Cheery Цитата: а вирусы вообще посылаются кому то? eicar - ом пробовал тестировать?
Конечно посылаются, около сотни в день. EICAR -ом тестировался, все как положено, и в логах запись есть и уведомление пришло. Но!!! EICAR то несколько по другому через почтовик проходит, его сам почтовик генерит и в очередь на отправку запускает. То есть отсутствует фаза приема письма извне и из локалки.
вот здесь выдержка из лога EICAR - теста [more]
Tue 2006-11-07 14:25:28: [RAW] Converting <C:\MDAEMON\RAWFILES\md50000015474.raw>
Tue 2006-11-07 14:25:28: [RAW] From: postmaster@xxxxxxxx.com
Tue 2006-11-07 14:25:28: [RAW] To: admin@xxxxxxxx.com
Tue 2006-11-07 14:25:28: [RAW] Subject: EICAR Test Message
Tue 2006-11-07 14:25:28: [RAW] Message-ID: <MDAEMON0266200611071425.AA2528773@xxxxxxxx.com>
Tue 2006-11-07 14:25:28: [RAW] Encoding attachment file [C:\MDaemon\Temp\eicar.com]
Tue 2006-11-07 14:25:28: [RAW] Conversion completed (created c:\mdaemon\localq\md75000673550.msg)
Tue 2006-11-07 14:25:28: ----------
Tue 2006-11-07 14:25:29: SecurityPlus AntiVirus processing c:\mdaemon\localq\md75000673550.msg...
Tue 2006-11-07 14:25:29: > Message return-path:
Tue 2006-11-07 14:25:29: > Message from: postmaster@xxxxxxxx.com
Tue 2006-11-07 14:25:29: > Message to: admin@xxxxxxxx.com
Tue 2006-11-07 14:25:29: > Message subject: EICAR Test Message
Tue 2006-11-07 14:25:29: > Message ID: <MDAEMON0266200611071425.AA2528773@xxxxxxxx.com>
Tue 2006-11-07 14:25:29: Start SecurityPlus AntiVirus results
Tue 2006-11-07 14:25:29: * eicar.com is infected by EICAR-Test-File
Tue 2006-11-07 14:25:29: * eicar.com was removed from message
Tue 2006-11-07 14:25:29: * Total attachments scanned : 3 (including multipart/alternatives and message body)
Tue 2006-11-07 14:25:29: * Total attachments infected : 1
Tue 2006-11-07 14:25:29: * Total attachments disinfected: 0
Tue 2006-11-07 14:25:29: * Total errors while scanning : 0
Tue 2006-11-07 14:25:29: * Total attachments removed : 1
Tue 2006-11-07 14:25:30: * Virus notification sent to postmaster@xxxxxxxx.com (sender)
Tue 2006-11-07 14:25:30: * Virus notification sent to postmaster@xxxxxxxx.com (admin)
Tue 2006-11-07 14:25:30: End of SecurityPlus AntiVirus results
Tue 2006-11-07 14:25:30: ----------
[/more]
а тут лог сессии письма с вирусом [more]
Tue 2006-11-07 01:18:07: Session 8802; child 1; thread 2168
Tue 2006-11-07 01:16:23: Accepting SMTP connection from [212.152.42.154 : 3335]
Tue 2006-11-07 01:16:23: Performing PTR lookup (154.42.152.212.IN-ADDR.ARPA)
Tue 2006-11-07 01:16:23: * D=154.42.152.212.IN-ADDR.ARPA TTL=(980) PTR=[host42-154.dialup.inetcomm.ru]
Tue 2006-11-07 01:16:23: * Gathering A records...
Tue 2006-11-07 01:16:23: ---- End PTR results
Tue 2006-11-07 01:16:23: --> 220 xxxxxxxx.com ESMTP MDaemon 9.5.1; Tue, 07 Nov 2006 01:16:23 +0300
Tue 2006-11-07 01:16:26: <-- HELO 605beea85ca6453.com
Tue 2006-11-07 01:16:26: Performing IP lookup (605beea85ca6453.com)
Tue 2006-11-07 01:16:26: * Error: Name server reports domain name unknown
Tue 2006-11-07 01:16:26: ---- End IP lookup results
Tue 2006-11-07 01:16:26: --> 250 xxxxxxxx.com Hello host42-154.dialup.inetcomm.ru, pleased to meet you
Tue 2006-11-07 01:16:28: <-- RSET
Tue 2006-11-07 01:16:28: --> 250 RSET? Well, ok.
