[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Bouncing Email's with Attachements W32.Sircam.Worm@mm



> On Wed, 1 Aug 2001, Bill Gunning wrote:
>
> >
> > I am currently getting hit with 30 to 50 email's a day
> > that have the 'W32.Sircam.Worm@mm' virus attached to them.
> >
> > Is their a way to bounch/ Not accept any email's with
> > attachements to certain email accounts i.e., our
> > sales@xxxxxxxxxx or info@xxxxxxxxxxx
>
> I found this a while back, tho i havn't had a chance to try t out, looks
> promising tho...
>
> ftp://ftp.rubyriver.com/pub/jhardin/antispam/sanitizer-configuration.html
>
> (web page)
>
> > Also my clients are getting hit with 3 to 5 of these
> > email's a day. And I would like to setup an email
> > only account that does not accept email attachements
> > for all of my clients, and then setup another user
> > account that can accept email attachements.
>
> Says it can be used account by account or systemwide....

Well to catch sircam as it currently exists you can put this into
etc/procmailrc
---------------cut below this line----------------
:0:sircam.lock
* B ?? Hi\! How are you(\?|=3F)
* 1^0 B ?? I send you this file in order to have your advice
* 1^0 B ?? I hope you like the file that I send( t)?o you
* 1^0 B ?? This is the file with the information that you ask for
* B ?? See you later(\.|=2E) Thanks
	/home/tmp/sircam
#That could also be /dev/null instead

Regards & HTH
-Colin
--
Colin J. Raven