Re: [Clamav-users] Cannot update virus database

2006-04-12 Thread Rob MacGregor
On 4/12/06, Felipe Tonioli <[EMAIL PROTECTED]> wrote:
> Hi All,
>
> After i upgrade to 88.1 i can´t update my virus database.
>
> Whats Wrong ?
<---SNIP--->
> ERROR: Can't get information about database.clamav.net: Unrecoverable DNS 
> error
> Connection with database.clamav.net (IP: ???) failed.

DNS problems (at your end) - what if you do:

nslookup database.clamav.net

--
 Please keep list traffic on the list.
Rob MacGregor
  Whoever fights monsters should see to it that in the process he
doesn't become a monster.  Friedrich Nietzsche
___
http://lurker.clamav.net/list/clamav-users.html


RE: [Clamav-users] Cannot update virus database

2006-04-12 Thread Felipe Tonioli
I've checked this before post to list. but there go the results

nslookup database.clamav.net
Server: 10.0.4.2
Address:10.0.4.2#53

Non-authoritative answer:
database.clamav.net canonical name = db.local.clamav.net.
db.local.clamav.net canonical name = db.america1.clamav.net.

nslookup db.local.clamav.net.
Server: 10.0.4.2
Address:10.0.4.2#53

Non-authoritative answer:
db.local.clamav.net canonical name = db.america1.clamav.net.


nslookup db.america1.clamav.net.
Server: 10.0.4.2
Address:10.0.4.2#53

** server can't find db.america1.clamav.net: NXDOMAIN


I solved the update problem adding a DatabaseMirror.


Tks in advance,
Felipe Tonioli




> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Rob MacGregor
> Sent: quarta-feira, 12 de abril de 2006 04:18
> To: ClamAV users ML
> Subject: Re: [Clamav-users] Cannot update virus database
> 
> 
> On 4/12/06, Felipe Tonioli <[EMAIL PROTECTED]> wrote:
> > Hi All,
> >
> > After i upgrade to 88.1 i can´t update my virus database.
> >
> > Whats Wrong ?
> <---SNIP--->
> > ERROR: Can't get information about database.clamav.net: 
> Unrecoverable DNS error
> > Connection with database.clamav.net (IP: ???) failed.
> 
> DNS problems (at your end) - what if you do:
> 
> nslookup database.clamav.net
> 
> --
>  Please keep list traffic on the list.
> Rob MacGregor
>   Whoever fights monsters should see to it that in the process he
> doesn't become a monster.  Friedrich Nietzsche
> 

___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] Strange problem

2006-04-12 Thread JT Justman
Rick Macdougall wrote:
> Hi,
> 
> After upgrading to clamav 0.88.1 I was getting this in my log files
> 
> ERROR: Problem with internal logger. Please check the permissions on the
> /dev/stdout file.
> 
> The permissions were rw for all users.
> 
> clamd.conf contains
> 
> LogFile /dev/stdout
> 
> Only seems to affect FreeBSD 4.8 though, all my Slackware, CentOS,
> Fedora, Debian and RedHat Enterprise machines are ok with the exact same
> config.
> 
> Any changes in the logging functions that might explain this ?
> 

My (CentOS) systems use a physical file:

LogFile /var/log/clamav/clamd.log

Perhaps your run script was doing redirection and it was changed by the
upgrade?

JT

--
|Waiting to fix the world since 1995|
"Progress isn't made by early risers. It's made by lazy men trying to
find easier ways to do something."
- Robert Heinlein
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] Strange problem

2006-04-12 Thread Rick Macdougall

JT Justman wrote:

Rick Macdougall wrote:

Hi,

After upgrading to clamav 0.88.1 I was getting this in my log files

ERROR: Problem with internal logger. Please check the permissions on the
/dev/stdout file.

The permissions were rw for all users.

clamd.conf contains

LogFile /dev/stdout

Only seems to affect FreeBSD 4.8 though, all my Slackware, CentOS,
Fedora, Debian and RedHat Enterprise machines are ok with the exact same
config.

Any changes in the logging functions that might explain this ?



My (CentOS) systems use a physical file:

LogFile /var/log/clamav/clamd.log

Perhaps your run script was doing redirection and it was changed by the
upgrade?


I don't think so since the upgrade on every other server went just fine. 
 I assume it has something to do with FreeBSD and the logging function 
of clamav but I have no idea what may have changed in clamav to cause it.


Rick

___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] Strange problem

2006-04-12 Thread Richard Feldmann
Rick Macdougall spake thusly on Tue, Apr 11, 2006 at 07:28:16PM -0400:

> LogFile /dev/stdout

--- end quoted text ---

Try logging to /dev/stderr instead. I use tcpserver and daemontools with qmail 
to control my stuff. When I first started using clamd I found that stdout would 
never work for me as logging from within clam, but stderr did. I think it was 
actually built that way in clamd, though maybe it's different now.

Regards,
Richard

-- 
Did this email or post help you? If so, please rate
me at affero: http://rate.affero.net/RhunDraco


pgpsNRtpX1bdD.pgp
Description: PGP signature
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] Strange problem

2006-04-12 Thread Rick Macdougall

Richard Feldmann wrote:

Rick Macdougall spake thusly on Tue, Apr 11, 2006 at 07:28:16PM -0400:


LogFile /dev/stdout


--- end quoted text ---

Try logging to /dev/stderr instead. I use tcpserver and daemontools with qmail 
to control my stuff. When I first started using clamd I found that stdout would 
never work for me as logging from within clam, but stderr did. I think it was 
actually built that way in clamd, though maybe it's different now.


Hi,

Tried that as well, same error

ERROR: Problem with internal logger. Please check the permissions on the 
/dev/stderr file.


Regards,

Rick
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] cannot use yum to upgrade to 0.88.1

2006-04-12 Thread Ralf Durkee
Has anybody built trustworthy rpm's for ClamAV for Fedora Core 4, or 
would be willing to make them available if I built them? 


-- Ralf Durkee, CISSP, GSEC, GCIH
Principal Security Consultant
http://rd1.net



Ralf Durkee wrote:


Frank Elsner wrote:

On Mon, 10 Apr 2006 12:04:09 +0100 Obantec Support wrote:
 

Hi

i am using FC3 and currently running 0.88, freshclam log reports out 
of date

clamav so i did yum update clamav
only to get the response

"Could not find update match for clamav
No Packages marked for Update/Obsoletion"

i am using http://crash.fce.vutbr.cz/yum-repository.html and did use 
it last

time i upgraded. have i missed something?



Yes. FC3 is legacy. See http://fedoraproject.org/wiki/Legacy

  
There's also nothing available for FC4 for rpm updates, it would seem 
that there ought to be a more leniency in these messages rather than 
immediately declaring every past release as outdated and sending 
alarming uppercase warnings that require some of us to explain that 
the systems is in no immediate danger.  This is especially true when 
the release doesn't seem to contain any serious security fixes.

-- Ralf Durkee, CISSP, GSEC, GCIH
Principal Security Consultant



___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] cannot use yum to upgrade to 0.88.1

2006-04-12 Thread Obantec Support

- Original Message - 
From: "Frank Elsner" <[EMAIL PROTECTED]>
To: 
Sent: Monday, April 10, 2006 12:24 PM
Subject: Re: [Clamav-users] cannot use yum to upgrade to 0.88.1


> On Mon, 10 Apr 2006 12:04:09 +0100 Obantec Support wrote:
> > Hi
> >
> > i am using FC3 and currently running 0.88, freshclam log reports out of
date
> > clamav so i did yum update clamav
> > only to get the response
> >
> > "Could not find update match for clamav
> > No Packages marked for Update/Obsoletion"
> >
> > i am using http://crash.fce.vutbr.cz/yum-repository.html and did use it
last
> > time i upgraded. have i missed something?
>
> Yes. FC3 is legacy. See http://fedoraproject.org/wiki/Legacy
>
>
>
> --Frank Elsner
>
> ___
> http://lurker.clamav.net/list/clamav-users.html
>
>
Thanks Frank

I am now all up to date.

freshclam daemon 0.88.1 (OS: linux-gnu, ARCH: i386, CPU: i386)
ClamAV update process started at Wed Apr 12 16:10:16 2006
main.cvd is up to date (version: 37, sigs: 46700, f-level: 7, builder:
ccordes)
daily.cvd is up to date (version: 1394, sigs: 4000, f-level: 7, builder:
ccordes)

Mark

___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] cannot use yum to upgrade to 0.88.1

2006-04-12 Thread James Kosin
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
 
Ralf Durkee wrote:
> Has anybody built trustworthy rpm's for ClamAV for Fedora Core 4,
> or would be willing to make them available if I built them? -- Ralf
> Durkee, CISSP, GSEC, GCIH Principal Security Consultant
> http://rd1.net
>
DAG does a good job.
Check the clamav website for information.

There is also Petr Kristof's site for FC4
http://crash.fce.vutbr.cz/crash-hat/4/clamav/


- -James
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
 
iD4DBQFEPSOxkNLDmnu1kSkRAkPfAJiFWHBbIgPkaKCAkxmHqzImeBZ1AJ9LMOTu
T7hF4XEVbdr2L73716rlyA==
=EK5y
-END PGP SIGNATURE-

-- 
Scanned by ClamAV - http://www.clamav.net

___
http://lurker.clamav.net/list/clamav-users.html


[Clamav-users] clamav-0.88.1 segmentation fault on 64bit systems

2006-04-12 Thread Vieri Di Paola
Please read the bug report:
http://bugs.gentoo.org/show_bug.cgi?id=129702

Clamd 0.88.1 on 64bit Linux systems seems to be
broken.

