Re: [Clamav-users] clamd segment violations

2004-07-30 Thread Doug Hardie
I just noticed that clamd has a large number of files opened that the directory entries have been deleted. There are well over a hundred of them. The sizes appear to be about right for emails. On Jul 28, 2004, at 15:16, Doug Hardie wrote: I am running FreeBSD 4.6 ClamAV version devel-20040728

RE: [Clamav-users] RE: dot qmail files

2004-07-30 Thread Josep Ruano
Hello all, I completely agree with Jason. In my company we are thinking to develop such tool exactly for same reasons. Any idea on how to set up it on dot-qmail files? Thanks and best regards Josep Ruano Bou CAPSiDE CTO [EMAIL PROTECTED] Cell Phone +34 653 665 290 Phone +34 934 266 731

Re: [Clamav-users] RE: dot qmail files

2004-07-30 Thread Trog
On Fri, 2004-07-30 at 02:16, Jason wrote: What I ultimately need to do is take the delivery, check it for a virus, and take an action. This needs to be configurable by account and maintainable by an inexperienced admin that can follow directions. Updates should be easily performed and the

Re: [Clamav-users] clamd timeout?

2004-07-30 Thread Trog
On Fri, 2004-07-30 at 02:32, Brian Bruns wrote: Is there any way to have clamd stop scanning a file/archive/etc fed to it after a set amount of seconds, and return an error? No, but you can limit the amount of data/files in an archive it will scan. -trog signature.asc Description: This is a

Re: [Clamav-users] clamd devel-20040728 memory usage growing

2004-07-30 Thread Thomas Lamy
Igor Brezac wrote: On Thu, 29 Jul 2004, Mike Lambert wrote: OS: FreeBSD 4.9-RELEASE-p2 ClamAV: devel-20040728 Build options: --enable-milter --disable-clamuko --enable-bigstack --disable-dependency-tracking In 24 hours of running, memory usage for clamd (devel-20040728) has steadily increased from

[Clamav-users] Clamav 0.75-1 on sourceforge ??

2004-07-30 Thread Jerome Loyet
Hello Will Clamav-0.75-1 be released on sf ? It's for making the OpenBSD port, I used to use SF for downloading them and I would'nt change that. Thanks, ++ Jerome --- This SF.Net email is sponsored by OSTG. Have you noticed the changes on

Re: [Clamav-users] ClamAV malfunction

2004-07-30 Thread Wilson Mak
I switched to clamav0.75.1 and increase softlimit to 1800. Everything works fine now. Thanks! On Wed, 28 Jul 2004 16:09:29 +0800 Wilson Mak [EMAIL PROTECTED] wrote: P.S softlimit is 1500 where I used it in Clam0.6. It's worked perfectly OK before. Please increase it or

[Clamav-users] online scanner doesn't recognize (at least one) virus

2004-07-30 Thread Giorgio Bellussi
Good day all. Online scanner http://www.gietl.com/test-clamav/ doesn't recognize mabutu.a (same way as clamav-0.75) The same file results infected at http://www.kaspersky.com/scanforvirus (*I-Worm.Mabutu.a)* and h

[Clamav-users] ClamAV 0.75 segmentation violation (FreeBSD)

2004-07-30 Thread Ollie Cook
Hi, I am running clamd from ClamAV 0.75 under FreeBSD 4.10. About six to ten times a day, clamd will either hang and not accept new connections or crash with SIGSEGV. I have got the following backtrace: (gdb) c Continuing. [Switching to process 25012, thread 10] Program received signal

Re: [Clamav-users] online scanner doesn't recognize (at least one) virus

2004-07-30 Thread Trog
On Fri, 2004-07-30 at 10:17, Giorgio Bellussi wrote: Good day all. Online scanner http://www.gietl.com/test-clamav/ doesn't recognize mabutu.a (same way as clamav-0.75) The same file results infected at http://www.kaspersky.com/scanforvirus (*I-Worm.Mabutu.a)* and h

[Clamav-users] ClamAV 0.75 assertion failure (reproducible)

2004-07-30 Thread Ollie Cook
Hi, While investigating the crashes I've been seeing with ClamAV 0.75 on FreeBSD I have discovered a place where an assertion fails. The assertion that fails is on line 331 of message.c: assert(m-base64chars == 0); The backtrace for the process in question was: (gdb) c Continuing.

Re: [Clamav-users] ClamAV 0.75 assertion failure (reproducible)

2004-07-30 Thread Trog
On Fri, 2004-07-30 at 10:37, Ollie Cook wrote: Hi, While investigating the crashes I've been seeing with ClamAV 0.75 on FreeBSD I have discovered a place where an assertion fails. The assertion that fails is on line 331 of message.c: assert(m-base64chars == 0); This doesn't crash

[Clamav-users] versions 0.72 - 0.75 freeze on freebsd 4.10-STABLE when reloading databases

2004-07-30 Thread Maciej Kroenke
Hello, I've been running clamav for some time on my server. Unfortunately I am facing one problem: clamd freezes whenever freshclam updates databases and asks clamd to reload them. It's not that big problem since once a day I can stop clamd, update databases and restart daemon. But still I guess

Re: [Clamav-users] [Clamav] [OpenBSD] port for 0.75

2004-07-30 Thread Lars Hansson
Jerome Loyet wrote: Thanks for you feedback. Seems to be running fine on my 3.4 boxes so far, one scanning ~15k messages/day and the other 5k. Both are running qmail with the scanning done from qmail-qfilter using clamdscan. --- Lars Hansson

Re: [Clamav-users] online scanner doesn't recognize (at least one) virus

2004-07-30 Thread Kristof Hardy
Trog wrote: On Fri, 2004-07-30 at 10:17, Giorgio Bellussi wrote: Online scanner http://www.gietl.com/test-clamav/ doesn't recognize mabutu.a (same way as clamav-0.75) clamav-devel-20040728 contains a UPX unpacker, clamav-0.75 does not. Hence, it is able to unpack the file and finds the worm. and

Re: [Clamav-users] ClamAV 0.75 segmentation violation (FreeBSD)

2004-07-30 Thread Ollie Cook
On Fri, Jul 30, 2004 at 10:24:50AM +0100, Ollie Cook wrote: I have recompiled with debugging symbols, so I will be able to provide a more comprehensive backtrace the next time this occurs. With debugging symbols the backtrace is: (gdb) c Continuing. [Switching to process 33496, thread 24]

Re: [Clamav-users] ClamAV 0.75 segmentation violation (FreeBSD)

2004-07-30 Thread Tomasz Kojm
On Fri, 30 Jul 2004 15:49:18 +0100 Ollie Cook [EMAIL PROTECTED] wrote: On Fri, Jul 30, 2004 at 10:24:50AM +0100, Ollie Cook wrote: I have recompiled with debugging symbols, so I will be able to provide a more comprehensive backtrace the next time this occurs. With debugging symbols the

Re: [Clamav-users] clamd devel-20040728 memory usage growing

2004-07-30 Thread Tomasz Kojm
On Thu, 29 Jul 2004 22:11:42 -0400 (EDT) Igor Brezac [EMAIL PROTECTED] wrote: How about this? --- matcher-bm.c.orig Mon Jul 19 13:54:40 2004 The patch is correct. Thanks. -- oo. Tomasz Kojm [EMAIL PROTECTED] (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] Crash in clamscan / ClamAV version devel-20040726

2004-07-30 Thread Tomasz Kojm
On Mon, 26 Jul 2004 11:07:49 -0400 James F. Hranicky [EMAIL PROTECTED] wrote: ClamAV version: clamscan / ClamAV version devel-20040726 OS: FreeBSD palm.cise.ufl.edu 4.10-PRERELEASE When scanning a file which appears to have a virus, but not currently

Re: [Clamav-users] ClamAV 0.75 segmentation violation (FreeBSD)

2004-07-30 Thread Tomasz Kojm
On Fri, 30 Jul 2004 15:49:18 +0100 Ollie Cook [EMAIL PROTECTED] wrote: limits=0xbfbffa20, options=27, copt=0x80564c0) at scanner.c:240 240 if ((he = gethostbyname(cpt-strarg)) == 0) { (gdb) p cpt-strarg $7 = 0x805a0c0 80.168.70.183 Since the call to gethostbyname has a

[Clamav-users] Unsupported multipart format

2004-07-30 Thread Jorge Valdes
I got the following in my logs: LibClamAV Warning: Unsupported multipart format `fax-message' I do get these a lot since I provide a fax-2-email service for my customers. Since a virus could use this as a transport, could this multipart-type be treated as an image?? generally these are TIFF. --

RE: [Clamav-users] Unsupported multipart format

2004-07-30 Thread Nigel Horne
I got the following in my logs: LibClamAV Warning: Unsupported multipart format `fax-message' I do get these a lot since I provide a fax-2-email service for my customers. Since a virus could use this as a transport, could this multipart-type be treated as an image?? generally these are

[Clamav-users] Mydoom.M

2004-07-30 Thread Arthur Kerpician
Hi, 1. I'm running ClamAV-0.73 on RH9 machine (qmail) and made all the updates, including daily 429. Anyway, it seems that mydoom.m is bypassing ClamAV since 2 of my servers (same config) didn't send any notification to the admin e-mail regarding the worm. After one of the servers i have NAV

