Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-12-2010, 09:41 AM
Special Member
 
Posts: 124
Default Question about eicar AV test

I thought I'd see what happens when an incoming email contains a virus. I found several mentions of eicar, so I went to their site and downloaded the files. However, trying to send these from either a hotmail or mobileme account didn't work as hotmail won't attach the files and mobileme will send but the email never arrives (guess Apple has AV filter).

I found a website (Send EICAR Test E-Mail to Check Reability of Your Anti-Virus E-Mail Protection) that can send you the eicar files. I tried these two:

Quote:
Clean notification e-mail (to confirm that all your test mails were send as your mail protection software should filter them out)

eicar.com (standard anti-virus test file, recomented for usual test of your e-mail anti-virus protection)
The first one I receive because it's just an email, but the second one never arrives. I looked in clamd.log, mailbox.log and zimbra.log and nothing.

However, when I try sending this one:

Quote:
eicarpasswd.zip (new! - zip compressed eicar.com with password)
I receive the email and can see that the zip file has been detected as a virus and is quarantined!

Is there some intermediary that is stopping the email from the site with eicar.com?

Also, do I manually need to clear the /opt/zimbra/data/amavisad/quarantine folder or is there a cron job that does it?
EDIT: Just found the cronjob that clears the folder everyday at 01:00.

Last edited by yonatan; 12-12-2010 at 10:30 AM..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.