[ale] procmail filter on attachment name?

Eric Melo ericmelo at hackernetwork.com
Fri Aug 22 14:14:42 EDT 2003


1) Yes, its just a comment to the code.
2)a copy of the messege as it is in the mail spool.

=)
|Any trouble, call me =) /me be glad to help.
------------------------------------------------


>Can you break down the sections?  I see you send out a message to the
>offender that they sent you a virus, but where does /tmp/tumb get
>defined, etc?


T>hus spake Eric Melo (ericmelo at hackernetwork.com):

> Yes it is, check script below, make you ajustments.
> ps: if you need more help give a call! 
> Good luck! :)
> ###################################################3
> :0 B
>     * $"filename=.\+(pif|com|exe|bat|lnk|scr)"
> {
>     :0 c
>     |(formail -r -i"From:antivirus" -A"X-Loop: antivirus";\
>     cat /etc/virus.msg)|$SENDMAIL -oi -t
>     /tmp/tumb
> 
>     :0
>     /var/spool/procmail/${LOGNAME}.virus
>     /tmp/virus-tumb
> }
> 
> ######### end of /etc/procmailrc #####################
> :0 B
> * $"filename=.\+(pif|com|exe|vbs|bat|lnk|scr)"
> /tmp/xit
> 
> 



[]'s Eric Melo
Registered User #277266
Started: feb 1996  
"Be free,use Linux!"


--- message from "Robert L. Harris" <Robert.L.Harris at rdlg.net> attached:
-- BEGIN included message

To: ale at ale.org
Subject: Re: [ale] procmail filter on attachment name?
From: "Robert L. Harris" <Robert.L.Harris at rdlg.net>
To: ale at ale.org
Date: Thu, 21 Aug 2003 09:34:29 -0400
In-Reply-To: <20030821132835.761DCAC21 at sitemail.everyone.net>
List-Archive: <http://www.ale.org/pipermail/ale/>
List-Help: <mailto:ale-request at ale.org?subject=help>
List-Id: Atlanta Linux Enthusiasts <ale.ale.org>
List-Post: <mailto:ale at ale.org>
List-Subscribe: <http://www.ale.org/mailman/listinfo/ale>,<mailto:ale-request at ale.org?subject=subscribe>
List-Unsubscribe: <http://www.ale.org/mailman/listinfo/ale>,<mailto:ale-request at ale.org?subject=unsubscribe>
References: <20030821132835.761DCAC21 at sitemail.everyone.net>
Reply-To: ale at ale.org
Sender: ale-admin at ale.org
User-Agent: Mutt/1.5.4i



Can you break down the sections?  I see you send out a message to the
offender that they sent you a virus, but where does /tmp/tumb get
defined, etc?


Thus spake Eric Melo (ericmelo at hackernetwork.com):

> Yes it is, check script below, make you ajustments.
> ps: if you need more help give a call! 
> Good luck! :)
> ###################################################3
> :0 B
>     * $"filename=.\+(pif|com|exe|bat|lnk|scr)"
> {
>     :0 c
>     |(formail -r -i"From:antivirus" -A"X-Loop: antivirus";\
>     cat /etc/virus.msg)|$SENDMAIL -oi -t
>     /tmp/tumb
> 
>     :0
>     /var/spool/procmail/${LOGNAME}.virus
>     /tmp/virus-tumb
> }
> 
> ######### end of /etc/procmailrc #####################
> :0 B
> * $"filename=.\+(pif|com|exe|vbs|bat|lnk|scr)"
> /tmp/xit
> 
> 
> 
> []'s Eric Melo
> Registered User #277266
> Started: feb 1996  
> "Be free,use Linux!"




:wq!
---------------------------------------------------------------------------
Robert L. Harris                     | GPG Key ID: E344DA3B
                                         @ x-hkp://pgp.mit.edu
DISCLAIMER:
      These are MY OPINIONS ALONE.  I speak for no-one else.

Life is not a destination, it's a journey.
  Microsoft produces 15 car pileups on the highway.
    Don't stop traffic to stand and gawk at the tragedy.

 PGP signature

-- END included message




More information about the Ale mailing list