How to block .scr and .pif attachments in incomming mails

As you’ve probably heard there’s another new virus (Worm) out today. My users love opening all attachments, so is it possible to stop attachments of a certain file extension getting through by changing a setting on the Domino Mail Server?

Thanks

Subject: How to block .scr and .pif attachments in incomming mails

Since you are on R6 you can go into the server’s configuration document.

Go under Router SMTP/ Restrictions and Controls/ Rules - you should be able to setup and enable rules to move, journal or refuse messages based on the attachment. I’m assuming this would work if you set up a rule that said “any attachment name contains: scr” (or pif)

I haven’t tested these out because we’re using SAV for Domino and they have the same kinds of rules that are specifically setup to block file types, the “rules” naitive to Domino seem a little less specific and I can only imagine that an attachment named “Screen” would get caught by such a rule as well. My other caution is that I’ve never liked the way rules have behaved in the mail client so I can only imagine that this server based set of rules should be approached cautiously.

If you are interested, set it up to Journal or move, set it up on a test server, run some attachments through and see how it behaves.

I would strongly suggest you look at getting some sort of virus filter though, while Domino may not be targeted like the Microsoft products, you will see a LOT of things coming in. We block an endless stream of infected files…

Subject: Highly Recommended Antivirus Product…

We recently purchased Trend Micro’s “Scanmail” for Lotus and it provides an additional feature to easily block attachments by filename extension. Very good product, I highly recommend it. No email system should be without an antivirus system this day and age.

Subject: Seconded

Yes. Scanmail does it for us every time. We have it configured to block

.scr

.shs

.shx

.bat

.pif

and numerous other executable file types.

This was blocking Bugbear.B before anyone knew there was a Bugbear.B