RE: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Mitch \(WebCob\)
> So does that mean you no longer use Exiscan's "demime" facility, because, > if I understand this correctly, it is sufficient to pass the mime parts > to clamd for scanning. Using it and ScanMail would appear to bring some > "competition" between Exiscan's demime and ClamAV's ScanMail. > > Could s

Re: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Niek
Кирилл Усатов said the following on 8/12/2004 5:44 AM GMT+2: I scan mail with clamav 0.75 on my gentoo. My bases is up to date. Clamdscan /virus_file Not catch a virus. You are probably scanning a broken sample. In any case, update to clamav 0.75.1. Regards, Niek Baakman

Re: [Clamav-users] SomeFool.P/Q occasionally passing through

2004-08-12 Thread Arthur Kerpician
Todd Lyons wrote: Brian Morrison wanted us to know: >Received: from localhost [127.0.0.1] by backup.ccina.ro with >SpamAssassin (2.60 1.212-2003-09-23-exp); Wed, 11 Aug 2004 17:53:00 >+0300 This is the last line of Received headers, so it never says exactly what host it came from. It was

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Кирилл Усатов
>Кирилл Усатов said the following on 8/12/2004 5:44 AM GMT+2: >> I scan mail with clamav 0.75 on my gentoo. >> >> My bases is up to date. >> >> Clamdscan /virus_file >> >> Not catch a virus. > >You are probably scanning a broken sample. >In any case, update to clamav 0.75.1. I update clamav

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Trog
On Thu, 2004-08-12 at 09:02, Кирилл Усатов wrote: > >Кирилл Усатов said the following on 8/12/2004 5:44 AM GMT+2: > >> I scan mail with clamav 0.75 on my gentoo. > >> > >> My bases is up to date. > >> > >> Clamdscan /virus_file > >> > >> Not catch a virus. > > > >You are probably scanning a br

[Clamav-users] error in Clamav 0.72 with EXIM 4.41

2004-08-12 Thread Silly Billy
Hi, I'm configuring my EXIM 4.41 with Clamav 0.72 .. the anti-virus installed and working fine but when i un-comment the following lines in exim4.conf acl_smtp_mime = acl_check_mime acl_smtp_data = acl_check_content av_scanner = clamd:/var/run/clamav/clamd and send mail ... to LOCAL/WAN user

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Fajar A. Nugraha
Eric Becker wrote: Although, he does bring up a good point about the ScanMail option still not being officially supported. While I haven't had any problems with the feature on my work's server, it certainly does raise problems with some network admins. ScanMail is not the only way to scan mai

Re: [Clamav-users] error in Clamav 0.72 with EXIM 4.41

2004-08-12 Thread Fajar A. Nugraha
Silly Billy wrote: Hi, I'm configuring my EXIM 4.41 with Clamav 0.72 .. You should try 0.75.1. 2004-08-12 12:50:28 1Bv9Pw-r3-I6 malware acl condition: clamd: unable to connect to UNIX socket /var/run/clamav/clamd (Permission denied) /var/run/clamav/clamd must be writable by exim user.

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Scott Call
On Thu, 12 Aug 2004, Odhiambo Washington wrote: So does that mean you no longer use Exiscan's "demime" facility, because, if I understand this correctly, it is sufficient to pass the mime parts to clamd for scanning. Using it and ScanMail would appear to bring some "competition" between Exiscan's d

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Кирилл Усатов
I'm update clamav to 0.75.1 Clamscan catch virus But clamdscan don't & clamav-milter don't stop infected mail -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Trog Sent: Thursday, August 12, 2004 2:11 PM To: [EMAIL PROTECTED] Subject: RE: [Clamav-users] W

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Trog
On Thu, 2004-08-12 at 10:31, Кирилл Усатов wrote: > I'm update clamav to 0.75.1 > Clamscan catch virus > But clamdscan don't > & clamav-milter don't stop infected mail Make sure you have ScanMail enabled in clamav.conf, that you've restarted clamd and that you don't have any old libclamav librar

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Кирилл Усатов
>On Thu, 2004-08-12 at 10:31, Кирилл Усатов wrote: >> I'm update clamav to 0.75.1 >> Clamscan catch virus >> But clamdscan don't >> & clamav-milter don't stop infected mail > >Make sure you have ScanMail enabled in clamav.conf, that you've >restarted clamd and that you don't have any old libclama

Re: [Clamav-users] (no subject)

2004-08-12 Thread Antony Stone
On Wednesday 11 August 2004 9:13 pm, [EMAIL PROTECTED] wrote: > Hi, > > I was wondering prior to version .05 (feb 10, 2004) what the real virus > installed with mail clam av was. Please can you rephrase your question? Version 0.05 of what? ClamAV does not install any viruses. Regards, Antony.