[Clamav-users] Re: clamd devel-20040728 memory usage growing

2004-07-30 Thread Jesse Guardiani
Tomasz Kojm wrote: On Thu, 29 Jul 2004 22:11:42 -0400 (EDT) Igor Brezac [EMAIL PROTECTED] wrote: How about this? --- matcher-bm.c.orig Mon Jul 19 13:54:40 2004 The patch is correct. Thanks. Did this solve the problem? Did it make it into 75.1? Or do I need to patch manually when I

[Clamav-users] Re: ClamAV 0.75 segmentation violation (FreeBSD)

2004-07-30 Thread Jesse Guardiani
Tomasz Kojm wrote: On Fri, 30 Jul 2004 15:49:18 +0100 Ollie Cook [EMAIL PROTECTED] wrote: On Fri, Jul 30, 2004 at 10:24:50AM +0100, Ollie Cook wrote: I have recompiled with debugging symbols, so I will be able to provide a more comprehensive backtrace the next time this occurs. With

[Clamav-users] Re: versions 0.72 - 0.75 freeze on freebsd 4.10-STABLE when reloading databases

2004-07-30 Thread Jesse Guardiani
Maciej Kroenke wrote: Hello, I've been running clamav for some time on my server. Unfortunately I am facing one problem: clamd freezes whenever freshclam updates databases and asks clamd to reload them. It's not that big problem since once a day I can stop clamd, update databases and

Re: [Clamav-users] Re: clamd devel-20040728 memory usage growing

2004-07-30 Thread Tomasz Kojm
On Fri, 30 Jul 2004 15:43:45 -0400 Jesse Guardiani [EMAIL PROTECTED] wrote: Or do I need to patch manually when I upgrade from 73 - 75.1 on Monday? No, you don't. Only CVS version was affected. -- oo. Tomasz Kojm [EMAIL PROTECTED] (\/)\.

Re: [Clamav-users] Mydoom.M

2004-07-30 Thread Daniel J McDonald
On Fri, 2004-07-30 at 14:27, Arthur Kerpician wrote: Hi, 1. I'm running ClamAV-0.73 on RH9 machine (qmail) and made all the updates, 0.73 doesn't support mangled MIME encoding. That was added in 0.75. You probably want to upgrade to 0.75.1 at this point. -- Daniel J McDonald [EMAIL

[Clamav-users] support idea

2004-07-30 Thread Christopher McCrory
Hello... I've been going through our internal process for sending a donation for the clamav developers. I've run into two issues from the various people in this process. 1: why? accounting people cannot always grasp the concept of because they need resources to keep the software current 2:

[Clamav-users] ScanRAR usability

2004-07-30 Thread Todd Lyons
In the default clamav.conf exists the following verbage: # By default the built-in RAR unpacker is disabled by default because # the code terribly leaks, however it's probably a good idea to enable # it. #ScanRAR Does anybody know if that's still accurate? -- Regards... Todd They

[Clamav-users] Clam av 0.75 and GNU MP 4.13 on Mac OS X 10.3.4 (Server)

2004-07-30 Thread Dave Hoebe
Hi, Anyone managed to build ClamAV 0.75 and GNU MP 4.13 on MAc OS X 10.3.4 (Server) ? I did a build without the gnu mp and found the "SECURITY WARNING: NO SUPPORT FOR DIGITAL SIGNATURES" message in the clam-update logfile. Folowing the instructions in the documentation i did a install

Re: [Clamav-users] Clam av 0.75 and GNU MP 4.13 on Mac OS X 10.3.4 (Server)

2004-07-30 Thread OpenMacNews
Anyone managed to build ClamAV 0.75 and GNU MP 4.13 on MAc OS X 10.3.4 (Server) ? well, close ... clamav cvs-head 07/26/04 gmp 4.1.3 macosx 10.3.4 -- NOT server I did a build without the gnu mp and found the SECURITY WARNING: NO SUPPORT FOR DIGITAL SIGNATURES message in the clam-update logfile.

[Clamav-users] success report on 0.75.1

2004-07-30 Thread Christopher McCrory
Hello... FWIW , I updated to 0.75.1 today and it is working well. broken MIME Mydoom.M are (almost all) caught and mem usage is at ~14M. 0.75 would reach 1G ram then soon seg fault and fail. I was blocking all free@ instantly@ and noreply@ to keep the mem usage down. I started allowing

[Clamav-users] Re: qmail dot files

2004-07-30 Thread Jason
Thanks to all for your replies. In summary my need was: What I ultimately need to do is take the delivery, check it for a virus, and take an action. This needs to be configurable by account and maintainable by an inexperienced admin that can follow directions. Updates should be easily performed

Re: [Clamav-users] Re: qmail dot files

2004-07-30 Thread Steve Lenti
On Fri, 30 Jul 2004 22:35:10 -0400, Jason [EMAIL PROTECTED] wrote: Thanks to all for your replies. In summary my need was: What I ultimately need to do is take the delivery, check it for a virus, and take an action. This needs to be configurable by account and maintainable by an