[sanesecurity] Re: False Positive

  • From: "Steve Basford" <steveb_clamav@xxxxxxxxxxxxxxxx>
  • To: sanesecurity@xxxxxxxxxxxxx
  • Date: Thu, 25 Aug 2016 20:14:24 +0100


On Thu, August 25, 2016 6:00 pm, Paul Stead wrote:


If you want to, however, you can add the rule name to your whitelist file
(sigwhitelist.ign2) and this will avoid these signatures from firing.

Thank would work but you'd forever be adding in entried to .ign2 as
each spam report get's a hit.

I think the *only* solution is to actually get the MTA to whitelist/score
and ignore the ClamAV results.


Cheers,

Steve
Web : sanesecurity.com
Twitter: @sanesecurity


Other related posts: