<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail 开源邮件服务解决方案 - 如何关闭ClamAV-clamd的PDF文件检查]]></title>
		<link>https://bbs.iredmail.org/topic1753-clamavclamdpdf.html</link>
		<atom:link href="https://bbs.iredmail.org/feed-rss-topic1753.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[如何关闭ClamAV-clamd的PDF文件检查 里最新回复的文章]]></description>
		<lastBuildDate>Tue, 28 Dec 2010 08:21:35 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8837.html#p8837</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin 写道:</cite><blockquote><p>/etc/clamd.conf 里有一个 &quot;ScanPDF yes&quot;，将它改为 no，并重启 clamav 试试。</p><p>如果还不行，就在 /etc/amavisd.conf 的顶部找到这句：<br /></p><div class="codebox"><pre><code># @bypass_virus_checks_maps = (1);</code></pre></div><p>将这一行的注释去掉，重启 amavisd，就不会再调用 ClamAV 了。</p></blockquote></div><p>ScanPDF yes 这个我是最早就改成 no 了</p><p>关闭ClamAV是最后的办法了 <img src="https://bbs.iredmail.org/img/smilies/sad.png" width="15" height="15" alt="sad" /></p>]]></description>
			<author><![CDATA[null@example.com (jackwjy)]]></author>
			<pubDate>Tue, 28 Dec 2010 08:21:35 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8837.html#p8837</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8834.html#p8834</link>
			<description><![CDATA[<p>/etc/clamd.conf 里有一个 &quot;ScanPDF yes&quot;，将它改为 no，并重启 clamav 试试。</p><p>如果还不行，就在 /etc/amavisd.conf 的顶部找到这句：<br /></p><div class="codebox"><pre><code># @bypass_virus_checks_maps = (1);</code></pre></div><p>将这一行的注释去掉，重启 amavisd，就不会再调用 ClamAV 了。</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 28 Dec 2010 07:54:53 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8834.html#p8834</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8832.html#p8832</link>
			<description><![CDATA[<p>有人可以解决吗？<br />难道只能关闭ClamAV啦<br /><img src="https://bbs.iredmail.org/img/smilies/sad.png" width="15" height="15" alt="sad" /></p>]]></description>
			<author><![CDATA[null@example.com (jackwjy)]]></author>
			<pubDate>Tue, 28 Dec 2010 07:26:20 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8832.html#p8832</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8831.html#p8831</link>
			<description><![CDATA[<p>[root@mail local]# sudo freshclam<br />ClamAV update process started at Tue Dec 28 14:28:26 2010<br />main.cvd is up to date (version: 53, sigs: 846214, f-level: 53, builder: sven)<br />daily.cld is up to date (version: 12446, sigs: 12211, f-level: 58, builder: guitar)<br />bytecode.cld is up to date (version: 114, sigs: 27, f-level: 58, builder: edwin)<br />[root@mail local]#</p><br /><p>已经更新到最新的了，还是老样子</p>]]></description>
			<author><![CDATA[null@example.com (jackwjy)]]></author>
			<pubDate>Tue, 28 Dec 2010 06:32:39 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8831.html#p8831</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8830.html#p8830</link>
			<description><![CDATA[<p>你升级了 clamav 的病毒库没？</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 28 Dec 2010 05:46:37 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8830.html#p8830</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8827.html#p8827</link>
			<description><![CDATA[<p>maillog<br />Dec 28 12:54:05 mail amavis[2790]: (02790-06) Blocked INFECTED (Exploit.PDF-22610(f60cfc7e5ee22c0382f3535fab9c5cbc:930379), Exploit.PDF-22610(82dfea702439669d850582516766ef9f:682526)), LOCAL [58.246.3.174] [58.246.3.174] &lt;jack@lanever.com&gt; -&gt; &lt;jackwjy@gmail.com&gt;, quarantine: virus-kqVOxqD2BWzF, Message-ID: &lt;47D1244287FC417083444F48DA9FC5B7@JackT400&gt;, mail_id: kqVOxqD2BWzF, Hits: -, size: 942584, 641 ms<br />Dec 28 12:54:05 mail postfix/smtp[3490]: AA9A438B0708: to=&lt;jackwjy@gmail.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=7.8, delays=7.2/0.01/0/0.65, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=02790-06, DISCARD(bounce.suppressed))<br />Dec 28 12:54:05 mail postfix/qmgr[2783]: AA9A438B0708: removed</p><p>clamd.log<br />Tue Dec 28 12:54:05 2010 -&gt; /var/amavis/tmp/amavis-20101228T124909-02790/parts/p007: Exploit.PDF-22610 FOUND<br />Tue Dec 28 12:54:05 2010 -&gt; /var/amavis/tmp/amavis-20101228T124909-02790/parts/p003: Exploit.PDF-22610 FOUND</p><br /><p>amavisd.conf</p><p>$policy_bank{&#039;MYNETS&#039;} = {&nbsp; &nbsp;# mail originating from @mynetworks<br />&nbsp; originating =&gt; 1,&nbsp; # is true in MYNETS by default, but let&#039;s make it explicit<br />&nbsp; os_fingerprint_method =&gt; undef,&nbsp; # don&#039;t query p0f for internal clients<br />&nbsp; bypass_virus_checks_maps =&gt; [1],<br />&nbsp; allow_disclaimers =&gt; 1, # enables disclaimer insertion if available<br />};</p><p># it is up to MTA to re-route mail from authenticated roaming users or<br /># from internal hosts to a dedicated TCP port (such as 10026) for filtering<br />$interface_policy{&#039;10026&#039;} = &#039;ORIGINATING&#039;;</p><p>$policy_bank{&#039;ORIGINATING&#039;} = {&nbsp; # mail supposedly originating from our users<br />&nbsp; originating =&gt; 1,&nbsp; # declare that mail was submitted by our smtp client<br />&nbsp; allow_disclaimers =&gt; 1,&nbsp; # enables disclaimer insertion if available<br />&nbsp; # notify administrator of locally originating malware<br />&nbsp; virus_admin_maps =&gt; [&quot;root\@$mydomain&quot;],<br />&nbsp; spam_admin_maps&nbsp; =&gt; [&quot;root\@$mydomain&quot;],<br />&nbsp; warnbadhsender&nbsp; &nbsp;=&gt; 1,<br />&nbsp; bypass_virus_checks_maps =&gt; [1],<br />&nbsp; # forward to a smtpd service providing DKIM signing service<br />&nbsp; forward_method =&gt; &#039;smtp:[127.0.0.1]:10027&#039;,<br />&nbsp; # force MTA conversion to 7-bit (e.g. before DKIM signing)<br />&nbsp; smtpd_discard_ehlo_keywords =&gt; [&#039;8BITMIME&#039;],<br />&nbsp; bypass_banned_checks_maps =&gt; [1],&nbsp; # allow sending any file names and types<br />&nbsp; terminate_dsn_on_notify_success =&gt; 0,&nbsp; # don&#039;t remove NOTIFY=SUCCESS option<br />};</p><br /><p>还是不行啊，amavisd.conf修改好以后已经重启服务器了，还是被过滤</p>]]></description>
			<author><![CDATA[null@example.com (jackwjy)]]></author>
			<pubDate>Tue, 28 Dec 2010 05:05:21 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8827.html#p8827</guid>
		</item>
		<item>
			<title><![CDATA[回复: 如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8824.html#p8824</link>
			<description><![CDATA[<p>在 /etc/amavisd.conf 里找到这几段：<br /></p><div class="quotebox"><blockquote><p>$policy_bank{&#039;MYNETS&#039;} = {}<br />$policy_bank{&#039;ORIGINATING&#039;} = {}<br />$policy_bank{&#039;MYUSERS&#039;} = {} # 这一个在旧版本 iredmail 里没有，所以可以不用</p></blockquote></div><p>在上面几个设置的大括号内，加入这么一句：<br /></p><div class="quotebox"><blockquote><p>bypass_virus_checks_maps =&gt; [1],</p></blockquote></div><p>重启 amavisd 后，所有你的用户发出去的邮件都不会做病毒检测，包括 PDF 和其它各种类型的文件，但对于收到的外部邮件仍然会做检测。</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 28 Dec 2010 03:53:23 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8824.html#p8824</guid>
		</item>
		<item>
			<title><![CDATA[如何关闭ClamAV-clamd的PDF文件检查]]></title>
			<link>https://bbs.iredmail.org/post8822.html#p8822</link>
			<description><![CDATA[<p>Two viruses were found:<br />&nbsp; Exploit.PDF-22610(3a6f6bc64bd3fa36666385767f2b58b0:926454), Exploit.PDF-22610(82dfea702439669d850582516766ef9f:682526)</p><p>Bad header:<br />&nbsp; Non-encoded 8-bit data (char D2 hex): Subject: Fw:<br />&nbsp; &nbsp; \322\273\312\265\315\342\273\343\265\307\274\307\326\244<br />Scanner detecting a virus: ClamAV-clamd</p><p>Content type: Virus<br />Internal reference code for the message is 07517-17/iSOwArvRfTAC</p><p>First upstream SMTP client IP address: [210.13.93.94] According to a &#039;Received:&#039; trace, the message apparently originated at:<br />&nbsp; [210.13.93.94], DJKADM001 unknown [210.13.93.94]</p><p>Return-Path: &lt;xxx@xxx.com&gt;<br />From: &lt;xxx@xxx.com&gt;<br />Message-ID: &lt;572B49CD52844CAF8C4809EC6205D772@DJKADM001&gt;<br />Subject: Fw: xxxxxx<br />The message has been quarantined as: virus-iSOwArvRfTAC</p><p>Notification to sender will not be mailed.</p><p>The message WAS NOT relayed to:<br />&lt;xxx@xxxx.com&gt;:<br />&nbsp; &nbsp;554 5.7.0 Reject, id=07517-17 - INFECTED: Exploit.PDF-22610(3a6f6bc64bd3fa36666385767f2b58b0:926454), Exploit.PDF-2261...</p><p>Virus scanner output:<br />&nbsp; p006: Exploit.PDF-22610(3a6f6bc64bd3fa36666385767f2b58b0:926454) FOUND<br />&nbsp; p003: Exploit.PDF-22610(82dfea702439669d850582516766ef9f:682526) FOUND</p><p>在公司里内部转发出现以上的pdf病毒，但是这个pdf文件是理光扫描仪直接出来的pdf文件，不可能有病毒<br />能否关闭clamav pdf文件扫描呢？</p><p>公司里常用pdf文件，影响很大，谢谢</p>]]></description>
			<author><![CDATA[null@example.com (jackwjy)]]></author>
			<pubDate>Tue, 28 Dec 2010 03:31:00 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post8822.html#p8822</guid>
		</item>
	</channel>
</rss>
