Solved

create an event sink that filters and delete emails after being scanned by SAV for exchange

Posted on 2004-04-15
3
691 Views
Last Modified: 2010-08-05
This question is pretty specific to a type of system
Exchange 2000
SAV for exchange
running on Windows 2000 server SP4
 
 
Our problem starts when we are receiving infected emails. SAV for exchange is meant to remove any infected attachment from an email but still delivers the mail to the recipient.
 
Example : someone outside the company has an infected computer with Netsky. The user doesn't know that his computer is infected but the virus sends itself to everybody in the address book. Usually the subject is random and the text as well.
In the address book, there is one or more addresses of our users from our organisation; so we will be receiving a bunch of infected emails. Fortunately SAV for exchange will scan those incoming emails and remove the attachment. Unfortunately the way SAV works, it will still deliver the mail with the random subject and text and will attach a new file that will be called "Deleted attachment.txt". In that text file there's a description of what happened, basically it will say that the mail contained a virus called Netsky and that the attachment has been removed.
If we have many people outside the company with an infected computer, our users will receive a LOT of those emails with an attachment called "Deleted attachment" ( one of ours is getting up to 800 a day now ).
 
 
Now there are many solutions:
1st - first one which is pretty effective is to create a rule on each stations that would delete those type of emails. Unfortunately if the user uses outlook express this won't get effective, and most of all it would take forever to get to everybody stations to create the rules.
2nd - We could use a "perimeter mail app" that would actually do that kind of work but usually these apps tie to an RBL list and filter emails based on those lists which is not totally reliable. Some other of those apps are also pretty expensive
 
3rd - So by doing some research I noticed that something called "event sink" could be used to filter an email right after it has been scanned by SAV.
 
The idea would be then to register a new event sink on the mail server ( from what I understand, this would be a VBscript ). The event sink would just delete any email with an attachment called "Deleted Attachment.txt".
 
Does anyone know how to write such a script ?
 
 
 
Thanks
0
Comment
Question by:ekriner
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 20

Accepted Solution

by:
What90 earned 500 total points
ID: 10838507
I'm always awary of using Event sinks. If you are going to use one of these then test it on a test server first.



Have a look at this link:
http://www.vamsoft.com/orf/howto-attfltr.asp

And these as background:
http://www.outlookexchange.com/articles/glenscales/attarch.asp
http://www.outlookexchange.com/articles/glenscales/attarch2.asp

otherwise you might be able to adapt this:
http://support.microsoft.com/default.aspx?scid=kb;en-us;308303
0
 
LVL 7

Expert Comment

by:rosesolutions1
ID: 10848643
This is a poor solution if your mail server is running under any load. For running under load, you will need this code to be properly compiled inside a theadsafe, multiprocessor-compliant component.

Best choice is to upgrade SAV to the latest release, which - according to http://enterprisesecurity.symantec.com/products/products.cfm?ProductID=66 - features "Mass-Mailer Cleanup automatically eliminates entire messages generated by mass-mailer worms, not just attachments "
0
 

Author Comment

by:ekriner
ID: 10928629
Thanks for the participation everyone! I have used the accepted answer.
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
This video discusses moving either the default database or any database to a new volume.

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question