelin <jk@xxxxxxx>
  • Date: Mon, 3 Dec 2001 07:06:48 +0100
  • Message-id: <200112030606.fB366mr19987@xxxxxxxxxxxxxxxx>
I installes Antivir and AntivirMailGate from
SuSEs original 7.3prof.

antivir is working find and it detects the test-file
from eicar:

checking drive/path (cwd): /home/jochen
/home/jochen/fff
Date: 2.12.2001 Time: 10:10:59 Size: 68
VIRUS: file contains code of the virus 'Eicar-Test-Signatur'

/home/jochen/eicarcom2.zip
Date: 2.12.2001 Time: 23:58:43 Size: 308
VIRUS: file contains a signature of the virus 'Eicar-Test-Signatur'


My /etc/avmailgate.conf looks this way:

user uucp
group uucp
SpoolDir /var/spool/vscan/avmailgate
Postmaster jochen
PidFile_avgated /var/run/avmailgate/avmailgate_d.pid
ListenAddress 192.168.0.1 port 25
SmtpTimeout 300
MaxIncomingConnections 0
MaxMessageSize 0
#MaxRecipientsPerMessage100
#MinFreeBlocks 100
RefuseEmptyMailFrom NO
PidFile_avgatefwd /var/run/avmailgate/avmailgate_fwd.pid
MaxForwarders 3
BlockSuspiciousMime FALSE
ExposeAlerts FALSE
ForwardTo SMTP: localhost port smtp-backdoor

my /etc/sendmail.cf contains the following:
O DaemonPortOptions=Name=MTA,Port=smtp-backdoor

my /etc/services contains the following:

smtp-backdoor 825/tcp # AntiVir MailGate

When I send the attached eicar-test-file AntiVirMailGate
shows no reaction.

When starting with "rcavgate start" /var/log/mail shows the
following:

Dec 3 06:58:15 jochen avgated[19907]: ready to accept connections on
port 25
Dec 3 06:58:16 jochen avmgatefwd[19906]: running in full featured mode

When sending a mail with kmail /var/log/mail shows the following:

Dec 3 07:05:38 jochen sendmail[19982]: fB365c419982: from=jochen,
size=442, class=0, nrcpts=1,
msgid=<200112030605.fB365c419982@xxxxxxxxxxxxxxxx>, relay=localhost
[[UNIX: localhost]]
Dec 3 07:05:39 jochen sendmail[19984]: fB365c419982: to=jk@xxxxxxx,
ctladdr=jochen (500/100), delay=00:00:01, xdelay=00:00:01,
mailer=relay, pri=120442, relay=smtp.wa-p.de [62.67.200.3], dsn=2.0.0,
stat=Sent (ok 1007359540 qp 28590)


Can anyone please help me - it's very urgent for me.
Thanx.

--
WA-P: Programmierung - Beratung - Hosting
Stuttgarter Strasse 3 - D-73033 Goeppingen
Tel. 07161 - 92 95 94 Fax 07161 - 1 36 01
http://internet.wa-p.de - jk@xxxxxxx

< Previous Next >
Follow Ups