Re: [Clamav-users] 64bit RH ES5 Compile Error for Clamav 0.95.3

2009-10-30 Thread Kelson
of using the package that comes with Red Hat. Is that correct? RHEL's package installs in /usr/lib and /usr/lib64, not in /usr/local/lib. It's also simpler to install. Just run yum install zlib zlib-devel and it'll download and install automatically, including any dependencies. -- Kelson Vibber

Re: [Clamav-users] Twitter

2008-12-04 Thread Kelson
to be a newfangled self-important fad not worth the neologism. :-P Besides, running a blog with, as you say, actual content takes a *lot* more time than setting up Twitter. I can say that from experience. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] False positive? PUA.Script.Packed-1

2008-10-16 Thread Kelson
, but might also be used to sneak something unwanted onto a system. There was a thread a few weeks ago where someone had a whole list of things like VNC clients, port scanners, etc. -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build

Re: [Clamav-users] PUAs

2008-09-11 Thread Kelson
network was relatively patchwork and tended to be low on network tools. Though I think even Windows 98 had at least a command-line FTP client, so I'd think anything with working email should at least be able to retrieve a file from an FTP server. -- Kelson Vibber SpeedGate Communications

Re: [Clamav-users] false alarm with uploading js from wordpress

2008-04-07 Thread Kelson
://jquery.com/ The obfuscation, in this case, is a really annoying form of compression. (95 KB for the source code vs. 29 KB for the packed script.) -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV guide

Re: [Clamav-users] live CD

2008-01-22 Thread Kelson
can probably bundle in NTFS drivers from http://rpm.livna.org -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] What's this? I can't believe it!

2008-01-22 Thread Kelson
the earlier posts in this thread, but this makes it sound a lot like the problem encountered in this series of posts: http://isc.sans.org/diary.html?storyid=3817 -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV

Re: [Clamav-users] Clam bugs/vulns

2008-01-03 Thread Kelson
the target file. 4. Attacker can either enjoy the chaos, or attempt to manipulate just what the privileged app will write. -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net

Re: [Clamav-users] PhishingScanURLs is dreadfully slow/CPU-intensive

2007-11-12 Thread Kelson
*? It doesn't need root access to modify the user's own files. -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] signature names

2007-09-12 Thread Kelson
; will eventually need to add categories. -- Kelson Vibber SpeedGate Communications www.speed.net ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] XF.Sic.L def is causing tons of false positives

2006-05-23 Thread Kelson
that trigger false positives on that rule, then yes, they're going to see tons of them -- regardless of the number of hits in anyone else's logs. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] RE: Report infected mail to the user

2006-01-10 Thread Kelson Vibber
. -- Kelson Vibber SpeedGate Communications, www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] RE: Report infected mail to the user

2006-01-06 Thread Kelson Vibber
the recipient and choose a likely admin address for their domain, like [EMAIL PROTECTED], [EMAIL PROTECTED], etc. -- and those often exist. -- Kelson Vibber SpeedGate Communications, www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Triggering freshclam with procmail

2005-12-28 Thread Kelson Vibber
Harry Phillips wrote: I was wondering if it is possible and if it is advisable to trigger freshclam when I receive a message that the daily database has been updated. I used to do this, but it's no longer necessary now that freshclam can check for updates via a DNS query. You can run it as a

Re: [Clamav-users] Worm.Sober.U not being recognized

2005-11-21 Thread Kelson
what's necessary) and see if that does it. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Somebody know where find rpm packages clamav 0.87.1 for Redhat 9 / Redhat 7.3

2005-11-16 Thread Kelson
to set up a tree in your home directory so you can build as yourself. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Binary packages

2005-10-18 Thread Kelson
a package manager to take care of *all* of that (and maybe even save a copy of my config files in case I wanted to reinstall). I mean, that's what you get with RPM, and people are always telling me that Debian has *better* package management. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] Binary packages

2005-10-18 Thread Kelson
Kelson wrote: Isn't that the whole point of a package manager? Never mind -- I should have read the original post and realized he was upgrading from a manually-installed ClamAV to a pacakged version. Under that circumstance, you *do* need to manually remove everything first before installing

Re: [Clamav-users] WARNING: Your ClamAV installation is OUTDATED

2005-07-28 Thread Kelson
this behavior but being a neophyte I was only able to figure out and recompile with: You're probably better off removing the RPM entirely, rather than writing over its files. It's cleaner that way, and easier to keep track of what version is actually installed. -- Kelson Vibber SpeedGate

Re: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Kelson
to be adding several signatures a day for variations of this virus. Presumably Sophos is looking for a more generic signature that catches several variants instead of looking for lots of specific signatures. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] scanning dll type files

2005-06-17 Thread Kelson
it as a ordinary binary file. To further clarify: Yes, ClamAV can scan DLL files, just as it can scan EXE files. They're ordinary files, so no special process is needed to scan them. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http

Re: [Clamav-users] For those who submitted adware/spyware samples

2005-06-17 Thread Kelson
Niek wrote: If you want protection from ad- spyware, get anti-spyware software. I don't want to start up another flame war, but I really have to ask this question: Isn't email-borne spyware more in a virus scanner's domain than phishing is? -- Kelson Vibber SpeedGate Communications

Re: [Clamav-users] sober.p and german adverts?

2005-05-17 Thread Kelson
you suggest. And even *those* solutions have problems. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] sober.p and german adverts?

