[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [suse-security] postfix - amavisd-new - clamav
I have tried with the debug mode and this is my output...
In this output i read that no virus code is found but in clamav.conf i have defined the clamav ....
Thanks ,
Jul 1 17:48:51 cristian.lucca.osratoscana.it amavisd[9230]: Net::Server: 2004/07/01-17:48:51 CONNECT TCP Peer: "127.0.0.1:35286" Local: "127.0.0.1:10024"
Jul 1 17:48:52 cristian.lucca.osratoscana.it amavisd[9230]: lookup_ip_acl: key="127.0.0.1" matches "127.0.0.1", result=1
Jul 1 17:48:52 cristian.lucca.osratoscana.it amavisd[9230]: prolong_timer after new request - timer reset: remaining time = 300 s
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: SMTP> 220 [127.0.0.1] ESMTP amavisd-new service ready
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: prolong_timer after reading SMTP command: remaining time = 299 s
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: SMTP< EHLO cristian.lucca.osratoscana.it\r\n
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP> 250-[127.0.0.1]
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP> 250-PIPELINING
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP> 250-SIZE
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP> 250-8BITMIME
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP> 250 ENHANCEDSTATUSCODES
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: prolong_timer after reading SMTP command: remaining time = 299 s
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: ESMTP< MAIL FROM:<cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> SIZE=694 BODY=8BITMIME\r\n
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: prolong_timer after MAIL FROM received - timer reset: remaining time = 300 s
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prepare_tempdir: creating directory /var/spool/amavis/amavis-20040701T174853-09230
Jul 1 17:48:53 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prepare_tempdir: creating file /var/spool/amavis/amavis-20040701T174853-09230/email.txt
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx", no match
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP> 250 2.1.0 Sender cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx OK
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after reading SMTP command: remaining time = 299 s
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP< RCPT TO:<cristian.delcarlo@xxxxxxxxxxxxxx>\r\n
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP> 250 2.1.5 Recipient cristian.delcarlo@xxxxxxxxxxxxxx OK
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after reading SMTP command: remaining time = 299 s
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP< DATA\r\n
Jul 1 17:48:54 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after DATA received - timer reset: remaining time = 300 s
Jul 1 17:48:55 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP::10024 /var/spool/amavis/amavis-20040701T174853-09230: <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> -> <cristian.delcarlo@xxxxxxxxxxxxxx> Received: SIZE=694 BODY=8BITMIME from cristian.lucca.osratoscana.it ([127.0.0.1]) by localhost (cristian.lucca.osratoscana.it [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 09230-01 for <cristian.delcarlo@xxxxxxxxxxxxxx>; Thu, 1 Jul 2004 17:48:54 +0200 (CEST)
Jul 1 17:48:55 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP> 354 End data with <CR><LF>.<CR><LF>
Jul 1 17:48:55 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP< .\r\n
Jul 1 17:48:56 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) body hash: 66ea3660589b9b599de0985e806fb953
Jul 1 17:48:57 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Original mail size: 676; quota set to: 338000 bytes
Jul 1 17:48:57 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Checking: <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> -> <cristian.delcarlo@xxxxxxxxxxxxxx>
Jul 1 17:48:57 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:48:57 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:48:58 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Extracting mime components
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Issued a new file name: part-00001
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) mime_decode: Content-type: text/plain, name:
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Charging 8 bytes to remaining quota 338000 (out of 338000, (0%)) - by mime_decode
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after mime_decode-1: remaining time = 293 s
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Checking for banned MIME types and names
Jul 1 17:49:01 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) check_for_banned - mime-type: text/plain
Jul 1 17:49:02 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_RE: key="text/plain", no match
Jul 1 17:49:02 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) decode_parts: level=1, #parts=1 : part-00001
