Re: [clamav-users] freshclam vs sudo freshclam

2018-08-21 Thread Micah Snyder (micasnyd)
Woah, I need to proof-read my emails better. I meant to say, "You shouldn't need 'sudo' if your user can write to the directory. Micah Snyder ClamAV Development Talos Cisco Systems, Inc. On Aug 21, 2018, at 12:45 PM, Micah Snyder (micasnyd) mailto:micas...@cisco.com>> wrote: Hi Mike, It

Re: [clamav-users] freshclam vs sudo freshclam

2018-08-21 Thread Micah Snyder (micasnyd)
Hi Mike, It depends on whether what your clamav database directory's user permissions are set to. You shouldn't need freshclam if your user can write to the directory. At this time, ClamAV relies on the installer (or sys admin) to configure the permissions. If you install from source, the

Re: [clamav-users] ClamAV signature update sync errors have gotten worse

2018-08-21 Thread Joel Esler (jesler)
On Aug 21, 2018, at 12:32 PM, G.W. Haywood mailto:cla...@jubileegroup.co.uk>> wrote: Hi there, On Tue, 21 Aug 2018, Joel Esler wrote: The amount of people using ClamAV version 0.90 and below is surprising as well. That's not really surprising to me. Most of them probably don't even know

Re: [clamav-users] ClamAV signature update sync errors have gotten worse

2018-08-21 Thread G.W. Haywood
Hi there, On Tue, 21 Aug 2018, Joel Esler wrote: The amount of people using ClamAV version 0.90 and below is surprising as well. That's not really surprising to me. Most of them probably don't even know that they're running it, and those who do could easily be lying as it's trivial to forge

Re: [clamav-users] ClamAV signature update sync errors have gotten worse

2018-08-21 Thread Joel Esler (jesler)
CC'ing your comments over to Micah. We have a heavy freshclam rewrite in the pipeline. The amount of people using ClamAV version 0.90 and below is surprising as well. None of those versions support .diff files on the daily file. So, those versions are downloading the whole daily.cvd

Re: [clamav-users] Malwarepatrol false positive

2018-08-21 Thread Alex
On Tue, Aug 21, 2018 at 9:02 AM Steve Basford wrote: > On Tue, August 21, 2018 12:27 pm, Dave McMurtrie wrote: > > > > I'm beginning to get the feeling they don't have any type of review > > process in place. > > I whitelisted the sig on the Sanesecurity mirrors this morning UK time: > >

Re: [clamav-users] Malwarepatrol false positive

2018-08-21 Thread Steve Basford
On Tue, August 21, 2018 12:27 pm, Dave McMurtrie wrote: > > I'm beginning to get the feeling they don't have any type of review > process in place. I whitelisted the sig on the Sanesecurity mirrors this morning UK time: 21/08/2018 @ 11:37 It's usually quicker to do that, if not ideal. --

Re: [clamav-users] Malwarepatrol false positive

2018-08-21 Thread Arnaud Jacques
Hello, Do it yourself: https://www.securiteinfo.com/services/anti-spam-anti-virus/whitelisting_clamav_signatures.shtml Btw, users/customers of https://www.securiteinfo.com/services/anti-spam-anti-virus/improve-detection-rate-of-zero-day-malwares-for-clamav.shtml have no problem because the

Re: [clamav-users] Malwarepatrol false positive

2018-08-21 Thread Al Varnell
OK, I don't think there is anything that ClamAV can do about it since it's an UNOFFICIAL. Maybe Steve Basford from SaneSecurity can put some pressure on them. He usually reads what's posted here. -Al- On Tue, Aug 21, 2018 at 04:27 AM, Dave McMurtrie wrote: > They did this in April, 2017

Re: [clamav-users] Malwarepatrol false positive

2018-08-21 Thread Dave McMurtrie
They did this in April, 2017 also. When I reported it as a false positive at that time, they responded with: "Thank you for contacting us. There is a file hosted there with a vague AV classification. After further reviewing it, we've decided to remove the URL from our block lists and data