Attachment Filtering RSS

1

I have exe files by name getting blocked. I also have exe files where you strip the .exe off the file name working. However if you change the .exe file to .doc ORF is not picking it up. Is there something I'm missing?

My MIME Type is application/octet-stream and simple text

Thanks,
Jean

by Jean 5 years ago
2

@Jean: I understand your are basically running an attachment filter for the MIME type "application/octet-stream" and no file name specified, is that correct? This would indeed behave the way you have described, but not only this won't catch .DOC files, you can expect a few more issues with that.

As for why it doesn't catch .EXE files renamed to .DOC is that these latter usually have the MIME type "application/msword". The MIME type is entirely up to the email client (e.g. Outlook). When composing an email, the email client typically turns to the list of known-file-extension-to-MIME-type associations and assigns the MIME type based on the extension. Due to this, when you change the file extension to .DOC, the MIME type also changes to "application/msword". You can find a lot of those associations under HKEY_CLASSES_ROOT\MIME\Database\Content Type in the registry.

About the issues you may run into: The "application/octet-stream" MIME type is basically a catch-all MIME type used for .EXE files, but also for _any unidentified binary content_. When receiving email from the outside of your organization, you cannot be sure if the original composing email client was smart enough to assign "application/pdf" MIME type for a .PDF file, so you might be losing attachment/emails to this.

Unfortunately, the Attachment Filtering feature of ORF not sophisticated enough to recognize such .EXE files posing as .DOC files. In this sense, you should consider it more like a first line of defense. I suppose you also run anti-virus software on your server and these typically have really good attachment support given the nature of threats they're dealing with. You might want to give a try to your AV to see if it has something for this specific scenario.

by Péter Karsai (Vamsoft) 5 years ago
(in reply to this post)

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

Nickname:
Email address (will not be published):
Your comment:

ORF Technical Support

Configuring, installing and troubleshooting ORF.

News & Announcements

Your dose of ORF-related news and announcements.

Everything but ORF

Discuss Exchange and system administration with fellow admins.

Feature Test Program

Feature Test Program discussion. Membership is required to visit this forum.

ORF Beta

Join the great bug hunt of the latest test release.

Customer Service

Stay Informed