2005-05-17 Thread Kelson
to the same server (all to verify the same forged address), they just drop to the next MX, use up those connections and drop to the next Eventually they get down to our ultra-low priority decoy MX that we set up to attract spammers, and they land in our tar pit. -- Kelson Vibber SpeedGate

Re: [Clamav-users] Yum plus clamav

2005-05-13 Thread Kelson
ClamAV, and he usually updates quickly: http://dag.wieers.com/home-made/apt/ -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] possible new virus?

2005-04-19 Thread Kelson
it -- or want it! -- if you just want to enable additional features on top of the defaults. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] [CLA-2005:928] Conectiva Security Announcement - clamav

2005-03-04 Thread Kelson
for Gentoo and Mandrake (Jan. 31) and Trustix (Feb. 11). -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Tool to upgrade

2005-03-02 Thread Kelson
*are* in the database, and they're the libraries you compiled, with your options, patches and optimizations, built from the newer version your distro isn't willing to package because they prefer backporting fixes to upgrading. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] Virus Name

2005-02-03 Thread Kelson
it. In other words... Does anyone know which trojan/virus/etc. does this, and does ClamAV detect it? -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [Clamav-users] Very good (short) Article on New Technique by VirusAuthors

2005-01-31 Thread Kelson
ERROR messages over the last few days. (At first I thought something had broken in 0.81, since they started the same day I upgraded.) -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [Clamav-users] Sendmail Milter

2005-01-14 Thread Kelson
/clmilter.sock,F=,T=S:4m;R:4m)dnl define(confINPUT_MAIL_FILTERS, clmilter)dnl Looks to me as though you've used the wrong opening quote character. And closing quote character. IIRC, it should open with an ASCII backtick (`) and close with a (vertical) ASCII apostrophe (') -- Kelson Vibber

Re: [Clamav-users] Virus naming

2004-12-17 Thread Kelson
., and a few specific names to decide how to handle the message. (FWIW, we use MIMEDefang to integrate the scanners and discard/reject/disinfect messages.) -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lists.clamav.net/cgi-bin

[Clamav-users] Re: defanging HTML, was ClamAV should not try to detect phishing and other social engineering attacks

2004-11-16 Thread Kelson
. This can probably be done using action_external_filter, but you still need to figure out which parts to convert and which to discard, pick a parser (as Matthew pointed out, there can be security concerns here), change the mime type, etc. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] ClamAV should not try to detect phishing and other social engineering attacks

2004-11-15 Thread Kelson
...dynamically rewriting all email to a standard format. I believe you can do this with Can-It Pro. http://www.roaringpenguin.com/ They're the authors of MIMEDefang. Can-It is their commercial product, and a much more thorough solution. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] Updating to clamav 8 from 7.5 on Redhat8

2004-11-03 Thread Kelson
, clamav-milter, clamav-db, clamd) instead of just the 2 (clamav and clamav-milter) in the default RPM spec. Unfortunately, that means if you upgrade from DAG's package to a home-grown one, you can't just use rpm -Uvh like you would in most situations. -- Kelson Vibber SpeedGate Communications

Re: [Clamav-users] If you want to post/reply to the list, read this please.

2004-09-30 Thread Kelson
. -- Kelson Vibber SpeedGate Communications www.speed.net ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [Clamav-users] Notification E-mail

2004-09-22 Thread Kelson
Simple solution to the question of whether to send a notice: You know what virus was detected. You know whether it's a mass-mailer or something else. (starts with Worm., ends with @mm, a few specific others) Based on that, you can decide whether to reject it or discard it. -- Kelson Vibber

Re: [Clamav-users] Clamav and pictures

2004-09-16 Thread Kelson
to it, so as long as the signature is there, it should find it. -- Kelson Vibber SpeedGate Communications www.speed.net --- This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 Project Admins to receive an Apple iPod Mini FREE for your

Re: [Clamav-users] Chacking clamd

2004-09-09 Thread Kelson
[EMAIL PROTECTED] wrote: I use RedHat9 I've just installed clamav and I've started clamd. How can I chack if the daemon is really work? Is there any test virus to send to my email? See http://www.testvirus.org -- Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] Downloading clam virus definition files automatically

2004-08-20 Thread Kelson Vibber
them. Kelson Vibber SpeedGate Communications www.speed.net --- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33 Save 50% off Retail on Ink Toner - Free

Re: [Clamav-users] New virus/worm ???

2004-08-09 Thread Kelson Vibber
this? Tons of 'em. Run freshclam -- update 444 picks it up as Trojan.JS.RunMe. Kelson Vibber SpeedGate Communications www.speed.net --- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk

Re: [Clamav-users] Ethics Question

2004-06-11 Thread Kelson Vibber
asking Should we be concerned about this? I forget whether it had come in through another channel or just before freshclam picked up the signature, but they ended up on our blacklist because of the forward. So there are risks to anything. Kelson Vibber SpeedGate Communications www.speed.net

Re: [Clamav-users] ERROR: You must specify at least one database mirror.

2004-05-12 Thread Kelson Vibber
that is calling freshclam. Kelson Vibber SpeedGate Communications www.speed.net --- This SF.Net email is sponsored by Sleepycat Software Learn developer strategies Cisco, Motorola, Ericsson Lucent use to deliver higher performing products

Re: [Clamav-users] Recommendation RedHat replacement

2004-05-10 Thread Kelson Vibber
-party RPMs built for RHEL 3 should also work on WBEL. I installed it on a test box, and while I haven't done a whole lot with it, I haven't run into any problems with what I have tried. I hope this helps! Kelson Vibber SpeedGate Communications www.speed.net