Re: [clamav-users] ***Spam 3.041*** clamd using 100% CPU in Fedora 30 with sendmail & clamav-milter, : Probe for slot 1 returned: failed

2019-07-31 Thread James Brown via clamav-users
6.0.1 is now out. (Fixes a logging issue). The new version (6.0) has lots and lots of updates to the code. Mainly quicker and uses less bandwidth. James. > On 1 Aug 2019, at 1:21 am, Robert Kudyba wrote: > > Indeed we do use clamav-unofficial-sigs from > https://github.com/extremeshok/clamav

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Paul Kosinski via clamav-users
The problem with our using a Web proxy is that it too cached stale CVDs if it was using the BOS Cloudflare server. That is, the DNS TXT record reported a new CVD, but the proxy couldn't deliver it. I considered using a proxy on our offsite domain host (which happened not to use BOS), but that seeme

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Henrik K
On Wed, Jul 31, 2019 at 03:33:59PM +, Joel Esler (jesler) via clamav-users wrote: > > Would not private mirror users be usually a single organization, so in > practise a single "user"? Why do you need to know how many servers they > have? > > > You know how often I get asked how

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Joel Esler (jesler) via clamav-users
> On Jul 31, 2019, at 11:04 AM, Henrik K wrote: > > On Wed, Jul 31, 2019 at 02:49:33PM +, Joel Esler (jesler) via > clamav-users wrote: >> >> The only problem with the local mirrors, from our point of view are a couple >> things: >> >> 1. I don't know how many users we have > > Would n

Re: [clamav-users] ***Spam 3.041*** clamd using 100% CPU in Fedora 30 with sendmail & clamav-milter, : Probe for slot 1 returned: failed

2019-07-31 Thread Robert Kudyba
Indeed we do use clamav-unofficial-sigs from https://github.com/extremeshok/clamav-unofficial-sigs/blob/master/README.md. And interesting timing just announced a new version: Version 6.0 (30 July 2019) On Wed, Jul 31, 2019 at 10:41 AM Micah Snyder (micasnyd) via clamav-users < clamav-users@lists.

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Henrik K
On Wed, Jul 31, 2019 at 02:49:33PM +, Joel Esler (jesler) via clamav-users wrote: > > The only problem with the local mirrors, from our point of view are a couple > things: > > 1. I don't know how many users we have Would not private mirror users be usually a single organization, so in prac

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Joel Esler (jesler) via clamav-users
> On Jul 31, 2019, at 9:52 AM, J.R. via clamav-users > wrote: > >> Then, when we had trouble with Cloudflare's BOS server often being out >> of sync (for CVDs) with the DNS TXT record, I removed it. Now, I am >> dismayed that I have to give our file server a bit of Internet access so >> that i

Re: [clamav-users] ***Spam 3.041*** clamd using 100% CPU in Fedora 30 with sendmail & clamav-milter, : Probe for slot 1 returned: failed

2019-07-31 Thread Micah Snyder (micasnyd) via clamav-users
If you don’t mind my asking – are you using a large number of third party databases? Our official databases have grown quite a bit this year – but I wouldn’t expect anywhere near 5 minutes for load time. On my laptop this morning I see around 45 seconds load time for clamd. Every now and then

Re: [clamav-users] Can't query....

2019-07-31 Thread Micah Snyder (micasnyd) via clamav-users
Hi Jim, Some background about "ping.clamav.net": Freshclam has a feature to do a DNS query for domain names of the form: .ping.clamav.net It is of course not a real host in our domain, but instead the query gets logged and that provides an extremely low cost method for getting basic

Re: [clamav-users] ***Spam 3.041*** clamd using 100% CPU in Fedora 30 with sendmail & clamav-milter, : Probe for slot 1 returned: failed

2019-07-31 Thread Robert Kudyba
Sorry forgot to include the hive in my responses. So increasing the timeout value to 900 did work. I didn’t time it but it definitely seems like 4-5 minutes to finally start. We rebooted and it started fine. Should a big report be created? Would this be in Fedora’s Bugzilla, or Clamav’s bug tra

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread J.R. via clamav-users
> Then, when we had trouble with Cloudflare's BOS server often being out > of sync (for CVDs) with the DNS TXT record, I removed it. Now, I am > dismayed that I have to give our file server a bit of Internet access so > that it can directly download the CDIFFs. I remember issue where some proxy wa

Re: [clamav-users] scanning of a 1MB exe files takes up to 130seconds on a single core xeon cpu - is that normal?

2019-07-31 Thread J.R. via clamav-users
> Why is this so slow? I see almost 100% cpu. But seriously on a 1MB file 2 > mines? What could cause this high load? Can i speed this up a bit with kind > of cache or something? Basically what Iulian said... When running 'clamscan' it takes a while (especially if you have 3rd party rules) to load

[clamav-users] Can't query....

2019-07-31 Thread Jim Popovitch via clamav-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 > Jul 31 09:24:16 cav freshclam[3977]: Can't query > daily.25527.102.1.0.6810DA54.ping.clamav.net To me, "Can't" implies an inability to do something, generally this would therefore require action by someone else or something else. "I can't move t

Re: [clamav-users] how to configure to clamav daemon to reject file types

2019-07-31 Thread Jeremy O'Leary via clamav-users
Let me zoom out for a moment, ClamAV is part of a workflow that we are trying to prevent users from working with certain file types, if ClamAV would immediately throw a block, them then the chain of events would be broken. Another person who replied directly pointed out my understanding of file ty