A patch is proposed.


__
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] clamav-0.88.1 segmentation fault on 64bit systems

2006-04-12 Thread Vieri Di Paola
Thanks Damian.

--- Damian Menscher <[EMAIL PROTECTED]> wrote:

> So, this is the third report I've seen of people
> getting bitten by this 
> bug.  I've been warning friends not to upgrade as a
> result.
> 
> There needs to be another release to correct this
> issue.  It's silly to 
> argue otherwise (so please don't bother).
> 
> Damian
> 
> On Wed, 12 Apr 2006, Vieri Di Paola wrote:
> 
> > Please read the bug report:
> > http://bugs.gentoo.org/show_bug.cgi?id=129702
> >
> > Clamd 0.88.1 on 64bit Linux systems seems to be
> > broken.
> >
> > A patch is proposed.


__
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] cannot use yum to upgrade to 0.88.1

2006-04-12 Thread Ralf Durkee




James Kosin wrote:

Ralf Durkee wrote:
  

Has anybody built trustworthy rpm's for ClamAV for Fedora Core 4,
or would be willing to make them available if I built them? -- Ralf
Durkee, CISSP, GSEC, GCIH Principal Security Consultant
http://rd1.net



DAG does a good job.
Check the clamav website for information.

There is also Petr Kristof's site for FC4
http://crash.fce.vutbr.cz/crash-hat/4/clamav/

  


There wasn't anything available at either site when I posted it, but 
there is now at both sites.  Thanks!


-- Ralf Durkee, CISSP, GSEC, GCIH
Principal Security Consultant
http://rd1.net


___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] clamav-0.88.1 segmentation fault on 64bit systems

2006-04-12 Thread Damian Menscher
So, this is the third report I've seen of people getting bitten by this 
bug.  I've been warning friends not to upgrade as a result.


There needs to be another release to correct this issue.  It's silly to 
argue otherwise (so please don't bother).


Damian

On Wed, 12 Apr 2006, Vieri Di Paola wrote:


Please read the bug report:
http://bugs.gentoo.org/show_bug.cgi?id=129702

Clamd 0.88.1 on 64bit Linux systems seems to be
broken.

A patch is proposed.


__
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
___
http://lurker.clamav.net/list/clamav-users.html



Damian Menscher
--
-=#| <[EMAIL PROTECTED]> www.uiuc.edu/~menscher/ Ofc:(650)253-2757 |#=-
-=#| The above opinions are not necessarily those of my employers. |#=-
___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-devel] Re: [Clamav-users] clamav-0.88.1 segmentation fault on 64bit systems

2006-04-12 Thread Stephen Gran
On Wed, Apr 12, 2006 at 12:10:53PM -0500, Damian Menscher said:
> So, this is the third report I've seen of people getting bitten by
> this bug.  I've been warning friends not to upgrade as a result.
> 
> There needs to be another release to correct this issue.  It's silly
> to argue otherwise (so please don't bother).

No point holding off.  This bug has, as far as I can tell from the CVS
timestamps, been there since mid-November.  I have had several reports
of 64 bit issues via the Debian BTS before now (oddly, starting roughly
the same time as the CVS changes that added cli_dbgmsg), but hadn't been
able to track it down to that.  So, anyone running clamav version >=0.88
already has the bug.  I am not sure why it's manifesting itself now,
but it's not particular to this release.

Take care,
-- 
 --
|  Stephen Gran  | QOTD:  "I'd never marry a woman who |
|  [EMAIL PROTECTED] | didn't like pizza... I might play  golf |
|  http://www.lobefin.net/~steve | with her, but I wouldn't marry her!"|
 --


signature.asc
Description: Digital signature
___
http://lurker.clamav.net/list/clamav-users.html


[Clamav-users] Freshclam dying with SIGPIPE?

2006-04-12 Thread Robert Zilbauer

Since updating to 0.88.1 I've got a few systems (Solaris 9 & 10 - 
Sparc) where freshclam just dies during update checks. Not all the 
time, though, just occasionally. 

It puts an incomplete entry like this into the log and then 
the process dies: 

--
freshclam daemon 0.88.1 (OS: solaris2.10, ARCH: sparc, CPU: sparc)
ClamAV update process started at Wed Apr 12 12:55:04 2006
main.cvd is up to date (version: 37, sigs: 46700, f-level: 7, builder: ccordes)


I've been running ClamAV without any trouble (great software,
by the way :) up 'til now. I checked through the archives, but
didn't see anything that was too similar to this. Any ideas?


