From: Eric S. <eri...@uo...> - 2005-07-29 14:26:28
|
Hi, maybe this is a silly question, but lets say I have a rule for POP3 blocking a malware (it can be a normal rule or using ClamAV preprocessor). When an internal user try to download the message, the packet wich contain the malware will be drop (NF_DROP I guess). But since the email is still in his mailbox, this will not stay in looping and the user will be unable of downloading the other messages until someone remove the email from his mbox? If the above is true, is there some way of intercept 'trasnparently' the packet and send a DELE msg to the POP3 Server? Maybe changing the payload/saddr/daddr, etc of this packet using libipq? Regards, Eric Scopinho |