Jul 1 17:49:02 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) run_command: [9270] /usr/bin/file /var/spool/amavis/amavis-20040701T174853-09230/parts/part-00001 </dev/null
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) File-type of part-00001: ASCII text; (.asc)
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Checking for banned (contents-based) file types, 1 parts
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) check_for_banned (part-00001) - file type: .asc
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_RE: key=".asc", no match
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) check_for_banned (part-00001) - file type: ASCII text
Jul 1 17:49:04 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_RE: key="ASCII text", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) do_ascii: Decoding part part-00001 (0 items)
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) decompose_part: part-00001 - atomic
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after decoding: remaining time = 290 s
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) No anti-virus code loaded, skipping this section
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) white_black_list: checking sender <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_RE: key="cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key="cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key="cristian2@", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key="cristian.lucca.osratoscana.it", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key=".cristian.lucca.osratoscana.it", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key=".lucca.osratoscana.it", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key=".osratoscana.it", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key=".it", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_hash: key=".", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx", no match
Jul 1 17:49:05 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:49:06 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) calling SA parse, SA version 2.63
Jul 1 17:49:06 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) CALLING SA check
Jul 1 17:49:26 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) RETURNED FROM NoMailAudit::check, time left: 10 s
Jul 1 17:49:26 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after spam_scan_SA: remaining time = 289 s
Jul 1 17:49:26 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) spam_scan: hits=0 tests=
Jul 1 17:49:26 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after spam_scan: remaining time = 289 s
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup: (scalar) matches, result="5"
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) header: Received: from cristian.lucca.osratoscana.it ([127.0.0.1])\n by localhost (cristian.lucca.osratoscana.it [127.0.0.1]) (amavisd-new, port 10024)\n with ESMTP id 09230-01 for <cristian.delcarlo@xxxxxxxxxxxxxx>;\n Thu, 1 Jul 2004 17:48:54 +0200 (CEST)\n
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup_acl: key="cristian.delcarlo@xxxxxxxxxxxxxx", no match
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup: (scalar) matches, result="3"
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) lookup: (scalar) matches, result="5"
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) headers CLUSTERING: NEW CLUSTER <cristian.delcarlo@xxxxxxxxxxxxxx>: hits=0.0, tag=0, tag2=0, subj=0, subj_u=0, local=0, bl=0
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) headers CLUSTERING: done all 1 recips in one go
Jul 1 17:49:27 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) FWD via SMTP: [127.0.0.1]:10025 <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> -> <cristian.delcarlo@xxxxxxxxxxxxxx>
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Remote host introduces itself as: cristian.lucca.osratoscana.it
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-connect: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-mail-from: remaining time = 288 s
==> /var/log/mail <==
Jul 1 17:49:30 localhost postfix/smtpd[9277]: connect from localhost[127.0.0.1]
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-rcpt-to: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) response to DATA: "354 End data with <CR><LF>.<CR><LF>"
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-data: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-data-end: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) response to data end: "250 Ok: queued as 7E6BC2E5AE"
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after fwd-rundown-1: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) mail_via_smtp: 250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after forwarding: remaining time = 288 s
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) one_response_for_all <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>: success, dsn_needed=0, '250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE'
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) warnsender_with_pass=(,,,), dsn_needed=0, exit=0, 250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE
Jul 1 17:49:31 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) Passed, <cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> -> <cristian.delcarlo@xxxxxxxxxxxxxx>, Message-ID: <20040701.qLI.61337500@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>, Hits: 0
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) sending SMTP response: "250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE"
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) timer stopped after DATA end
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) rmdir_recursively: /var/spool/amavis/amavis-20040701T174853-09230/parts, excl=1
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) TIMING [total 39930 ms] - SMTP EHLO: 1256 (3%), SMTP pre-MAIL: 2 (0%), mkdir tempdir: 399 (1%), create email.txt: 211 (1%), SMTP pre-DATA-flush: 1209 (3%), SMTP DATA: 138 (0%), body hash: 973 (2%), mkdir parts: 883 (2%), mime_decode: 4627 (12%), get-file-type: 2608 (7%), decompose_part: 760 (2%), parts: 0 (0%), SA msg read: 879 (2%), SA parse: 525 (1%), SA check: 20059 (50%), fwd-connect: 4276 (11%), fwd-mail-from: 142 (0%), fwd-rcpt-to: 429 (1%), write-header: 78 (0%), fwd-data: 0 (0%), fwd-data-end: 72 (0%), fwd-rundown: 29 (0%), unlink-1-files: 335 (1%), rundown: 40 (0%)
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP> 250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) prolong_timer after reading SMTP command: remaining time = 0 s
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP< QUIT\r\n
Jul 1 17:49:32 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) ESMTP> 221 2.0.0 [127.0.0.1] (amavisd) closing transmission channel
Jul 1 17:49:31 localhost postfix/smtpd[9277]: 7E6BC2E5AE: client=localhost[127.0.0.1]
Jul 1 17:49:31 localhost postfix/cleanup[9266]: 7E6BC2E5AE: message-id=<20040701.qLI.61337500@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
Jul 1 17:49:31 localhost postfix/smtpd[9277]: disconnect from localhost[127.0.0.1]
Jul 1 17:49:32 localhost postfix/smtp[9269]: E09822E5AD: to=<cristian.delcarlo@xxxxxxxxxxxxxx>, relay=localhost[127.0.0.1], delay=50, status=sent (250 2.6.0 Ok, id=09230-01, from MTA: 250 Ok: queued as 7E6BC2E5AE)
Jul 1 17:49:32 localhost postfix/qmgr[8674]: 7E6BC2E5AE: from=<cristian2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>, size=1146, nrcpt=1 (queue active)
Jul 1 17:49:32 localhost postfix/qmgr[8674]: E09822E5AD: removed
Jul 1 17:49:32 localhost postfix/smtp[9269]: 7E6BC2E5AE: to=<cristian.delcarlo@xxxxxxxxxxxxxx>, relay=192.168.9.30[192.168.9.30], delay=1, status=sent (250 2.0.0 i61Fn4L02073 Message accepted for delivery)
Jul 1 17:49:32 localhost postfix/qmgr[8674]: 7E6BC2E5AE: removed
Jul 1 17:49:35 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) tempdir being removed: /var/spool/amavis/amavis-20040701T174853-09230
Jul 1 17:49:35 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) rmdir_recursively: /var/spool/amavis/amavis-20040701T174853-09230, excl=
Jul 1 17:49:35 cristian.lucca.osratoscana.it amavisd[9230]: (09230-01) rmdir_recursively: /var/spool/amavis/amavis-20040701T174853-09230/parts, excl=0
Jul 1 17:49:37 cristian.lucca.osratoscana.it amavisd[9205]: Net::Server: 2004/07/01-17:49:36 Server closing!
On Jul 01, 2004 05:36 PM, Andreas Winkelmann <ml@xxxxxxxxxxxxxx> wrote:
> Am Donnerstag, 1. Juli 2004 17:05 schrieb Cristian Del Carlo:
>
> > i have tried to configure postfix with amavis-new and clamav , but clamav
> > doesn't scan te mail. This is my configuration in /etc/postfix/main.cf :
> > content_filter = smtp-amavis:[127.0.0.1]:10024
> > And in /etc/postfix/master.cf :
>
> > When i send a mail in /var/log/mail i have the following messages :
>
> > Where is the mistake ?
>
> Stop amavisd. (rcamavis stop) and start it from the commandline with debug as
> argument.
>
> # amavisd debug
>
> Try to send the mail again and show the Output.
>
> --
> Andreas
>
>
> --
> Check the headers for your unsubscription address
> For additional commands, e-mail: suse-security-help@xxxxxxxx
> Security-related bug reports go to security@xxxxxxx, not here
>
Cristian Del Carlo
delcarlo@xxxxxxxxxxxxxx
Tel. 0583 424700
Fax 0583 424750
http://www.osratoscana.it
Il testo e gli eventuali documenti trasmessi contengono informazioni riservate al destinatario indicato. La seguente e-mail è confidenziale e la sua riservatezza è tutelata legalmente dal Decreto Legislativo 196 del 30/06/2003 (Codice di tutela della privacy). La lettura, copia o altro uso non autorizzato o qualsiasi altra azione derivante dalla conoscenza di queste informazioni sono rigorosamente vietate. Qualora abbiate ricevuto questo documento per errore siete cortesemente pregati di darne immediata comunicazione al mittente e di provvedere, immediatamente, alla sua distruzione.
--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here