[Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Wolfgang Breyha
Hi! Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) freshclam did not detect the malformed sig and told clamd to read the sigs... LibClamAV Error: cli_tgzload: File 782872.cbc not correctly loaded LibClamAV Error:

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Christopher X. Candreva
On Tue, 11 May 2010, Wolfgang Breyha wrote: Hi! Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) What version of ClamAV are you running ? == Chris Candreva

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Török Edwin
On 05/11/2010 03:13 PM, Wolfgang Breyha wrote: Hi! Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) freshclam did not detect the malformed sig and told clamd to read the sigs... LibClamAV Error: cli_tgzload:

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Wolfgang Breyha
Christopher X. Candreva wrote, on 11.05.2010 14:21: On Tue, 11 May 2010, Wolfgang Breyha wrote: Hi! Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) What version of ClamAV are you running ? 0.96 ... and I'm

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Matus UHLAR - fantomas
On 11.05.10 14:13, Wolfgang Breyha wrote: Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) freshclam did not detect the malformed sig and told clamd to read the sigs... LibClamAV Error: cli_tgzload: File 782872.cbc

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Steve Ladewig
Török Edwin said the following, On 05/11/2010 07:22 AM: On 05/11/2010 03:13 PM, Wolfgang Breyha wrote: Hi! Most of my clamd died today after freshclam updated to... bytecode.cld (version: 16, sigs: 3, f-level: 51, builder: nervous) freshclam did not detect the malformed sig and told clamd to

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread Daniel McDonald
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 5/11/10 7:38 AM, Steve Ladewig st...@ladewig.net wrote: Török Edwin said the following, On 05/11/2010 07:22 AM: On 05/11/2010 03:13 PM, Wolfgang Breyha wrote: Hi! Most of my clamd died today after freshclam updated to... bytecode.cld

Re: [Clamav-users] bytecode Rev 16 DoS

2010-05-11 Thread John W. Baxter
On our test machine, in US Pacific Daylight time (-0700). ... Tue May 11 05:17:32 2010 - bytecode.cld is up to date (version: 15, sigs: 2, f-level: 51, builder: nervous) ... Tue May 11 06:17:53 2010 - WARNING: getfile: Error while reading database from db.us.clamav.net (IP: 199.184.215.2):

[Clamav-users] STATS command timeout

2010-05-11 Thread Clayton Keller
I am trying to execute the STATS command with clamd. I have created the socket and am trying to send 'zSTATS' to the daemon, and am returned a COMMAND READ TIMEOUT. I am able to issue other commands without issue (i.e. 'VERSION', 'PING', 'SCAN'). After reading through the documentation I

Re: [Clamav-users] STATS command timeout

2010-05-11 Thread Török Edwin
On 05/11/2010 09:51 PM, Clayton Keller wrote: I am trying to execute the STATS command with clamd. I have created the socket and am trying to send 'zSTATS' to the daemon, and am returned a COMMAND READ TIMEOUT. Did you terminate it with a \0? (z needs \0, n needs \n). Best regards, --Edwin

Re: [Clamav-users] STATS command timeout

2010-05-11 Thread Clayton Keller
On 5/11/2010 1:52 PM, Török Edwin wrote: On 05/11/2010 09:51 PM, Clayton Keller wrote: I am trying to execute the STATS command with clamd. I have created the socket and am trying to send 'zSTATS' to the daemon, and am returned a COMMAND READ TIMEOUT. Did you terminate it with a \0? (z needs

[Clamav-users] Can not get clamav-milter to work on Sendmail

2010-05-11 Thread Shawn Bakhtiar
I have been trying to get clamav-milter to work on Linux FC 8: Linux smtp 2.6.26.6-49.fc8 #1 SMP Fri Oct 17 15:33:32 EDT 2008 x86_64 x86_64 x86_64 GNU/Linux Fedora release 8 (Werewolf) I downloaded the latest source and built. freshclam is working, it looks like I am able to run the clamav

Re: [Clamav-users] Can not get clamav-milter to work on Sendmail

2010-05-11 Thread Jason Bertoch
On 2010/05/11 3:03 PM, Shawn Bakhtiar wrote: I have been trying to get clamav-milter to work on Linux FC 8: Perhaps you're not waiting long enough for clamd to start before loading clamav-milter. Your logs show it takes a full 4 seconds for clamd to start. I suppose it could also be the

[Clamav-users] excluding signatures on SMTP

2010-05-11 Thread Matus UHLAR - fantomas
Hello, I'm working on code that would prevent rejecting some kinds of signarures at SMTP level. For example, phishing reports sent to abuse@ contact should pass, even if they contain phishing signatures. Now I'm curious which patterns to exclude from rejecting: I'm sure about Phishing in

Re: [Clamav-users] excluding signatures on SMTP

2010-05-11 Thread Stephen Gran
On Tue, May 11, 2010 at 11:27:54PM +0200, Matus UHLAR - fantomas said: Hello, I'm working on code that would prevent rejecting some kinds of signarures at SMTP level. For example, phishing reports sent to abuse@ contact should pass, even if they contain phishing signatures. Now I'm

[Clamav-users] sendmail queue

2010-05-11 Thread Lists
So, I'm working on getting ClamAV setup in milter mode with some custom signatures I've been writing. It's working pretty good, except that its hooking into the Sendmail quarantine function now. Is there a way to tell it to just throw all files into a directory for quarantine instead of

Re: [Clamav-users] excluding signatures on SMTP

2010-05-11 Thread Chuck Swiger
On May 11, 2010, at 2:27 PM, Matus UHLAR - fantomas wrote: I'm working on code that would prevent rejecting some kinds of signarures at SMTP level. For example, phishing reports sent to abuse@ contact should pass, even if they contain phishing signatures. You haven't mentioned which MTA or

Re: [Clamav-users] excluding signatures on SMTP

2010-05-11 Thread Matus UHLAR - fantomas
On 11.05.10 23:27, Matus UHLAR - fantomas wrote: I'm working on code that would prevent rejecting some kinds of signarures at SMTP level. For example, phishing reports sent to abuse@ contact should pass, even if they contain phishing signatures. Now I'm curious which patterns to exclude from

Re: [Clamav-users] excluding signatures on SMTP

2010-05-11 Thread Matus UHLAR - fantomas
On Tue, May 11, 2010 at 11:27:54PM +0200, Matus UHLAR - fantomas said: I'm working on code that would prevent rejecting some kinds of signarures at SMTP level. For example, phishing reports sent to abuse@ contact should pass, even if they contain phishing signatures. Now I'm curious