1 (edited by stefanogatto 2020-01-25 00:28:14)

Topic: amavis not blocking exe files in rar attachments

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 0.9.9
- Deployed with iRedMail Easy or the downloadable installer? downloadable installer
- Linux/BSD distribution name and version: Debian Jessie
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): NGINX
- Manage mail accounts with iRedAdmin-Pro? no
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Hi all,
I just realized that amavis can't block executables files in rar archives attached to emails. It just mark them UNCHECKED in the logs but let them be delivered.
I read it's not the supposed behavior, but I cannot figure out what to do.... can someone help me?
BR Stefano Gatto

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: amavis not blocking exe files in rar attachments

Please show us related Amavisd log in /var/log/maillog. We need log for troubleshooting.

3 (edited by stefanogatto 2020-02-03 00:08:28)

Re: amavis not blocking exe files in rar attachments

ZhangHuangbin wrote:

Please show us related Amavisd log in /var/log/maillog. We need log for troubleshooting.

My apologies for the delay, I did some research and find that debian doesn't install by default libclamunrar7,  mandatory to expand on the fly and check compressed rar archives
after installing libclamunrar7, amavis started to work and now the compressed executables are checked and banned.
BR

4

Re: amavis not blocking exe files in rar attachments

- Neither Debian 9 or 10 offers "libclamunrar7" package, did you install it from a third-party apt repo?
- Does installing package "unrar-free" fix your issue?

5

Re: amavis not blocking exe files in rar attachments

ZhangHuangbin wrote:

- Neither Debian 9 or 10 offers "libclamunrar7" package, did you install it from a third-party apt repo?
- Does installing package "unrar-free" fix your issue?

My server is still on debian jessie, I had to add non-free repository to install it