Closed stephdl closed 3 years ago
in 7.9.2009/testing
:
QA
After the upgrade the extended mode is set to false, when oletools finds a macro in the maillog you must have something like this
OLETOOLS(0.00){AutoExec + Suspicious (CheckPrinters_Layout,Shell);}
the extended mode with flags must be disable (see below)
OLETOOLS(0.00){-----AMS;adp_com_Layout;ExecuteExcel4Macro;Chr;Hex Strings;}
On a 7.8.2003 machine.
vi /etc/e-smith/templates/etc/rspamd/local.d/external_services.conf/10base
and changed extended
from true
to false
expand-template /etc/rspamd/local.d/external_services.conf
signal-event nethserver-mail-filter-update
redis-cli -s /var/run/redis-rspamd/rspamd FLUSHDB
All works fine! Nice job @stephdl. Thanks to @filippocarletti for the patience ;-)
in 7.9.2009/testing
:
in 7.9.2009/testing
:
In 7.8.2003/updates: nethserver-mail-2.18.2-1.ns7.src.rpm nethserver-mail-common-2.18.2-1.ns7.noarch.rpm nethserver-mail-disclaimer-2.18.2-1.ns7.noarch.rpm nethserver-mail-filter-2.18.2-1.ns7.noarch.rpm nethserver-mail-getmail-2.18.2-1.ns7.noarch.rpm nethserver-mail-imapsync-2.18.2-1.ns7.noarch.rpm nethserver-mail-ipaccess-2.18.2-1.ns7.noarch.rpm nethserver-mail-p3scan-2.18.2-1.ns7.noarch.rpm nethserver-mail-quarantine-2.18.2-1.ns7.noarch.rpm nethserver-mail-server-2.18.2-1.ns7.noarch.rpm nethserver-mail-smarthost-2.18.2-1.ns7.noarch.rpm
in 7.9.2009/updates
:
The extended mode of oletools can prone to error with false positive, It is better to disable the extended mode by now, we need more time to study and find a better setting rather to only reject if the oletools find a positive macro inside the email
Proposed solution
we need to set the extended to false in the external_services.conf of rspamd
Alternative solutions
rather than simply reject when we found something positive with oletools, we could
make a score, add a score for each symbol found by oletools (something like 3*1) Do not reject when oletools find some flag like suspicious but eventually just add a score.
Additional context
this is what oletools find in a legitimate email