I am totally confused. I just updated to ClamAV 0.95 RC2 for use with 
1.5.1.0 final and enabled Scan Whitelisted Senders and set Suspicious 
Virus to UNOFFICIAL|Safebrowsing\. and sent the test email below that 
contains an unsafe url.

ASSP logs Message OK and lets the message through. Yet a CLI test 
shown below indicates that the URL returns 
Safebrowsing.Suspected-malware_safebrowsing.clamav.net

Why isn't assp detecting and scoring this?  What can I do to help test?

From: TR Shaw <[email protected]>
To: [email protected]
Subject: test
Date: Tue, 17 Mar 2009 12:55:13 -0400
X-Assp-Delay: not delayed (whiteListedIPs '17.0.0.0/8'); 17 Mar 2009
        12:55:17 -0400
X-Assp-Whitelisted: Yes
X-Assp-Envelope-From: [email protected]

        http://msio.org.ir

 From Log:
Mar-17-09 12:55:17 17.148.16.91 <[email protected]> found [email protected] in 
LDAP-cache
Mar-17-09 12:55:17 17.148.16.91 <[email protected]> to: [email protected] ClamAV: 
scanned 738 bytes in whitelisted message - OK

COmmand line test:

URL="msio.org.ir"; echo -e "From test\n\n<a 
href=http://$URL>test</a>" | clamdscan -
stream: Safebrowsing.Suspected-malware_safebrowsing.clamav.net FOUND



------------------------------------------------------------------------------
Apps built with the Adobe(R) Flex(R) framework and Flex Builder(TM) are
powering Web 2.0 with engaging, cross-platform capabilities. Quickly and
easily build your RIAs with Flex Builder, the Eclipse(TM)based development
software that enables intelligent coding and step-through debugging.
Download the free 60 day trial. http://p.sf.net/sfu/www-adobe-com
_______________________________________________
Assp-test mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to