Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cempax
New Contributor

Password-protected attachments

Hello!

 

FortiMail 400F version 7.0.9 here. This FM is associated with a FortiSandbox solution. Under Archive Handling, we have Check archive content > Detect password protected archive enabled in our content profile. According to this article, this is supposed to be enough for FortiMail to detect pass-protected attached files and block them, but we find way many true positives slipping by.

 

The attachments are mostly zip, 7z, tar files, and the passwords aren't usually included in the body of the message.

 

I mention the FortiSandbox because every attachment gets sent to it and analysed while FortiMail waits for a result in order to deliver the email. FortiSandbox can't unzip it, TAC said it's because its password protected, it gets a clean verdict and thus sent through.

 

We're beginning to suspect that FortiSandbox is interfering with FortiMail's actions somehow. Are there any additional settings we can apply before looking into fortisandbox?

 

Thank you all for your time.

3 REPLIES 3
fiesta
New Contributor III

Hi,

 

FortiSandbox is interfering with FortiMail's actions is true since you configured it with submit and wait result.

Any password protected cannot be check for signatures and verdict will always be clean whether with/without fortisandbox, and it will always be send to fortisandbox first before checked by content filter (detect password) since the scanning always antispam > antivirus > content filter.

 

Best regards.

FWD~

FWD~
FWD~
colunjo1
New Contributor

you should also explain the vulnerabilities that the company is open to, that you cannot mitigate against, when unscannable attachments come in to random people in the company. a couple of recent examples of crypto eliminating medical records at hospitals or dashcam footage at major american police departments should do the trick

10.0.0.0.1 192.168.1.254
filiaks1
Contributor II

What about the file filter maybe test it for password protected?

 

Also strange that FortiSandbox does not have an option to mark password protected files as bad as this seems security gap.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors