Re: Virus warnings originating from the list

From: Willy Tarreau <w#1wt.eu>
Date: Thu, 30 Dec 2010 16:22:27 +0100


Hi Karl,

On Thu, Dec 30, 2010 at 05:24:08PM +1100, Karl Kloppenborg wrote:
> Hey guys,
>
> Our mailserver keeps popping its head up and crying about someone on the list with a virus infection:
>
> ----------------------------------
> VIRUS ALERT
>
> Our content checker found
> viruses: Suspect.DoubleExtension-zippwd-9, Worm.Mydoom.M
>
> in an email to you from probably faked sender:
> ?@[88.191.124.161]
> claiming to be: <haproxy+bounces-6752-karl=crucialp.com#formilux.org>
>
> Content type: Virus
> Our internal reference code for your message is 15320-02/7TgmtDhTpGW9
>
> First upstream SMTP client IP address: [88.191.124.161] flx02.formilux.org
> According to a 'Received:' trace, the message apparently originated at:
> [88.191.124.161], flx02.formilux.org flx02.formilux.org [127.0.0.1]
(...)

Strange, I don't recall having noticed any such message. Maybe they're simply deleted before reaching me, but I don't think so as I'm not performing any filtering on the ML at home.

How many of them do you get a day ?

Willy Received on 2010/12/30 16:22

This archive was generated by hypermail 2.2.0 : 2010/12/30 16:30 CET