Tue 2006-11-07 01:16:31: <-- MAIL FROM:<635CAE34F80DA365CF9@e-xecutive.ru>
Tue 2006-11-07 01:16:31: Performing IP lookup (e-xecutive.ru)
Tue 2006-11-07 01:16:31: * D=e-xecutive.ru TTL=(78) A=[217.74.32.183]
Tue 2006-11-07 01:16:31: * P=010 S=000 D=e-xecutive.ru TTL=(112) MX=[mail.e-xecutive.ru] {217.69.199.138}
Tue 2006-11-07 01:16:31: ---- End IP lookup results
Tue 2006-11-07 01:16:31: Performing SPF lookup (e-xecutive.ru / 212.152.42.154)
Tue 2006-11-07 01:16:31: * Result: none; no SPF record in DNS
Tue 2006-11-07 01:16:31: ---- End SPF results
Tue 2006-11-07 01:16:31: --> 250 <635CAE34F80DA365CF9@e-xecutive.ru>, Sender ok
Tue 2006-11-07 01:16:33: <-- RCPT TO:<personal@xxxxxxxx.com>
Tue 2006-11-07 01:16:33: --> 250 <personal@xxxxxxxx.com>, Recipient ok
Tue 2006-11-07 01:16:34: <-- DATA
Tue 2006-11-07 01:16:34: Creating temp file (SMTP): c:\mdaemon\temp\30\md50000000590.tmp
Tue 2006-11-07 01:16:34: --> 354 Enter mail, end with <CRLF>.<CRLF>
Tue 2006-11-07 01:18:04: Message size: 135316 bytes
Tue 2006-11-07 01:18:04: Performing DomainKeys lookup (Sender: 635CAE34F80DA365CF9@e-xecutive.ru)
Tue 2006-11-07 01:18:04: * File: c:\mdaemon\temp\30\md50000000590.tmp
Tue 2006-11-07 01:18:04: * Message-ID: 272112ABAB073A0C1A5@xxxxxxxx.com
Tue 2006-11-07 01:18:04: * Querying for policy: e-xecutive.ru
Tue 2006-11-07 01:18:04: * Querying: _domainkey.e-xecutive.ru ...
Tue 2006-11-07 01:18:04: * DNS: Name server reports domain name unknown
Tue 2006-11-07 01:18:04: * Result: pass
Tue 2006-11-07 01:18:04: ---- End DomainKeys results
Tue 2006-11-07 01:18:04: Performing DKIM lookup
Tue 2006-11-07 01:18:04: * File: c:\mdaemon\temp\30\md50000000590.tmp
Tue 2006-11-07 01:18:04: * Message-ID: 272112ABAB073A0C1A5@xxxxxxxx.com
Tue 2006-11-07 01:18:04: * Result: neutral
Tue 2006-11-07 01:18:04: ---- End DKIM results
Tue 2006-11-07 01:18:04: Passing message through AntiVirus (Size: 135316)...
Tue 2006-11-07 01:18:05: * Message is infected with Email-Worm.Win32.Scano.gen
Tue 2006-11-07 01:18:05: ---- End AntiVirus results
Tue 2006-11-07 01:18:05: Message refused because it contains a virus
Tue 2006-11-07 01:18:05: --> 554 Sorry, message is infected with Email-Worm.Win32.Scano.gen virus
Tue 2006-11-07 01:18:07: Connection closed
Tue 2006-11-07 01:18:07: SMTP session terminated (Bytes in/out: 135417/372)
Tue 2006-11-07 01:18:07: ----------[/more]
а вот тут лог сессии с вирусом, но с отключенным "Refuse to accept messages that are infected with viruses" и все как с EICAR тестом, в логах все есть, уведомление отправляются [more]Wed 2006-11-08 20:07:41: Session 2912; child 7; thread 504
Wed 2006-11-08 20:07:01: Accepting SMTP connection from [213.184.226.185 : 3727]
Wed 2006-11-08 20:07:01: Performing PTR lookup (185.226.184.213.IN-ADDR.ARPA)
Wed 2006-11-08 20:07:01: * D=185.226.184.213.IN-ADDR.ARPA TTL=(10080) PTR=[d185.dialup.telecom.by]
Wed 2006-11-08 20:07:01: * Gathering A records...