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Кирилл Усатов
I remove old version of clamav & install clamav .75.1 from tar.gz Clamav.conf _ LogFile /var/log/clamd.log LogFileMaxSize 16M LogTime LogSyslog User clamav LocalSocket /var/run/clamav/clamav.sock StreamSaveToDisk ScanMail ScanArchive ___ ls -l /usr/lib/clamav/ -rw-r--r-

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Trog
On Thu, 2004-08-12 at 12:25, Кирилл Усатов wrote: > > I have old libmilter.a: is it ? > I wouldn't have thought so. I guess you are scanning the file by hand rather than pushing it back through the mail system. You are running clamd as the user clamav - does that user have access rights to th

Re[2]: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread AV-report
Hello, Кирилл. You wrote, 12 августа 2004 г., 15:25:03: КУ> I remove old version of clamav КУ> & install clamav .75.1 from tar.gz КУ> Clamav.conf КУ> _ КУ> LogFile /var/log/clamd.log КУ> LogFileMaxSize 16M КУ> LogTime КУ> LogSyslog КУ> User clamav КУ> LocalSocket /var/run/clamav/clam

Re: [Clamav-users] Idea for more timely virusdb updates

2004-08-12 Thread Bart Silverstrim
On Aug 11, 2004, at 1:22 PM, Martin Konold wrote: Am Wednesday 11 August 2004 16:19 schrieb Bart Silverstrim: Hi Bart, DNS was developed exactly for this kind of purpose. Storing non-DNS related information for retrieval? As I understand the proposition (and the original lecture that this idea wa

Re: [Clamav-users] Idea for more timely virusdb updates

2004-08-12 Thread Bart Silverstrim
On Aug 11, 2004, at 10:40 AM, Damian Menscher wrote: On Wed, 11 Aug 2004, Lionel Bouton wrote: Since some time I am thinking of a bittorrent approach too. Bittorrent is quite efficient at distributing files and there are implementations allowing multiple trackers to distribute the remaining server-

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Damjan
> >Although, he does bring up a good point about the ScanMail option > >still not being officially supported. While I haven't had any > >problems with the feature on my work's server, it certainly does raise > >problems with some network admins. > > ScanMail is not the only way to scan mail vi

Re: [Clamav-users] Idea for more timely virusdb updates

2004-08-12 Thread Martin Konold
Am Thursday 12 August 2004 15:16 schrieb Bart Silverstrim: > > Abusing the DNS to directly transfer files etc is not appropriate as > > the DNS > > infrastructure is not ready for such kind of "abuse". > > Give it time...someone's going to do it. Well, people have tried to abuse it before fortuna

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Fajar Nugraha
On Thu, 12 Aug 2004 15:41:50 +0200 Damjan <[EMAIL PROTECTED]> wrote: Does anyone know what does CGPav use? Clamav ScanMail option or some internal mail demime-fier? cgpav is capable to rip attachments by itself. You can safely turn off ScanMail with cgpav. Regards, Fajar --

Re: [Clamav-users] Mail-ClamAV installed virus

2004-08-12 Thread junkmail
Hi, Sorry for he confusion. The virus I'm referring to is found in a CPAN module archive Mail-ClamAV-0.01.tgz < Mail-ClamAV-0.05.tgz http://www.cpan.org/modules/by-authors/id/S/SA/SABECK/ The change log in 0.05 mentions that the "real" virus was replaced by the ecair virus signature. A virus sca

[Clamav-users] Anyone using milter, clamav with Mac OSX?

2004-08-12 Thread Randall Perry
I'm still having trouble trying to find info on using milter, clamav with OSX. I assume I need to compile clamav-milter, but in the INSTALL notes all is says about OSX is this: Sendmail on MacOS/X (10.1) is provided without a development package so this can't be run "out of the box" Any help is

Re: [Clamav-users] Mail-ClamAV installed virus

2004-08-12 Thread Trog
On Thu, 2004-08-12 at 15:07, [EMAIL PROTECTED] wrote: > > If this is the wrong list to post this or these CPAN modules have nothing > to do with the clamav project I apologize for the interruption. The second of those two options. -trog signature.asc Description: This is a digitally signed m

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Nigel Horne
> Although, he does bring up a good point about the ScanMail option > still not being officially supported. While I haven't had any > problems with the feature on my work's server, it certainly does raise > problems with some network admins. ScanMail should be safe in the CVS/daily snapshot ve

[Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Plant, Dean
I need to increase the ArchiveMaxCompressionRatio in clamscan as I have had a few zips being incorrectly identified as oversized zips. I first increased the ArchiveMaxCompressionRatio in clamav.conf but the zip file was still incorrectly identified. From reading the changelog it looks like that th

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Trog
On Thu, 2004-08-12 at 15:58, Plant, Dean wrote: > I need to increase the ArchiveMaxCompressionRatio in clamscan as I have had > a few zips being incorrectly identified as oversized zips. > > I first increased the ArchiveMaxCompressionRatio in clamav.conf but the zip > file was still incorrectly id

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Tomasz Kojm
On Thu, 12 Aug 2004 15:58:30 +0100 "Plant, Dean" <[EMAIL PROTECTED]> wrote: > I need to increase the ArchiveMaxCompressionRatio in clamscan as I > have had a few zips being incorrectly identified as oversized zips. > > I first increased the ArchiveMaxCompressionRatio in clamav.conf but > the zip

[Clamav-users] Re: Anyone using milter, clamav with Mac OSX?

2004-08-12 Thread David Champion
* On 2004.08.12, in <[EMAIL PROTECTED]>, * "Randall Perry" <[EMAIL PROTECTED]> wrote: > I'm still having trouble trying to find info on using milter, clamav with > OSX. > > I assume I need to compile clamav-milter, but in the INSTALL notes all is > says about OSX is this: > > Sendmail on Ma

Re: [Clamav-users] Anyone using milter, clamav with Mac OSX?

2004-08-12 Thread Erich Titl
At 16:09 12.08.2004, Randall Perry wrote: I'm still having trouble trying to find info on using milter, clamav with OSX. AFAIK you should be able to recompile sendmail, Then you get the latest version with all goodies. cheers Erich THINK Püntenstrasse 39 8143 Stallikon mailto:[EMAIL PROTECTED] PG

RE: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Plant, Dean
Tomasz Kojm wrote: > On Thu, 12 Aug 2004 15:58:30 +0100 > "Plant, Dean" <[EMAIL PROTECTED]> wrote: > >> I need to increase the ArchiveMaxCompressionRatio in clamscan as I >> have had a few zips being incorrectly identified as oversized zips. >> >> I first increased the ArchiveMaxCompressionRatio

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Charlie Watts
On Thu, 12 Aug 2004, Tomasz Kojm wrote: > On Thu, 12 Aug 2004 <[EMAIL PROTECTED]> wrote: > > I need to increase the ArchiveMaxCompressionRatio in clamscan as I > > have had a few zips being incorrectly identified as oversized zips. > > > > I first increased the ArchiveMaxCompressionRatio in clamav.

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Charlie Watts
On Thu, 12 Aug 2004, Charlie Watts wrote: > On Thu, 12 Aug 2004, Tomasz Kojm wrote: > > On Thu, 12 Aug 2004 <[EMAIL PROTECTED]> wrote: > > > I need to increase the ArchiveMaxCompressionRatio in clamscan as I > > > have had a few zips being incorrectly identified as oversized zips. > > > > > > I fi

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Tomasz Kojm
On Thu, 12 Aug 2004 10:06:40 -0600 (MDT) Charlie Watts <[EMAIL PROTECTED]> wrote: > So a --max-ratio of 12 should be sufficient (right?), but isn't. Even > a--max-ratio of 93 isn't sufficient. The file isn't scanned correctly > until--max-ratio is 94 or above. I see nothing strange in that, so wh

