Re: [clamav-users] freshclam incremental update

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Birger Birger via clamav-users wrote: Den lör 31 aug. 2019 20:35 G.W. Haywood skrev: On Sat, 31 Aug 2019, Birger Birger via clamav-users wrote: ... download of daily.cvd with freshclam still stops at 99% In the last few days I've seen freshclam remove a few b

Re: [clamav-users] freshclam incremental update

2019-08-31 Thread Birger Birger via clamav-users
Have tried to remove the files manually already. That did not help. Den lör 31 aug. 2019 20:35G.W. Haywood via clamav-users < clamav-users@lists.clamav.net> skrev: > Hi there, > > On Sat, 31 Aug 2019, Birger Birger via clamav-users wrote: > > > have tried that but download of daily.cvd with fresh

Re: [clamav-users] Question regarding Metasploit signatures

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, J.R. via clamav-users wrote: If the virus pattern is in one of the database files, then you are alerted... If it's not, then no alert... That's how every antivirus works... There's a bit more to it than that. Some detection is based on other characteristics, su

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, J.R. via clamav-users wrote: ... I wouldn't call the current design a "bug"... It works as intended. +1 However it would be nice if a fresh DB could be parsed & loaded, then swapped, to prevent service interruption. That's exactly what the patch in #10979 do

Re: [clamav-users] freshclam incremental update

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Birger Birger via clamav-users wrote: have tried that but download of daily.cvd with freshclam still stops at 99% and never completes downloading daily and icremental with wget works fine If others don't have the same issue, and you can download the files OK wi

Re: [clamav-users] freshclam incremental update

2019-08-31 Thread Birger Birger via clamav-users
have tried that but download of daily.cvd with freshclam still stops at 99% and never completes downloading daily and icremental with wget works fine Den lör 31 aug. 2019 19:51J.R. via clamav-users < clamav-users@lists.clamav.net> skrev: > daily-25558.cdiff downloaded fine for my linux server th

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread J.R. via clamav-users
> Normally postfix gets a response after 3 secondes. > > In the clamav.log I see at the same time, that reloading the database > takes up to two minutes. Yes, reloading the DB can take some time depending on which signature DBs you are using. I can't speak for postfix (I run sendmail), but on my s

Re: [clamav-users] Question regarding Metasploit signatures

2019-08-31 Thread J.R. via clamav-users
> Hence, my question or curiosity over how ClamAV determines > the *true* threat level of a malicious file. If the virus pattern is in one of the database files, then you are alerted... If it's not, then no alert... That's how every antivirus works... You are more than welcome to report files for

Re: [clamav-users] freshclam incremental update

2019-08-31 Thread J.R. via clamav-users
daily-25558.cdiff downloaded fine for my linux server this morning... You can always remove the daily.cld file and let freshclam download the current whole file. ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailm

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Scott Kitterman via clamav-users
On August 31, 2019 4:32:00 PM UTC, Henrik K wrote: >On Sat, Aug 31, 2019 at 12:21:11PM -0400, Scott Kitterman via >clamav-users wrote: >> >> Not to put too fine a point on it, but if you are unhappy with the >service you >> are receiving, you should switch to a different vendor. I suspect >it

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Henrik K
On Sat, Aug 31, 2019 at 12:21:11PM -0400, Scott Kitterman via clamav-users wrote: > > Not to put too fine a point on it, but if you are unhappy with the service > you > are receiving, you should switch to a different vendor. I suspect it's > unlikely you'll get the same value for money elsewhe

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Henrik K wrote: On Sat, Aug 31, 2019 at 04:48:54PM +0100, G.W. Haywood via clamav-users wrote: The final responsibility of implementing and testing the issue is still that of the ClamAV team. Agreed. You are really making this much more complex and "scary" issu

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Scott Kitterman via clamav-users
On Saturday, August 31, 2019 12:04:36 PM EDT Henrik K wrote: > On Sat, Aug 31, 2019 at 04:48:54PM +0100, G.W. Haywood via clamav-users wrote: > > More testing, by people prepared to chip in some effort instead of > > complaining about something that they get for free, would be great. > > The fina