Wed 2006-11-08 20:07:01: * D=d185.dialup.telecom.by TTL=(1440) A=[213.184.226.185]
Wed 2006-11-08 20:07:01: ---- End PTR results
Wed 2006-11-08 20:07:01: --> 220 xxxxxxxx.com ESMTP MDaemon 9.5.2; Wed, 08 Nov 2006 20:07:01 +0300
Wed 2006-11-08 20:07:01: <-- HELO hybycrisy.com
Wed 2006-11-08 20:07:01: Performing IP lookup (hybycrisy.com)
Wed 2006-11-08 20:07:02: * Error: Name server reports domain name unknown
Wed 2006-11-08 20:07:02: ---- End IP lookup results
Wed 2006-11-08 20:07:02: --> 250 xxxxxxxx.com Hello d185.dialup.telecom.by, pleased to meet you
Wed 2006-11-08 20:07:02: <-- RSET
Wed 2006-11-08 20:07:02: --> 250 RSET? Well, ok.
Wed 2006-11-08 20:07:02: <-- MAIL FROM:<sales@divers-motors.ru>
Wed 2006-11-08 20:07:02: Performing IP lookup (divers-motors.ru)
Wed 2006-11-08 20:07:03: * P=030 S=000 D=divers-motors.ru TTL=(1157) MX=[mail.divers-motors.ru] {212.114.13.1}
Wed 2006-11-08 20:07:03: ---- End IP lookup results
Wed 2006-11-08 20:07:03: Performing SPF lookup (divers-motors.ru / 213.184.226.185)
Wed 2006-11-08 20:07:03: * Result: none; no SPF record in DNS
Wed 2006-11-08 20:07:03: ---- End SPF results
Wed 2006-11-08 20:07:03: --> 250 <sales@divers-motors.ru>, Sender ok
Wed 2006-11-08 20:07:03: <-- RCPT TO:<savina@xxxxxxxx.com>
Wed 2006-11-08 20:07:03: --> 250 <savina@xxxxxxxx.com>, Recipient ok
Wed 2006-11-08 20:07:03: <-- DATA
Wed 2006-11-08 20:07:03: Creating temp file (SMTP): c:\mdaemon\temp\md50000002885.tmp
Wed 2006-11-08 20:07:03: --> 354 Enter mail, end with <CRLF>.<CRLF>
Wed 2006-11-08 20:07:35: Message size: 135620 bytes
Wed 2006-11-08 20:07:35: Performing DomainKeys lookup (Sender: sales@divers-motors.ru)
Wed 2006-11-08 20:07:35: * File: c:\mdaemon\temp\md50000002885.tmp
Wed 2006-11-08 20:07:35: * Message-ID: 9B627F92F87F492B9B4@xxxxxxxx.com
Wed 2006-11-08 20:07:35: * Querying for policy: divers-motors.ru
Wed 2006-11-08 20:07:35: * Querying: _domainkey.divers-motors.ru ...
Wed 2006-11-08 20:07:35: * DNS: Name server has no records of the requested type for that domain
Wed 2006-11-08 20:07:35: * Result: pass
Wed 2006-11-08 20:07:35: ---- End DomainKeys results
Wed 2006-11-08 20:07:35: Performing DKIM lookup
Wed 2006-11-08 20:07:35: * File: c:\mdaemon\temp\md50000002885.tmp
Wed 2006-11-08 20:07:35: * Message-ID: 9B627F92F87F492B9B4@xxxxxxxx.com
Wed 2006-11-08 20:07:35: * Result: neutral
Wed 2006-11-08 20:07:35: ---- End DKIM results
Wed 2006-11-08 20:07:35: Passing message through Spam Filter (Size: 135620)...
