GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » Scanning Virus in ZIP (Scanning Virus in ZIP)
Re: Scanning Virus in ZIP [message #120437 is a reply to message #120427] Wed, 01 April 2015 23:04 Go to previous messageGo to next message
MarkK is currently offline  MarkK
Messages: 342
Registered: April 2007
Between Sophos AV and ClamAV both running on our connect server, it is more of an exception that a malware zip file comes through. Getting the spam filter working good will also help, since that is the channel that a majority of those come in through.
(Yes, AV and spam are separate things, but catching and stopping bad emails in any form helps.)
Re: Scanning Virus in ZIP [message #120439 is a reply to message #120426] Wed, 01 April 2015 23:35 Go to previous messageGo to next message
Pavel Dobry (Kerio) is currently offline  Pavel Dobry (Kerio)
Messages: 2057
Registered: October 2003
Location: Czech Republic
Machete wrote on Wed, 01 April 2015 17:25
Just to confirm from the first reply of this post -

- Connect does scan inside .zip attachments for Virus? I just had a user open an .exe that inside a zip file and I'm now evaluating where the holes are in my protection - in addition to her desktop AV not being up to date somehow...

- Does Connect scan inside .zip attachments for blocked file types? I have ZIPs allowed - but block .exe's


1. Yes it does scan inside .zip attachments. With Kerio Connect 8.4.2 there is also an online Sophos Live Protection scan for malware attachments.

2. This option will come with upcoming Kerio Connect 8.5.


Re: Scanning Virus in ZIP [message #120540 is a reply to message #120439] Wed, 08 April 2015 18:01 Go to previous messageGo to next message
88fingerslukee is currently offline  88fingerslukee
Messages: 92
Registered: November 2007
Sophos is garbage. It is constantly allowing .zip files through that my Avast! desktop scanner is picking up.

Kerio needs to provide instructions on how to setup an alternative, virus-scanner or change to a company that provides better response to threats. I will be cancelling the Sophos portion of my software license the next time I renew.

I'm not happy.
Re: Scanning Virus in ZIP [message #120544] Wed, 08 April 2015 18:50 Go to previous messageGo to next message
graeme is currently offline  graeme
Messages: 38
Registered: October 2013
No simple layer of defence is a good idea - esp. antivirus.
You can test samples on 50+ engines and only one will get it.
We use a EU firm to do our firm layer and even that misses some.
Use a gateway or saas product.
Re: Scanning Virus in ZIP [message #120545 is a reply to message #120540] Wed, 08 April 2015 18:56 Go to previous messageGo to next message
MarkK is currently offline  MarkK
Messages: 342
Registered: April 2007
Actually Sophos is one of the better malware detection companies. But there has been a lot of new malware variations coming out lately, and it takes time for the anti-malware companies to develop the detection for them. You can test this by submitting the malware attachments to virustotal.com to see if the 50+ various vendors will detect it. We have had some attachments lately that only 1 vendor was detecting it.

So it may not be Kerio fault, and it does take some time for the any vendor to develop detection for new malware.

Avast used to have a Kerio specific edition. I see it listed for other countries, but I don't see a specific one for Kerio on the US web site, though there is an email server edition. Contact Avast and see if they still have a Kerio capable version. You can buy that and have Kerio use it in addition to Sophos, or instead of Sophos.
Re: Scanning Virus in ZIP [message #120571 is a reply to message #120540] Thu, 09 April 2015 14:22 Go to previous messageGo to next message
Pavel Dobry (Kerio) is currently offline  Pavel Dobry (Kerio)
Messages: 2057
Registered: October 2003
Location: Czech Republic
88fingerslukee wrote on Wed, 08 April 2015 18:01
Sophos is garbage. It is constantly allowing .zip files through that my Avast! desktop scanner is picking up.

Kerio needs to provide instructions on how to setup an alternative, virus-scanner or change to a company that provides better response to threats. I will be cancelling the Sophos portion of my software license the next time I renew.

I'm not happy.


Few minutes ago I got a virus that is not detected by Avast either - eg. https://www.virustotal.com/en/file/edaf688e01c6918e8b16c62f6 790c1c75c7046cdb4e3242844b8da7df7a24828/analysis/1428581786/
Does this render Avast as garbage too?



