Enhancing E-Mail Security With Procmail

User Comments

Back to the home page

Unsolicited testimonials I have received in my email:


Date: Tue, 21 May 2002 17:03:43 -0400
From: Kent Wagoner 
To: jhardin@impsec.org
Subject: Compliments on the E-Mail Sanitizer

Mr. Hardin,

I just wanted to send you a short note thanking you for your e-mail 
sanitizer system.  It has, without a doubt, saved my company (and my 
sanity) many times over.

Since installing it on my company's central mailserver, I have trapped 
and disposed of every single inbound e-mail virus that has come our way. 

We have a zero-percent infection rate for systems that get their mail 
from my mailserver.  In fact, some of my users have grown so confident 
in the mailserver's ability to stop viruses and worms that they've 
talked about removing the anti-virus software installed on their 
workstations (an idea I have strongly discouraged.)

My thanks for an incredible application.  You've made this SysAdmin's 
life much, much easier.

Kent J. Wagoner
System Administrator
Osprey Technologies / ViewCast Corporation


Date: Wed, 07 Feb 2001 08:29:06 -0800
From: ******
To: *****
Cc: jhardin@wolfenet.com
Subject: Helpful E-mail for getting rid of Hybris and other net based  virii - system admins

Here's the deal:

I'm a network admin with a few mail servers running Sendmail 8.11.
E-mail security has ALWAYS been the highest priority on our security
checklist for invasion techniques.

Today we were battling with the Hybris worm, behind the scenes...

Point blank, we've stopped the following dead, even before the news
services caught on to the onslaught:

Melissa (all variants)
CIH
Hermes
Hybris
ProLin
MyRomeo
I Love You
Navidad
New Apt
Explore Zip
All VBS, SCR, CHM, PIF delivered virii
And more...

All I can say is: Jason[sic] Hardin's Procmail script
http://www.impsec.org/email-tools/procmail-security.html

This script has saved myself, and our company well into the
ten-thousands of dollars of downtime, productivity, and overall
potential destruction by these viruses.  It's easy to use, and anyone
with a UNIX mail server and procmail should implement this (either
sitewide or per user).


Thanks!

n.b.: my name is John...


I can be contacted at <jhardin@impsec.org> - you could also visit my home page.


Created with vi   Bobby approved   Best viewed with Any Browser

$Id: sanitizer-comments.html,v 1.8 2002-05-26 13:23:28-07 jhardin Exp $
Contents Copyright (C) 2001 by John D. Hardin - All Rights Reserved.