Skip to main content
Contributor III
December 6, 2006
Question

BLOCKING EMBEDDED GIF ???

  • December 6, 2006
  • 16 replies
  • 9555 views
Hi All, F-60 : we are inundated with spam which carries embedded GIF images. This of course negates use of word filters to block. Although they can be succesfully blocked by including GIF in the FileBlock option this also blocks substantial valid mail. Also blocking by IP and URLs is possible but simply never ending and impractical as they' re ever-changing. I have raised this twice with Fortinet on the support page with two separate tickets and thay have no real solution. If anyone has experienced similar problems a solution will be most welcome. Tks, John

    16 replies

    Contributor III
    December 15, 2006
    John, I to have this exact issue not only on my Corporate firewall, but on dozens of client firewalls. THe only answer I can get from Fortinet Support is a new SPAM engine will be release mid 2007 that will adress the issue. I to have blocked GIF and that blockes to many emails, supports only offer of help was to maintain the black list and banned words list int he firewalls. No real solution. So I am still looking for a solution as well. Chris
    Contributor III
    December 23, 2006
    I found most of the gif file name is ten char. Therefore, I try to set the following File Pattern ??????????.GIF It seems okay
    simport
    New Member
    January 3, 2007
    I tried your trick, ??????????.gif and it works ! Even if not all gifspams are blocked, it helps a lot. ...But... I have one specific customer which uses gifs in his emails (a web designer...) and they are blocked. I added his address in the antispam whitelist, expecting they would be released...but they are still blocked. I think the antivirus pattern list is in 1st priority, before the antispam whitelist. Does anyone have idea to bypass this blocking rule for this email address? Thanks, JF
    Contributor III
    February 15, 2007
    Firstly, we should understand file pattern " *.gif" is not equal to " ??????????.gif" In your case I have the following idea 1) To Confirm the filename (gifs) which your customer is using (e.g. abcde12345.gif) 2) To Add the filename (e.g. abcde12345.gif) in the AntiVirs->File Pattern but set the action = ' Allow' Pls try and let me know result
    Contributor III
    January 3, 2007
    Hi all, I optimized the spam recognition by the banned Word list. I added:
    <BODY bgColor=#ffffff> 	 Wildcard 	Western 	Body
    Most mailclients define the Background color by a stylesheet, put the color in quotes(" ffffff" ), or use a lot more Parameters in this line. 0 False Positive yet.
    Contributor III
    January 3, 2007
    It didnt work to me I have tried <BODY bgColor=#ffffff> (wildcard body) " <BODY bgColor=#ffffff>" (wildcard body) (?i)\<BODY bgColor\=\#ffffff\> (regex body) all scored to 50 and the firewall profile set set as following set smtp scan block quarantine fragmail spamipbwl spamrbl spamemailbwl spamhdrcheck bannedword splice Any idea?
    Contributor III
    January 4, 2007
    The Antispam seems to ignore the Banned Word list in some cases. Today i recived this Mail, which sould be tagged by the BWL.
      ....  <STYLE></STYLE>  </HEAD>  <BODY bgColor=#ffffff>  <DIV><FONT face=Arial size=2><IMG alt=" "  hspace=0   src=" cid:000801c72f95$705c53c0$00000000@T1000"  align=baseline   border=0></FONT></DIV>  <DIV><FONT face=Arial size=2>Artists subscribe feedsee available feeds learn.   ....  
    Contributor III
    January 4, 2007
    How do you set the ??????????.gif value in FilePattern? When I try to enter the value in a ssh session i get this error:
      (filepattern)# edit "   token line: Unmatched double quote.  
    and if I use the web GUI I cannot set the blocking to smtp only
    simport
    New Member
    January 4, 2007
    To block for SMTP only, I created a protection profile specifically for smtp service and a banned word list only for this specific profile. So the gifs in web pages (or other services) aren' t blocked. JF
    Contributor III
    January 4, 2007
    I did it as well, however when I work in a ssh session, when I go to FilePattern section , following the quote I cannot type as value the question mark because an error appears (token line: Unmatched double quote) What I want to type is
    edit " ??????????.gif" 
    rwpatterson
    New Member
    January 4, 2007
    What I believe is going on here is that the switch is expecting a name, where you' re trying to input the value. Names cannot have special characters, or spaces (I think). ??????????.gif isn' t the name of the file pattern, it' s the value, isn' t it? Call it something like q10, and use the same value. See if that works.
    Contributor III
    January 4, 2007
    excerpt from FortiGate CLI Version 3.0 MR2 reference: Command syntax pattern (FortiGate-500 and below)
    config antivirus filepattern edit <filepattern_string> set action <allow | block> set active {ftp http imap nntp pop3 smtp im} end
    Example:
    config antivirus filepattern edit *.xyz set allow imap smtp pop3 set block http ftp end
    I realize that it ins' t a name, but the extension (or file pattern) itself
    rwpatterson
    New Member
    January 4, 2007
    Have you tried without the quotes?
    Contributor III
    January 4, 2007
    I did it.... and as soon as I type the question mark the fortigate shows me all the existing file extensions
    Eastwind
    New Member
    February 3, 2007
    I think many people are having the same problem, althought adding *.gif to antivirus pattern block will stop all email with gif coming in, but I notice notebooks that we got that have Forticlient 3.0 installed actually can catches embeded gif email and relief the customer from deleting them every 2nd hours from the inbox, anyone has that experience as well.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!