1
Potentially dangerous scripts
Problem reported by Lennart Eliasson - 7/12/2022 at 5:23 AM
Not A Problem
Windows Server 2022 with Smartermail Enterprise 15.7

We actually have some customers who still use POP3. Recently, we have received complaints from more than one customer that they cannot retrieve their emails.
Extensive debugging with configuration change in their Mac without resolving the issue. Logged in to webmail, we see that there are new emails.
However, when reviewing all messages, we notice that some emails show "Potentially dangerous scripts". When we took the chance to delete these, the emails started coming in to their computer.
The problem was solved for today, but tomorrow it may come back when new emails arrive.
What can we do to fix this problem permanently?

9 Replies

Reply to Thread
0
Tony Scholz Replied
Employee Post
Hello Lennart, 

I would suggest making sure that your POP logs are set to detailed and see if there is a better error message there to see what needs to be done to resolve the issue? 

Thank you
Tony Scholz System/Network Administrator SmarterTools Inc. www.smartertools.com
0
Lennart Eliasson Replied
Hello Tony,

Thanks.

Our settings for POP logs are detailed.

[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] connected at 7/12/2022 8:40:12 AM
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] CAPA
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] USER jan@xxxxxxxxxxxxxxx.com
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] PASS XXXX
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] jan@xxxxxxxxxxxxxxx.com logged in
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] STAT
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] +OK 45 11412789
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] UIDL
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] uidl list given for 45 messages
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] LIST
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] list response given with 45 messages. 
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] RETR 23
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] retr completed for message 23
[2022.07.12] 08:40:12 [xx.xxx.xx.xx][57042148] disconnected at 7/12/2022 8:40:12 AM
I guess number 23 is one of the emails that is the culprit.

After removing email with "Potentially dangerous scripts"

[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] connected at 7/12/2022 8:45:03 AM
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] CAPA
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] USER jan@xxxxxxxxxxxxxxx.com
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] PASS XXXX
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] jan@xxxxxxxxxxxxxxx.com logged in
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] STAT
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] +OK 41 11076870
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] UIDL
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] uidl list given for 41 messages
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] LIST
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] list response given with 41 messages. 
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] RETR 22
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] retr completed for message 22
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] RETR 23
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] retr completed for message 23
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] RETR 24
[2022.07.12] 08:45:03 [xx.xxx.xx.xx][57622907] retr completed for message 24
Etc. for message 25-38
[2022.07.12] 08:45:08 [xx.xxx.xx.xx][57622907] RETR 39
[2022.07.12] 08:45:08 [xx.xxx.xx.xx][57622907] retr completed for message 39
[2022.07.12] 08:45:08 [xx.xxx.xx.xx][57622907] RETR 40
[2022.07.12] 08:45:08 [xx.xxx.xx.xx][57622907] retr completed for message 40
[2022.07.12] 08:45:08 [xx.xxx.xx.xx][57622907] RETR 41
[2022.07.12] 08:45:11 [xx.xxx.xx.xx][57622907] retr completed for message 41
[2022.07.12] 08:45:15 [xx.xxx.xx.xx][57622907] QUIT
[2022.07.12] 08:45:15 [xx.xxx.xx.xx][57622907] disconnected at 7/12/2022 8:45:15 AM
0
Tony Scholz Replied
Employee Post
Hello, 

Looks like it, Can you pull up the pop logs for the connecting client? See if there is an error message there that is more descriptive?  

Thank you
Tony Scholz System/Network Administrator SmarterTools Inc. www.smartertools.com
0
Lennart Eliasson Replied
Hi,

Unfortunately, I do not have the opportunity to do so.
But I can add that he also has an iPad (with IMAP) and it has worked ok all the time.
Could it be that his mac computer has an antivirus program that responds and blocks the download with POP when it hits a suspicious email?

0
Tony Scholz Replied
Employee Post
Hello Lennart. 

If this issue is only occurring on the one device and works for the same account on other machines then it is most likely something on the machine or in the client. An AV could be the culprit. 

You can try disabling the AV to see if this resolves the issue. You can also remove and re add the account to see if a clean install will resolve the issue. 

Thank you
Tony Scholz System/Network Administrator SmarterTools Inc. www.smartertools.com
0
Lennart Eliasson Replied
It turns out that a completely different customer is also having the same problem. They use Mac and have Kaspersky antivirus.
When I look in their inbox, I find some emails with the text:

Potentially dangerous scripts were removed from this message. Allow scripts.

I have a Windows 10 laptop with ESET antivirus (very good).
When I click Allow scripts, the warning text disappears, but my anti-virus program does not respond.
In the email there is also a link to view the email in the browser.
I click on the link and get the email in the browser.
My antivirus program is not responding.

Is something in Smartermail reacting incorrectly?
0
Zach Sylvester Replied
Employee Post
Hey Lennart, 

Thanks for reaching out again. This doesn't sound like a SmarterMail issue. The way that POP works is that it downloads the emails as is from the SmarterMail server and then displays them in the email client. While IMAP is a 2-way sync POP is only a one-way sync. So your antivirus hiding the text is a client-side problem sadly. 

Please let me know if you have any questions. 

Kind Regards, 


Zach Sylvester Software Developer SmarterTools Inc. www.smartertools.com
0
Lennart Eliasson Replied
Thanks Zach,
The email was ok, no virus.
My conclusion was that my antivirus software (ESET) saw the email as ok, while the customer's antivirus software (Kaspersky) mistakenly saw the email as suspicious and therefore blocked the download.
Could that be the answer to the problem?
0
Zach Sylvester Replied
Employee Post
Hey Lennart, 

That certainly could be. I would recommend reporting this issue to the antivirus vendor maybe this is a bug they can fix. For the time being, I would recommend disabling the email scanning. 

Kind Regards, 
Zach Sylvester Software Developer SmarterTools Inc. www.smartertools.com

Reply to Thread