Re: [Exim] Exim + virus-scanning

Página superior
Eliminar este mensaje
Responder a este mensaje
Autor: Mike Weller
Fecha:  
A: Dave Temple
Cc: exim-users
Asunto: Re: [Exim] Exim + virus-scanning
Dave Temple wrote:
> Mmm, this is odd, perhaps there is something I have missed. I just deliverately
> sent a copy of SirCam (god knows I have enough examples of it to play with!)


Yes, I have a bunch of those save up too! :-) Unfortunately, some ppl
at our company use hotmail, and get infected anyways, despite my
efforts to block it on the company server. Luckily, it's quickly
contained since they use our exim server as the smtp server.

I have some new information. For some reason, the "$pipe_addresses"
only expands properly for remote users, and not local users.

command = "/usr/sbin/scanmails -f ${sender_address} -d ${pipe_addresses}"

The $pipe_addresses only revealed 1 local address when I emailed to 2
local addresses.

However, when I ran the test to 2 remote users, scanmails DOES receive
2 arguments:

scan.26725
::::::::::::::
-f weller@??? -d test3@??? test4@???

syslog error:

Aug 8 13:00:11 zyvex exim[26723]: 2001-08-08 13:00:11 15UXco-0006x0-00 ** test3@??? R=vircheck T=scanmails_remote: Child process of scanmails_remote transport returned 2 from command: /usr/sbin/scanmails
Aug 8 13:00:11 zyvex exim[26723]: 2001-08-08 13:00:11 15UXco-0006x0-00 ** test4@??? R=vircheck T=scanmails_remote: Child process of scanmails_remote transport returned 2 from command: /usr/sbin/scanmails

I believe I have to upgrade to the PERL version, because it doesn't
accept multiple recipients. This would explain "error 2".

I'll let you know if it worked.

> Incidently, when you look at your Exim logs you can usually spot when there are
> multiple recipients down one transport instance without having to change your
> script. You get lines with <= in them to indicate the sender, and => to
> indicate the first recipient per transport, then -> to indicate additional


Ya, I did notice some '->''s for the first time since I made that
change yesterday, except it only happens to remote users... The ->'s
are immediately followed with **'s (output above).


-- 
Michael J. Weller, M.Sc.               office: (972) 235-7881 x.242
weller@???                         cell: (214) 616-6340
Zyvex Corp., 1321 N Plano           facsimile: (972) 235-7882    
Richardson, TX 75081                      icq: 6180540