quarantine problems MailControl
Posted: 28 Oct 2016, 07:36
I am noticing a few problems with mail control and quarantined files
If Clam Av detects a virus mail control tells me "Message not found in quarantine "
This only happens if clam AV detects an actual virus not when it detects a blocked file type which it still marks as a virus.
Using the old mailwatch, I can still release the "infected" file /email for examination and I can also see & download the email & contents using CSE, so the email is in Quarantine and available
It appears to be something about the way Mailcontrol works. I don't know why Mailcontrol cannot see it in quarantine, when mailwatch can and CSE can. Is it a permissions issue ?
I doubt this bug / feature will affect many users, who won't want to release many ( if any) viruses that Clam AV detects. In reality Clam AV is not great at detecting windows viruses. But like all AV they do have occasional FP and quarantine genuine needed files
However I research and blog about email based malware & phishing and need copies of all malware received. I can download via CSE but it is easier if I can do it directly from the MSFE / mail control interface
If Clam Av detects a virus mail control tells me "Message not found in quarantine "
This only happens if clam AV detects an actual virus not when it detects a blocked file type which it still marks as a virus.
Using the old mailwatch, I can still release the "infected" file /email for examination and I can also see & download the email & contents using CSE, so the email is in Quarantine and available
It appears to be something about the way Mailcontrol works. I don't know why Mailcontrol cannot see it in quarantine, when mailwatch can and CSE can. Is it a permissions issue ?
I doubt this bug / feature will affect many users, who won't want to release many ( if any) viruses that Clam AV detects. In reality Clam AV is not great at detecting windows viruses. But like all AV they do have occasional FP and quarantine genuine needed files
However I research and blog about email based malware & phishing and need copies of all malware received. I can download via CSE but it is easier if I can do it directly from the MSFE / mail control interface