Postby administrator » Fri, 16 Apr 2004 08:29:02 GMT

I have observed that most virus mail (99% plus) is sent directly from the 
infected machine to the recipient mail server using SMTP server software  
built in to the virus. If a Sendmail server is only supposed to receive mail 
that is forwarded from another server, would I be correct in assuming the first 
packet after the DATA statement should always start with "Received: from", and 
that anything else would be virus or "unauthorized" traffic.

There does not appear to be any specific order with the rest of the header 
information, but the relay info at the top always appears to start this way. 
Just as with Spam, the engine could add false relay information, but such does 
not appear to be the case at present time, and I want to use this to block the 
current crop of nasties.

Any comments?

J.A. Coutts

Re: Block on Relay Data?

Postby Andrzej Adam Filip » Mon, 19 Apr 2004 20:34:35 GMT

1) There are many MTAs on the net, some are "broken" in incredible ways 
=> expect some false positives (very small number for most sites).

2) You suggestion would be easy to implement in milter
(e.g. mimedefang).

3) It will be very easy for viral worms to add Received: header and pass 
the  check

