May 16, 2002 John Bijnens is a CAM/CAM engineer in the KHLim - Dep. IWT which is some kind of technical university in Belgium. He gives training in Pro/E and also writes CNC postprocessors (all development is done on OS/2.) If you have a comment about the content of this article, please feel free to vent in the OS/2 eZine discussion forums. There is also a Printer Friendly version of this page. |
|
Advanced Virus Filtering with Weasel
A few issues ago I talked about a simple filter I wrote for the mail server Weasel to scan incoming emails for viruses using 'Norman Virus Control (NVC)' (click here to read this article.)
| |||||||||||
InstallationYou need to have Weasel 1.40 or higher installed for the filter to work. You can download Weasel from the following URL : eepjm.newcastle.edu.au/os2/weasel.html. You can download the complete filter package from the ftp server of Cel Kunststoffen.You need to install the following software and copy some files into the mailroot directory of Weasel.
Now configure the filter in the Weasel Setup program.
Don't forget to check the option 'Serialize filter operations'. Create an email account 'Contaminated'. All infected emails will be copied into this account so that you can examine them more closely if you want to. UsageWhen an infected email is sent to you and processed by Weasel, you'll receive a warning message of your mail server like this:This is an automated email message. Please don't reply. The mail server of Cel Kunststoffen has intercepted an email addressed to you that contained a virus by using Norman Virus Control for OS/2. Following information has been extracted from this email and may help you identify the sender so that you can warn him that his PC is infected. -- Server info -- Arrived at server from : John.Bijnens@celkutstoffen.khlim.be The server has already sent a warning email to this user -- Info from infected email -- Return-Path : John.Bijnens@celkutstoffen.khlim.be Reply-To : - From : - Date : Mon, 15 Apr 2002 01:00:08 +0200 (MET DST) For : jbijnens Subject : - - Virusname : 'W32/Magistr.A@mm' It can take a while (about 5 minutes) before the warning message is actually sent by Weasel after the filter has been executed.
The sender of the infected email will receive a warning message like this one:
RemarkIf you experience problems with Norman Virus Control v5.x for OS/2, i.e. that the command line utility nvcc.exe doesn't work properly and gives warnings on completely innocent files, you need an update of the file Nlog5.dll. This file can be found in the directory \norman\nvc\bin. Normally this should have been distributed through the automatic internet updates of Norman. If this is not the case (you can verify this by checking the file size and the date/time stamps of the file: 24/04/02 16:05 66.198 31 Nlog5.Dll) you can also download it from our ftpserver. |
|||||||||||||
|