Re: [Clamav-users] Oversized zips with clamscan

2004-08-12 Thread Charlie Watts
On Thu, 12 Aug 2004, Tomasz Kojm wrote: > I see nothing strange in that, so what's the point ? The limit is > calculated on a per file basis and some files in the archive have big > compression ratios, e.g. That explains everything - per-file, rather than per-archive. Thank you muchly. I was assu

Re: [Clamav-users] SomeFool.P/Q occasionally passing through

2004-08-12 Thread Arthur Kerpician
Arthur Kerpician wrote: Todd Lyons wrote: Brian Morrison wanted us to know: >Received: from localhost [127.0.0.1] by backup.ccina.ro with >SpamAssassin (2.60 1.212-2003-09-23-exp); Wed, 11 Aug 2004 17:53:00 >+0300 This is the last line of Received headers, so it never says exactly what host it

Re: [Clamav-users] OpenSource Clamav not ready?

2004-08-12 Thread Philip Ershler
On Thursday, August 12, 2004, at 07:41 AM, Damjan wrote: Although, he does bring up a good point about the ScanMail option still not being officially supported. While I haven't had any problems with the feature on my work's server, it certainly does raise problems with some network admins. ScanMa

Re: [Clamav-users] error in Clamav 0.72 with EXIM 4.41

2004-08-12 Thread Brian Morrison
On Thu, 12 Aug 2004 15:57:26 +0700 in [EMAIL PROTECTED] "Fajar A. Nugraha" <[EMAIL PROTECTED]> wrote: > Silly Billy wrote: > > >Hi, > >I'm configuring my EXIM 4.41 with Clamav 0.72 .. > > > > > You should try 0.75.1. > > >2004-08-12 12:50:28 1Bv9Pw-r3-I6 malware acl > >condition: clamd

[Clamav-users] TCP streaming and Java

2004-08-12 Thread Sean Radford
Hi, I'm looking at possibly integrating ClamAV into a project of mine and would appreciate any advice from people before embarking... Basically the application is a J2EE web application where users can upload files. I wish to virus check the files which will commonly be Microsoft Word documents

[Clamav-users] Freshclam cron interval

2004-08-12 Thread Philip Ershler
What do folks think is an appropriate interval for a cron job to run freshclam? Is once an hour reasonable? Thanks, Phil --- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk Sonic D

Re: [Clamav-users] Freshclam cron interval

2004-08-12 Thread Jim Maul
Quoting Philip Ershler <[EMAIL PROTECTED]>: What do folks think is an appropriate interval for a cron job to run freshclam? Is once an hour reasonable? Once an hour is what i run. But please dont run it on the hour. Jim --- SF.Net email is spons

Re: [Clamav-users] Freshclam cron interval

2004-08-12 Thread Damian Menscher
On Thu, 12 Aug 2004, Philip Ershler wrote: > What do folks think is an appropriate interval for a cron job to run > freshclam? Is once an hour reasonable? Depends on your setup. If you're running a small-scale system, run it every 2 hours. If you have 500-5000 users, run it once an hour. If ov

Re: [Clamav-users] Segmentation Fault in clamav-milter

2004-08-12 Thread David Champion
* On 2004.08.05, in <[EMAIL PROTECTED]>, * "Robert Schmidt" <[EMAIL PROTECTED]> wrote: > #0 0x0804c0d7 in clamfi_connect () > (gdb) bt > #0 0x0804c0d7 in clamfi_connect () > #1 0x08051d2b in st_connectinfo () > #2 0x0856bce0 in ?? () > #3 0x015f7d94 in ?? () After working with Nigel to

RE: [Clamav-users] Worm.Mydoom.M

2004-08-12 Thread Кирилл Усатов
>> >> I have old libmilter.a: is it ? >> > >I wouldn't have thought so. > >I guess you are scanning the file by hand rather than pushing it back >through the mail system. > >You are running clamd as the user clamav - does that user have access >rights to the file you are trying to scan? > >What d

[Clamav-users] Errors with MacOS X Panther and libbz2

2004-08-12 Thread Pascal Oberndoerfer
Hello all. I have a problem with make on MacOS X Panther 10.3.5. I searched the archives and found the usual "run 'sudo ranlib /usr/lib/libbz2.a' " tip. However this does _not_ work for me (and someone else on this list). Scanning works though, but if I try to compile pyclamav it complains about