Skip to content

🪲 ORCA.110 test logic doesn't match description #1393

@SamErde

Description

@SamErde

Describe the bug

The "ORCA.110: Internal Sender notifications are disabled" test description does not match what gets checked.

Notifying internal senders about malware detected in email messages could have negative impact. An adversary with access to an already compromised mailbox may use this information to verify effectiveness of malware detection.

Disable notifying internal senders of malware detection.

Image

It (appropriately) instructs you to not notify internal senders of malware detection. However, the policy setting being checked is "Notify an admin about undelivered messages from internal senders."

Image

Would like verification from others who can confirm my observation or explain that I'm wrong. 🙃

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions