Hi @fasttech I’ve tried to reproduce the block of archives class (custom list disabled):
[root@vm3 ~]# config show amavisd
amavisd=service
BlockAttachmentClassList=Exec,Arch
BlockAttachmentCustomList=doc,odt
BlockAttachmentCustomStatus=disabled
BlockAttachmentStatus=enabled
SpamCheckStatus=disabled
SpamDsnLevel=20
[…]
status=enabled
- It works as expected blocking a ZIP file on port 25:
Sep 3 16:38:27 vm3 amavis[5404]: (05404-01) Blocked BANNED (CLASS Arch:bootstrap-3.3.4/) {RejectedInternal,Quarantined}, MYNETS LOCAL [192.168.122.1]:60969 davide.principi@vnet1.tld → prova@vnet1.tld, Message-ID: 1441298293.2232.56.camel@vnet1.tld, mail_id: MO5ai8-BmI-Z, Hits: -, size: 4476433, 13773 ms
Sep 3 16:38:27 vm3 transfer/smtpd[5366]: proxy-reject: END-OF-MESSAGE: 554 5.7.0 Reject, id=05404-01 - BANNED: CLASS Arch:bootstrap-3.3.4/; from=davide.principi@vnet1.tld to=prova@vnet1.tld proto=ESMTP helo=<davidep1.nethesis.it>
- Also on port 587, with SMTPAUTH:
Sep 3 16:41:29 vm3 submission/smtpd[5416]: NOQUEUE: client=unknown[192.168.122.1], sasl_method=PLAIN, sasl_username=davidep
Sep 3 16:41:31 vm3 amavis[5405]: (05405-01) Blocked BANNED (CLASS Arch:bootstrap-3.3.4/) {RejectedInternal,Quarantined}, SUBMISSION/MYNETS LOCAL [192.168.122.1]:45617 davide.principi@vnet1.tld → prova@vnet1.tld, Message-ID: 1441298489.2232.59.camel@vnet1.tld, mail_id: GgynetqKFJoI, Hits: -, size: 4476468, 2102 ms
Sep 3 16:41:31 vm3 submission/smtpd[5416]: proxy-reject: END-OF-MESSAGE: 554 5.7.0 Reject, id=05405-01 - BANNED: CLASS Arch:bootstrap-3.3.4/; from=davide.principi@vnet1.tld to=prova@vnet1.tld proto=ESMTP helo=<davidep1.nethesis.it>
- As stated in the source fragment above, I can confirm the applied configuration is from
/etc/amavisd.conf
.
Unfortunately the only chance of reproducibility was with the original ZIP file.
Edit: My doubt is now: was it a real archive or only the name was ending with .zip? the regexp above seems to match both file type and extension…