[Clamav-devel] Summer of Code: phishing detector

2006-05-24 Thread Török Edvin
Hi, I have been accepted to participate in Google's Summer of Code, and I'd like to thank the ClamAV developers, and Google for that. I am happy to work on ClamAV this summer. The project I've chosen is phishing detector. I just took a quick look at clamav-devel archives, and seen Nigel Home's

Re: [Clamav-devel] New phishing detection algorithm in cvs version of clamav

2006-09-16 Thread Török Edvin
On 9/16/06, Ian Castle [EMAIL PROTECTED] wrote: Török Edvin wrote: Looking forward for you ideas, comments, results (and bug reports). I built this (probably wrongly ;-) Tell me how you called ./configure and we'll see if its correct. the other day, in order to test it on our repository

Re: [Clamav-devel] New phishing detection algorithm in cvs version of clamav

2006-09-17 Thread Török Edvin
On 9/17/06, Ian Castle [EMAIL PROTECTED] wrote: Török Edvin wrote: I've updated the documentation in the phishsigs_howto with some examples on how to create those databases. Hmmm... phishsigs_howto.lyx says: \begin_layout Section Examples \end_layout \begin_layout

Re: [Clamav-devel] clamav for scanning files instead of emails

2006-09-23 Thread Török Edvin
On 9/23/06, James Courtier-Dutton [EMAIL PROTECTED] wrote: Hi, I know that clamav is designed to scan emails well, and it does a very good job of that. It can also scan files on the HD. In order to improve the scanning of files on the HD, has anyone considered building a signature database of

Re: [Clamav-devel] New phishing method...doubts

2006-09-26 Thread Török Edvin
version). OBS: Török Edvin the idea of a anti phishing is very good, and the tests made by Ian Castle are very intersting too. thanks Best regards, Edwin ___ http://lurker.clamav.net/list/clamav-devel.html

Re: [Clamav-devel] always detect Phishing.Email.HexURL ?

2006-10-03 Thread Török Edvin
On 10/2/06, Robert Allerstorfer [EMAIL PROTECTED] wrote: Hi, with the new url-based phishing detection enabled, but without the '--phish-scan-alldomains' option, some (or most) Phishing.Email.HexURL phishes get through. The corresponding --debug option says LibClamAV debug: PH:Checking url

Re: [Clamav-devel] Phishcheck routines applied even with --no-phishing-scan-urls

2006-11-19 Thread Török Edvin
On 11/2/06, Robert Allerstorfer [EMAIL PROTECTED] wrote: Hi, when scanning a PDF with clamscan 0.90rc2 with experimental code enabled, no phishing check is needed, thus I ran clamscan --no-phishing-scan-urls --debug Encrypted.pdf; echo Exit code: $? However, this does not disable the

Re: [Clamav-devel] freshclam looping

2007-03-03 Thread Török Edvin
On 3/2/07, Jose Celestino [EMAIL PROTECTED] wrote: Words by Jose Celestino [Sat, Feb 17, 2007 at 01:24:10AM +]: Hi, stepped into an infinite loop on freshclam when there's no permissions for daily.inc and daily.inc/*. I know the permissions are an install problem but it may happen and

Re: [Clamav-devel] [PATCH] workaround to invalid names in ole2

2007-03-15 Thread Török Edvin
On 3/15/07, Gianluigi Tiesi [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I've already posted something about this, but there was a problem when detecting real ole2 containers like office document, this new patch should avoid the regression. When a file is extracted

Re: [Clamav-devel] false positive rate for Phishing.Email

2007-06-14 Thread Török Edvin
On 6/14/07, Kelsey Cummings [EMAIL PROTECTED] wrote: Out of 912 messages that were caught by Phishing.Email a full 123 were human verified false positives. Please post output of: clamconf|grep Phish If you have PhishingRestrictedScan = No, its obvious what the problem is. An 87% accuracy

Re: [Clamav-devel] pthread_create failed

2007-06-19 Thread Török Edvin
On 6/19/07, George Georgalis [EMAIL PROTECTED] wrote: A week or so ago clamd stopped working for me, after upgrading to 0.90.3 --experimental I still get an unusable system. Linux ohm 2.4.20-ohm #1 Sat Jan 11 01:41:24 EST 2003 i586 unknown 2007-06-19 00:46:18.927419500 Reading databases

Re: [Clamav-devel] Virus Database Server

2007-09-25 Thread Török Edvin
On 9/25/07, Mehdi Sheikhalishahi [EMAIL PROTECTED] wrote: Hi, Is there Virus Database Server source code in the source of clamav(i.e. that freshclam update database)? Freshclam downloads databases through http. So the source code is the source code of insert your favourite webserver. What do

Re: [Clamav-devel] CL_DB_PHISHING_URLS in CL_DB_STDOPT

2007-10-03 Thread Török Edvin
On 10/3/07, Jan ONDREJ (SAL) [EMAIL PROTECTED] wrote: Hello, there is a lot of false positived when scanning with libclamav and it's CL_DB_STDOPT options. So you were not using clamscan, but libclamav directly. Please always mention this when you submit a false positive. Why this