TrashScan - ZapCoded by Trashware; 22.04.2004
=============================================

This little script allows you to scan incoming email attaches for suspicious
virus code.

You need:
----------------------------------------------------------------------------
- awk				(tested with 3.0.6)
- bash				(tested with 2.04)
- decoder			(metamail, tested with 2.7.19 or
				uudeview, tested with 0.5pl13)
- virus scanner			(clamav recommended, tested with 0.20 .. 0.70)
- procmail			(tested with 3.15.1, 3.22)
- sendmail			(tested with 8.11.2, 8.12.10)
- cat				(tested with 2.0.10)
- grep				(tested with 2.4)
- logger			(tested with 4.3)
- mkdir				(tested with 4.0.35)
- rm				(tested with 4.0.35)
- sed				(tested with 3.02)
----------------------------------------------------------------------------
Not much, isn't it?


INSTALLATION
------------

Well, this should be quite simple...

1. Change the "Settinx section" in the header of trashscan to hit your needs
2. Copy trashscan to /usr/local/bin
3. Check / change procmail.trashscan and put it into your .procmailrc
4. Enjoy


HINTS FOR OPERATORS OF MULTIUSER SYSTEMS
----------------------------------------

TrashScan works pretty fine on multiuser systems.

1. Readdress all incoming email to a single user ("mailservice" for example)
   by having a look at sendmail's virtusertable / sendmail.cw
2. Let THIS user do the virus scanning, spam checking and mail delivery
   for your WHOLE system by defining all neccessary recipes in it's sole
   .procmailrc file

2.1 Example .procmailrc for user "mailservice":
    --------------------------------------- Begin Cut ---------------------------------------
    #
    # Configuration for user "mailservice" running on a multiuser system as a mail robot
    # ZapCoded by Trashware; 17.02.2004
    #
    # You need (I'm pretty sure you already have):
    #   - cat
    #   - gawk
    #   - sendmail
    #   - test
    #   - SpamAssassin
    #   - TrashScan (won't you?)
    #
    # ------------------------------------------------------------------------------------- #
    # Admin section ...                                                                     #
    # ------------------------------------------------------------------------------------- #

    # 1. Define the logfile
    LOGFILE=/var/log/procmail.log

    # 2. Turn on/off extended diagnostics
    VERBOSE=off

    # 3. Debugging purposes only: Store all mail as "Debug.txt"
    # :0 c
    # Debug.txt

    # 4. Path settings
    CAT=/bin/cat
    FORMAIL=/usr/bin/formail
    GAWK=/usr/bin/gawk
    SENDMAIL=/usr/sbin/sendmail
    SPAMC=/usr/bin/spamc
    TEST=/usr/bin/test
    TRASHSCAN=/usr/local/bin/trashscan

    # 5. Shell
    SHELL=/bin/sh

    # ------------------------------------------------------------------------------------- #
    # Unwanted mail section ...                                                             #
    # ------------------------------------------------------------------------------------- #

    # :0 h
    # * ^From:.*twit@spam\.net
    # /dev/null

    # ------------------------------------------------------------------------------------- #
    # Mail robot section ...                                                                #
    # ------------------------------------------------------------------------------------- #

    # 1. Avoid robot loops (local user "mailservice" reflects mailservice.trashware@gmx.net
    :0 h
    * ^(To|Cc):.*mailservice\.trashware@gmx\.net
    * ^FROM_MAILER
    /dev/null

    # 2. Bounce the rest
    :0
    * ^(To|Cc):.*mailservice\.trashware@gmx\.net
    * !^FROM_MAILER
    | ($FORMAIL -A "X-Loop: mailservice.trashware@gmx.net" -r -k | \
	$GAWK '{print} /^/ && !HEADER {system("$CAT procmail.mailservice"); HEADER=1}') | \
	$SENDMAIL -t

    # ------------------------------------------------------------------------------------- #
    # Spam section ...                                                                      #
    # ------------------------------------------------------------------------------------- #

    # 1. Run the SpamAssassin client
    :0 cW
    | $SPAMC -c -s 1000000 -u mailservice
    SPAM=$?

    # 2. Handle identified spam
    :0
    * ? $TEST $SPAM != 0
    /dev/null

    # ------------------------------------------------------------------------------------- #
    # Virus scan section ...                                                                #
    # ------------------------------------------------------------------------------------- #

    # 1. Run TrashScan
    :0
    * multipart
    * !^X-Virus-Scan:
    | $TRASHSCAN

    # 2. Filter tagged virus mails
    :0:
    * ^X-Virus-Scan: Suspicious
    mail.virus

    # ------------------------------------------------------------------------------------- #
    # User section ...                                                                      #
    # ------------------------------------------------------------------------------------- #

    # 1. Forward trash@trashware.net to trash
    :0 c
    * ^(To|Cc):.*trash@trashware\.net
    ! trash

    # 2. Forward trashware@gmx.net to trash
    :0 c
    * ^(To|Cc):.*trashware@gmx\.net
    ! trash

    # 3. Forward anyuser@anyhow.de to anyuser
    :0 c
    * ^(To|Cc):.*anyuser@anyhow\.de
    ! anyuser

    # 4. [ ... ]

    # ------------------------------------------------------------------------------------- #
    # Bounce section ...                                                                    #
    # ------------------------------------------------------------------------------------- #

    # Raise a flag if the message was filed
    :0
    # 1. trash@trashware.net            2. trashware@gmx.net            3. anyuser@anyhow.de
    * (^(To|Cc):.*trash@trashware\.net)|(^(To|Cc):.*trashware@gmx\.net)|(^(To|Cc):.*anyuser@anyhow\.de)
    {
        HOST="_done_"
    }

    # Bounce the rest
    :0
    | ($FORMAIL -A "X-Loop: mailservice.trashware@gmx.net" -r -k | \
	$GAWK '{print} /^/ && !HEADER {system("$CAT procmail.unknown"); HEADER=1}') | \
	$SENDMAIL -t

    exit
    ---------------------------------------- End Cut ----------------------------------------

2.2 Content of procmail.unknown:
    --------------------------------------- Begin Cut ---------------------------------------
    Sorry, the user you wanted to contact is not listed on this system.
    -------------------------------------------------------------------
    ---------------------------------------- End Cut ----------------------------------------

2.3 Content of procmail.mailservice:
    --------------------------------------- Begin Cut ---------------------------------------
    Sorry, the user you wanted to contact is a mail robot.

    Hint for Spammers:
    You are caught by our SPAM TRAPPING SYSTEM, which means
    that your data were reported to several collaborative
    spam filtering databases, helping to keep the web clean.
    Your data were also reported to the service provider you
    used, requesting that they take appropriate internal
    actions.

    Hint for Advertisers:
    Now you are GLOBALLY BLACKLISTED, which means that your
    data were added to public accessible blocklists.

    Hint for Service Providers:
    I think your host was faked or in any way spoofed, I trust
    you would still like to know about it.
    Please correct this mistake as soon as possible.

    ----------------------------------------------------------
    ---------------------------------------- End Cut ----------------------------------------

3. Enjoy  ;-)


If you like TrashScan or if you run it on a regular basis let me know.
Suggestions are welcome...


CONTACT
-------

Email: trashware@gmx.de
Web: http://trashware.mirrorz.com


DISCLAIMER
----------

* Copyright (C) 2002 - 2004 Trashware
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at you option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public Licence for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA


Have fun!
Greetinx from Trash