Re: Scanning Virus in ZIP [message #120965 is a reply to message #120439] Mon, 27 April 2015 20:32 Go to previous messageGo to next message
Andrey.T is currently offline  Andrey.T
Messages: 6
Registered: April 2015
...

[Updated on: Mon, 27 April 2015 20:45]

Report message to a moderator

Re: Scanning Virus in ZIP [message #120966 is a reply to message #120439] Mon, 27 April 2015 20:47 Go to previous messageGo to next message
Andrey.T is currently offline  Andrey.T
Messages: 6
Registered: April 2015
Pavel Dobry (Kerio) wrote on Thu, 02 April 2015 03:35


2. This option will come with upcoming Kerio Connect 8.5.


I tested it

test.js>test.zip = virus is not delivered
test.js>test.cab>test.zip = virus delivered and running! only the second mouse click...
Maybe discard zip archive containing filter rule file extensions?
Re: Scanning Virus in ZIP [message #120979 is a reply to message #120966] Tue, 28 April 2015 09:29 Go to previous messageGo to next message
Kedar
Messages: 356
Registered: April 2005
The forbidden extensions are defined directly in mailserver.cfg (there is no GUI in WebAdmin). If you need, stop Kerio Connect and add .cab to the list in mailserver.cfg

(We know the GUI or some checkbox for each rule is better, but there is not time to implement GUI in WebAdmin to the 8.5.0, incl. translations, doc, testing... We think used solution is better than nothing.)
Re: Scanning Virus in ZIP [message #120981 is a reply to message #116675] Tue, 28 April 2015 11:29 Go to previous messageGo to next message
Andrey.T is currently offline  Andrey.T
Messages: 6
Registered: April 2015
Thx
I found a bug in ZipFilterExtensions section
I write to you in the mail

Section ZipFilterExtensions supports a mask?
for example .wm? or .{*}*
Re: Scanning Virus in ZIP [message #120982 is a reply to message #120981] Tue, 28 April 2015 11:37 Go to previous messageGo to next message
Kedar
Messages: 356
Registered: April 2005
Unfortunately the masks are not supported in 8.5.0
Re: Scanning Virus in ZIP [message #120983 is a reply to message #120982] Tue, 28 April 2015 12:05 Go to previous messageGo to next message
Andrey.T is currently offline  Andrey.T
Messages: 6
Registered: April 2015
I packed archive with a virus a few times and the result is sad...
virus.js>test1.zip>test2.zip>test3.zip - virus is delivered and running

I really hope this will correct.

Re: Scanning Virus in ZIP [message #120984 is a reply to message #120983] Tue, 28 April 2015 12:19 Go to previous messageGo to next message
Kedar
Messages: 356
Registered: April 2005
In 8.5.0 is only basic solution as the addition to build-in antivirus. We want deliver helpful feature for majority of users as soon as possible.

GUI, support for masks, nested archives etc. are not supported yet.
Re: Scanning Virus in ZIP [message #120985 is a reply to message #120983] Tue, 28 April 2015 12:35 Go to previous messageGo to next message
Pavel Dobry (Kerio) is currently offline  Pavel Dobry (Kerio)
Messages: 2057
Registered: October 2003
Location: Czech Republic
I think you expect some functionality that is not intended with this feature. Virus should not be delivered as it is supposed to be caught by antivirus.
This feature about blocking attachments and most common types of malware, which is distributed as a .zip file so it opens automatically on many clients. It does what it says - blocking executable files with certain file extension in .zip file. It is not supposed to block file embedded in ZIP in ZIP in RAR in 7Z in tar.gz and such ridiculous recursive chains.


[Updated on: Tue, 28 April 2015 12:36]

Report message to a moderator

Re: Scanning Virus in ZIP [message #120986 is a reply to message #120985] Tue, 28 April 2015 12:45 Go to previous messageGo to previous message
Andrey.T is currently offline  Andrey.T
Messages: 6
Registered: April 2015
I would like to have a minimum protection against targeted attacks. We have so often happens.
Previous Topic: User Rights by using "Another Mailbox"
Next Topic: Webmail server not responding after upgrade to 8.4.0
Goto Forum:
  


Current Time: Tue Oct 03 20:16:57 CEST 2023

Total time taken to generate the page: 0.07406 seconds