Wed 2006-11-08 20:07:37: * 0.1 FORGED_RCVD_HELO Received: contains a forged HELO
Wed 2006-11-08 20:07:37: * 1.0 BAYES_60 BODY: Bayesian spam probability is 60 to 80%
Wed 2006-11-08 20:07:37: * [score: 0.6033]
Wed 2006-11-08 20:07:37: * 0.0 HTML_MESSAGE BODY: HTML included in message
Wed 2006-11-08 20:07:37: * 0.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Wed 2006-11-08 20:07:37: * 0.2 MIME_BASE64_BLANKS RAW: Extra blank lines in base64 encoding
Wed 2006-11-08 20:07:37: * 2.7 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
Wed 2006-11-08 20:07:37: * 4.1 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
Wed 2006-11-08 20:07:37: ---- End SpamAssassin results
Wed 2006-11-08 20:07:37: Spam Filter score/req: 8.10/15.0
Wed 2006-11-08 20:07:37: Message creation successful: c:\mdaemon\inbound\md50000003220.msg
Wed 2006-11-08 20:07:37: --> 250 Ok, message saved <Message-ID: 9B627F92F87F492B9B4@xxxxxxxx.com>
Wed 2006-11-08 20:07:41: Connection closed
Wed 2006-11-08 20:07:41: SMTP session successful (Bytes in/out: 135702/352)
Wed 2006-11-08 20:07:41: ----------
Wed 2006-11-08 20:07:41: Processing message: c:\mdaemon\inbound\md50000003220.msg
Wed 2006-11-08 20:07:41: From: sales@divers-motors.ru; Recipient: savina@xxxxxxxx.com; Size: 135620; Message: c:\mdaemon\localq\md50000678758.msg
Wed 2006-11-08 20:07:41: Subject: Re: When you're gonna answer me?
Wed 2006-11-08 20:07:41: Message-ID: 9B627F92F87F492B9B4@xxxxxxxx.com
Wed 2006-11-08 20:07:41: ----------
Wed 2006-11-08 20:07:41: Spam Filter processing c:\mdaemon\localq\md50000678758.msg...
Wed 2006-11-08 20:07:41: > Message return-path: sales@divers-motors.ru
Wed 2006-11-08 20:07:41: > Message from: sales@divers-motors.ru
Wed 2006-11-08 20:07:41: > Message to: savina@xxxxxxxx.com
Wed 2006-11-08 20:07:41: > Message subject: Re: When you're gonna answer me?
Wed 2006-11-08 20:07:41: > Message ID: <9B627F92F87F492B9B4@xxxxxxxx.com>
Wed 2006-11-08 20:07:43: Start SpamAssassin results
Wed 2006-11-08 20:07:43: 9.40 points, 5.00 required
Wed 2006-11-08 20:07:43: * 0.1 FORGED_RCVD_HELO Received: contains a forged HELO
Wed 2006-11-08 20:07:43: * 0.0 HTML_MESSAGE BODY: HTML included in message
Wed 2006-11-08 20:07:43: * 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
Wed 2006-11-08 20:07:43: * [score: 0.9992]
Wed 2006-11-08 20:07:43: * 0.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Wed 2006-11-08 20:07:43: * 0.2 MIME_BASE64_BLANKS RAW: Extra blank lines in base64 encoding
Wed 2006-11-08 20:07:43: * 2.7 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
Wed 2006-11-08 20:07:43: * 4.1 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
Wed 2006-11-08 20:07:43: * -1.3 AWL AWL: From: address is in the auto white-list
Wed 2006-11-08 20:07:43: End SpamAssassin results
Wed 2006-11-08 20:07:43: ----------
Wed 2006-11-08 20:07:43: SecurityPlus AntiVirus processing c:\mdaemon\localq\md50000678758.msg...
Wed 2006-11-08 20:07:43: > Message return-path: sales@divers-motors.ru
Wed 2006-11-08 20:07:43: > Message from: sales@divers-motors.ru
Wed 2006-11-08 20:07:43: > Message to: savina@xxxxxxxx.com
Wed 2006-11-08 20:07:43: > Message subject: [***SPAM*** Score/Req: 09.4/5.0] Re: When you're gonna answer me?
Wed 2006-11-08 20:07:43: > Message ID: <9B627F92F87F492B9B4@xxxxxxxx.com>
Wed 2006-11-08 20:07:43: Start SecurityPlus AntiVirus results
Wed 2006-11-08 20:07:43: * private.hta is infected by Email-Worm.Win32.Scano.gen
Wed 2006-11-08 20:07:43: * Total attachments scanned : 3 (including multipart/alternatives and message body)
Wed 2006-11-08 20:07:43: * Total attachments infected : 1
Wed 2006-11-08 20:07:43: * Total attachments disinfected: 0
Wed 2006-11-08 20:07:43: * Total errors while scanning : 0
Wed 2006-11-08 20:07:43: * Message moved to \quarant\md50000000005.msg
Wed 2006-11-08 20:07:43: * Virus notification sent to postmaster@xxxxxxxx.com (admin)
Wed 2006-11-08 20:07:43: End of SecurityPlus AntiVirus results
Wed 2006-11-08 20:07:43: ----------
[/more]