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Henrik K
On Sat, Aug 31, 2019 at 04:48:54PM +0100, G.W. Haywood via clamav-users wrote: > > More testing, by people prepared to chip in some effort instead of > complaining about something that they get for free, would be great. The final responsibility of implementing and testing the issue is still that

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Henrik K wrote: ... If I encountered a bug like that on some project that I'm maintaining, I would be shamed not to rapidly fix it. If you called it a limitation I could agree, but I guess it's working as designed. I'd call it an issue rather than a fault in the

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Henrik K wrote: On Sat, Aug 31, 2019, G.W. Haywood via clamav-users wrote: Well not quite nothing, since you can download the source, apply the patch, and rebuild ClamAV. Sure but it's not reality for majority of users.. While it's good that people try it out,

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Henrik K
On Sat, Aug 31, 2019 at 11:18:00AM -0400, Michael Orlitzky via clamav-users wrote: > > Micah took the time to answer a question and provide a status update. > It's counterproductive to shame people for being honest. It's perfectly fine to shame a corporation for doing seemingly strange things.

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Michael Orlitzky via clamav-users
On 8/31/19 11:00 AM, Thomas Barth via clamav-users wrote: > > Realy bad attitude of developers! Micah took the time to answer a question and provide a status update. It's counterproductive to shame people for being honest. ___ clamav-users mailing li

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Henrik K
On Sat, Aug 31, 2019 at 03:55:30PM +0100, G.W. Haywood via clamav-users wrote: > > Well not quite nothing, since you can download the source, apply the > patch, and rebuild ClamAV. Sure but it's not reality for majority of users.. While it's good that people try it out, I doubt if would take long

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Thomas Barth via clamav-users
Am 2019-08-31 16:32, schrieb Henrik K: The reload bug has been known for years, even has a ready patch. Wow, this is a masterpiece ignoring a problem for years :) Thanks for pointing to the bugthread. But nothing you can do about it, ClamAV devs have a mind of their own. Micah Snyder 201

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 31 Aug 2019, Henrik K wrote: The reload bug has been known for years, even has a ready patch. https://bugzilla.clamav.net/show_bug.cgi?id=10979 But nothing you can do about it... Well not quite nothing, since you can download the source, apply the patch, and rebuild ClamAV

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Henrik K
The reload bug has been known for years, even has a ready patch. https://bugzilla.clamav.net/show_bug.cgi?id=10979 But nothing you can do about it, ClamAV devs have a mind of their own. Atleast servers in your scenario will (hopefully) retry sending. On Sat, Aug 31, 2019 at 04:25:05PM +0200,

[clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-08-31 Thread Thomas Barth via clamav-users
Hallo Mailinglist, sometimes I get in Postfix the error messages "451 4.3.0 Error: queue file write error". There is a warning timeout talking to localhost:10024 (Amavis) Aug 31 14:14:19 mx2 postfix/smtpd[15861]: connect from unknown[177.37.96.254] Aug 31 14:14:20 mx2 postfix/smtpd[15861]:

[clamav-users] freshclam incremental update

2019-08-31 Thread Birger Birger via clamav-users
downloading daily-25558.cdiff never completes. stops att 97%. any ideas what can be done to fix this? ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive Cla

Re: [clamav-users] Question regarding Metasploit signatures

2019-08-31 Thread Manna, Mohammed via clamav-users
Hi There, > -Original Message- > From: clamav-users On Behalf Of > G.W. Haywood via clamav-users > Sent: 31 August 2019 08:39 > To: Manna, Mohammed via clamav-users > Cc: G.W. Haywood > Subject: Re: [clamav-users] Question regarding Metasploit signatures > > Hi there, > > On Fri, 30 A

Re: [clamav-users] Question regarding Metasploit signatures

2019-08-31 Thread G.W. Haywood via clamav-users
Hi there, On Fri, 30 Aug 2019, Manna, Mohammed via clamav-users wrote: What I can see that ClamAV cannot always successfully detect reverse shell type of files (built using Metasploit msfvenom). And also, if the file is covered using a pseudo extension e.g. test.exe.txt When I was comparing th