In case it helps at all, I was able to get a truss of one such 
event, here's the end of it:

...
6518:   stat("/etc/resolv.conf", 0xFFBFE8D0)= 0
6518:   sysconfig(_CONFIG_OPEN_FILES)   = 1024
6518:   so_socket(PF_INET, SOCK_DGRAM, IPPROTO_IP, "", SOV_DEFAULT) = 0
6518:   connect(0, 0xFF20F208, 16, SOV_DEFAULT) = 0
6518:   send(0, "E4F501\0\001\0\0\0\0\0\0".., 40, 0)= 40
6518:   pollsys(0xFFBFE3B0, 1, 0xFFBFE220, 0x)  = 1
6518:   recvfrom(0, "E4F58180\001\001\007\002".., 512, 0, 0xFFBFE2A8, 
0xFFBFE3AC) = 238
6518:   close(0)= 0
6518:   time()  = 1144871208
6518:   open("main.cvd", O_RDONLY)  = 0
6518:   ioctl(0, TCGETA, 0xFFBFEC94)Err#25 ENOTTY
6518:   fstat64(0, 0xFFBFED08)  = 0
6518:   brk(0x00034D80) = 0
6518:   brk(0x00036D80) = 0
6518:   fstat64(0, 0xFFBFEBB0)  = 0
6518:   read(0, " C l a m A V - V D B : 0".., 8192) = 8192
6518:   llseek(0, 0xE200, SEEK_CUR) = 512
6518:   close(0)= 0
6518:   write(7, " m a i n . c v d   i s  ".., 80)  = 80
6518:   open("daily.cvd", O_RDONLY) = 0
6518:   ioctl(0, TCGETA, 0xFFBFEC94)Err#25 ENOTTY
6518:   fstat64(0, 0xFFBFED08)  = 0
6518:   fstat64(0, 0xFFBFEBB0)  = 0
6518:   read(0, " C l a m A V - V D B : 1".., 8192) = 8192
6518:   llseek(0, 0xE200, SEEK_CUR) = 512
6518:   close(0)= 0
6518:   so_socket(PF_INET, SOCK_STREAM, IPPROTO_IP, "", SOV_DEFAULT) = 0
6518:   open("/etc/netconfig", O_RDONLY|O_LARGEFILE)= 1
6518:   fcntl(1, F_DUPFD, 0x0100)   = 256
6518:   close(1)= 0
6518:   read(256, " # p r a g m a   i d e n".., 1024)   = 1024
6518:   read(256, " t s   t p i _ c".., 1024)   = 215
6518:   read(256, 0x0002BF50, 1024) = 0
6518:   lseek(256, 0, SEEK_SET) = 0
6518:   read(256, " # p r a g m a   i d e n".., 1024)   = 1024
6518:   read(256, " t s   t p i _ c".., 1024)   = 215
6518:   read(256, 0x0002BF50, 1024) = 0
6518:   close(256)  = 0
6518:   open("/dev/udp", O_RDONLY)  = 1
6518:   ioctl(1, SIOCGLIFNUM, 0xFFBFEEE4)   = 0
6518:   close(1)= 0
6518:   door_info(6, 0xFFBFCE60)= 0
6518:   door_call(6, 0xFFBFCE48)= 0
6518:   connect(0, 0xFFBFF0B8, 16, SOV_DEFAULT) (sleeping...)
6518:   connect(0, 0xFFBFF0B8, 16, SOV_DEFAULT) Err#145 ETIMEDOUT
6518:   connect(0, 0xFFBFF0B8, 16, SOV_DEFAULT) = 0
6518:   times(0xFFBFEE78)   = 590960133
6518:   sysconfig(_CONFIG_CLK_TCK)  = 100
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)   = 590960133
6518:   times(0xFFBFEE78)  

Re: [Clamav-users] clamav-milter does not run

2006-04-12 Thread .rp
> Hello, I'm having problem with Clamav-milter.  I have clamav-0.88.
> [EMAIL PROTECTED]:~$ /usr/local/sbin/clamav-milter -loD
> /var/run/clamav/clmilter.sock --max-children=2

i had trouble in the past with the  o  option and took it out (replaced with n)

___
http://lurker.clamav.net/list/clamav-users.html


Re: [Clamav-users] cannot use yum to upgrade to 0.88.1

2006-04-12 Thread Steffen Kluge
On Wed, 2006-04-12 at 10:52 -0400, Ralf Durkee wrote:
> Has anybody built trustworthy rpm's for ClamAV for Fedora Core 4, or 
> would be willing to make them available if I built them? 

The Fedora Extras repository has them. Look no further.

Cheers
Steffen.



signature.asc
Description: This is a digitally signed message part
___
http://lurker.clamav.net/list/clamav-users.html