2
Does anyone else have reports from clients about their AV software is blocking URL of SmarterMail webmail?
Question asked by Webio - 10/15/2024 at 3:37 AM
Unanswered
Hello,

today I'm getting some support tickets and calls from multiple customers reporting that their AV software is closing connection to my SmarterMail URL.

AV software: mostly Avast but also Norton and Avira

On my end I use Bitdefender and I'm not getting any reports about it. Also I've checked example message from webmail which caused issue (API call from webmail) using virustotal and also it didn't reported this as some malicious content.

Thanks

Build: 9042

EDIT:


Issue occurs after logging in and opening message (when API call to get message is being performed)

8 Replies

Reply to Thread
0
Ricardo Ranieri Replied
Hi,

We have the same problem here already on the login screen, it is randomly blocked
0
Webio Replied
Norton error view:

2
Sébastien Riccio Replied
Isn't this because the mailbox you're connecting with received a mail that contains some phising urls/patterns ?
Sébastien Riccio System & Network Admin https://swisscenter.com
0
Webio Replied
It's hard to tell. We've checked email content of message from client mailbox which was causing alarm for Avast and Virustotal didn't detected anything for this content when passed as .txt file.

Problem is only with webmail and after logging in where webmail is maiking POST request to

/api/v1/mail/message

to retrieve message content. After that operation user gets Empty message in webmail with error message not available or something similar or is being logged out.
0
Jereming Chen Replied
Employee Post
Unfortunately it is hard to tell what signature Avast or Norton are seeing that is triggering this response. Because the message is arriving via an API call, it does just arrive as a json so I can see the plain text or html code having something that could trigger these AV programs. 

Considering you know this is your own server, I would suggest excluding it from these scans. After all, you can have antispam and antivirus run on your spool. If you want to have Avast or Norton perform these checks, you can enable the proc folder and let these AV's run on that folder as SmarterMail processes the mail through the spool.
Jereming Chen System/Network Administrator SmarterTools Inc. www.smartertools.com
0
Webio Replied
This is not something runned serverside but on my clients side. Browser API call from webmail to fetch message content in webmail is being catched and dropped by AV software. It looks somehow that Avast and Norton could be using the same database for phishing because this can'be be coincidence that both AV software are reporting the same issue.

My suggestion for clients was adding webmail URL to whitelisting in their AV soft. I've also reported webmail URL to Avast and Norton using false positive form but I was wondering if this is also something that occured to other forum/community users.
0
Nathan Replied
Similar random reports with Chrome marking the page as 'unsafe' but fine for other users including our internal users.
1
Jade B Replied
We've had the same thing and reached out to F-Secure to have the false positive removed.

They were kind enough to advise that a file had triggered the event and upon review we found that a user had uploaded a file using file sharing and this file was subsequently downloaded and flagged.

Reply to Thread