Re: [clamav-users] Current replacement for --max-ratio?

2022-01-17 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: Hi there, On Fri, 14 Jan 2022, Kris Deugau wrote: I've just come across a presumed-malicious .zip file of about 500K that contains a ~315M ISO image, which in turn appears to contain a ~315M executable file. After a bit of searching and testing I see the

Re: [clamav-users] Current replacement for --max-ratio?

2022-01-15 Thread G.W. Haywood via clamav-users
Hi there, On Fri, 14 Jan 2022, Eric Tykwinski wrote: When did clamav start scanning iso files? https://blog.clamav.net/2013/09/clamav-098-has-been-released.html -- 73, Ged. ___ clamav-users mailing list clamav-users@lists.clamav.net https://list

Re: [clamav-users] Current replacement for --max-ratio?

2022-01-14 Thread Eric Tykwinski
Ged, When did clamav start scanning iso files? I just tried this and found a eicar.txt file, so yes it does work. For email, I always just blocked iso extensions. Still doesn’t like MacOS cdr extensions, but a great improvement. Sincerely, Eric Tykwinski > On Jan 14, 2022, at 6:21 PM, G.W.

Re: [clamav-users] Current replacement for --max-ratio?

2022-01-14 Thread G.W. Haywood via clamav-users
Hi there, On Fri, 14 Jan 2022, Kris Deugau wrote: I've just come across a presumed-malicious .zip file of about 500K that contains a ~315M ISO image, which in turn appears to contain a ~315M executable file. After a bit of searching and testing I see the --max-ratio option has been removed

[clamav-users] Current replacement for --max-ratio?

2022-01-14 Thread Kris Deugau
I've just come across a presumed-malicious .zip file of about 500K that contains a ~315M ISO image, which in turn appears to contain a ~315M executable file. After a bit of searching and testing I see the --max-ratio option has been removed from clamscan, and ArchiveMaxCompressionRatio in clam