Re: [Clamav-users] clamav-milter logging habbits

2005-06-30 Thread Nigel Horne
From /var/log/mail: Jun 30 03:38:28 diomedes clamav-milter[60071]: j5U0cN65081507: /var/tmp/clamav/msg.G8CVC4: HTML.Phishing.Bank-1 Intercepted virus from [EMAIL PROTECTED] to [EMAIL PROTECTED] Jun 30 03:38:28 diomedes clamav-milter[60071]: File quarantined as

[Clamav-users] Clam Denial Of Service

2005-06-30 Thread Scott Ryan
gentoo-announce] [ GLSA 200506-23 ] Clam AntiVirus: Denial of Service Vulnerability Sorry if this has been discussed before: I do not see anything on the ClamAV website indicating the status of this potential DoS or whether is rectified or even no applicable. Can anyone shed some light on this

Re: [Clamav-users] Clam Denial Of Service

2005-06-30 Thread Odhiambo Washington
* Scott Ryan [EMAIL PROTECTED] [20050630 11:34]: wrote: gentoo-announce] [ GLSA 200506-23 ] Clam AntiVirus: Denial of Service Vulnerability Sorry if this has been discussed before: I do not see anything on the ClamAV website indicating the status of this potential DoS or whether

Re: [Clamav-users] Clam Denial Of Service

2005-06-30 Thread Mehmet Ekiz
Odhiambo Washington yazmış: * Scott Ryan [EMAIL PROTECTED] [20050630 11:34]: wrote: gentoo-announce] [ GLSA 200506-23 ] Clam AntiVirus: Denial of Service Vulnerability Sorry if this has been discussed before: I do not see anything on the ClamAV website indicating the status

Re: [Clamav-users] Clam Denial Of Service

2005-06-30 Thread Odhiambo Washington
* Mehmet Ekiz [EMAIL PROTECTED] [20050630 12:15]: wrote: Odhiambo Washington yazmış: * Scott Ryan [EMAIL PROTECTED] [20050630 11:34]: wrote: gentoo-announce] [ GLSA 200506-23 ] Clam AntiVirus: Denial of Service Vulnerability Sorry if this has been discussed before: I do not see

[Clamav-users] Question about Virus definitions

2005-06-30 Thread Pedro Silva
Dear members, During the last hours I have received several email containing the W32/Mytob-Fam (Sophos name), which were not caught by Clam. Can someone tell me why Clam is not detecting this virus? Best Regards ___ Pedro Silva IT - Instituto

[Clamav-users] Problem with clamav

2005-06-30 Thread Jörg Wittkemper
Hi, at the last day's I have the following Mesage in my logfile: ... ClamAV-clamd: Can't send to socket /var/lib/clamav/clamd.sock: Transport endpoint is not connected, retrying (1) ... ClamAV-clamd: Can't connect to UNIX socket /var/lib/clamav/clamd.sock: Connection refused, retrying (2) ...

RE: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Randal, Phil
Pedro Silva asked: Dear members, During the last hours I have received several email containing the W32/Mytob-Fam (Sophos name), which were not caught by Clam. Can someone tell me why Clam is not detecting this virus? No idea, but you should submit samples to:

Re: [Clamav-users] Clamd Dies after zip attachment in email

2005-06-30 Thread Trog
On Wed, 2005-06-29 at 09:07 -0700, Dale Anderson wrote: I just updated my clamav to version 0.86.1/960 I had to change the clamd.conf I was receiving when tring to start Clamd. StreamSaveToDisk not supported. So I alter the clamd.conf that came with the update version and now clamd dies when

Re: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Odhiambo Washington
* Pedro Silva [EMAIL PROTECTED] [20050630 13:16]: wrote: Dear members, During the last hours I have received several email containing the W32/Mytob-Fam (Sophos name), which were not caught by Clam. Can someone tell me why Clam is not detecting this virus? clamd --version

RE: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Pedro Silva
definitions * Pedro Silva [EMAIL PROTECTED] [20050630 13:16]: wrote: Dear members, During the last hours I have received several email containing the W32/Mytob-Fam (Sophos name), which were not caught by Clam. Can someone tell me why Clam is not detecting this virus? clamd

[Clamav-users] Milter problem

2005-06-30 Thread Brett Greenleaf
Hi all. I was running 0.86rc1 on a Solaris 9 box, when on Monday night, suddenly, it stopped running. I looked in the log file, and found many instances of this: LibClamAV Warning: j5S0vCAs024426: /export/home/var/tmp/clamav-a125906f23a14050/msg.PsL6E1: No viruses detected ERROR LibClamAV

Re: [Clamav-users] Milter problem

2005-06-30 Thread Richard Pijnenburg
Hi Brett, It seems your server has reached the limit of open files: LibClamAV Error: Can't create temporary file /export/home/var/tmp/clamav-ae56442370c55c7c/textportion8sL6E1: Too many open files -- It could be that it isn't closing the files Or there are to many programs running. Perheaps

Re: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Kevin Brouelette
Paul, Additionally, you can create your own sig. http://www.clamav.net/doc/0.86.1/signatures.pdf Kevin - Original Message - From: Randal, Phil [EMAIL PROTECTED] To: ClamAV users ML clamav-users@lists.clamav.net Sent: Thursday, June 30, 2005 3:21 AM Subject: RE: [Clamav-users]

Re: [Clamav-users] Question about Virus definitions

2005-06-30 Thread Kelson
Pedro Silva wrote: During the last hours I have received several email containing the W32/Mytob-Fam (Sophos name), which were not caught by Clam. Can someone tell me why Clam is not detecting this virus? Mytob seems to mutate insanely fast. According to the clamav-virusdb list, Clam seems

Re: [Clamav-users] clamav-milter logging habbits

2005-06-30 Thread Panagiotis Christias
On 6/30/05, Nigel Horne [EMAIL PROTECTED] wrote: From /var/log/mail: Jun 30 03:38:28 diomedes clamav-milter[60071]: j5U0cN65081507: /var/tmp/clamav/msg.G8CVC4: HTML.Phishing.Bank-1 Intercepted virus from [EMAIL PROTECTED] to [EMAIL PROTECTED] Jun 30 03:38:28 diomedes

[Clamav-users] Why no actual data in mail header?

2005-06-30 Thread Thomas Booms
Hi all, I got the newest signatures automatic and the last one from today downloading manually: Received signal: wake up ClamAV update process started at Wed Jun 29 07:22:37 2005 main.cvd is up to date (version: 32, sigs: 34720, f-level: 5, builder: tkojm) daily.cvd updated (version: 960,

[Clamav-users] clamav updates - freshclam versus recompiling

2005-06-30 Thread Casey Allen Shobe
Why do we have to recompile clamav all the time to get updates? I thought that's what freshclam was for. We were running clamav 0.86 with freshclam, and Worm.Mytob.FM was making it past the filter. Compiling 0.86.1 fixed things, but I don't really understand why. We generally like to test

Re: [Clamav-users] clamav updates - freshclam versus recompiling

2005-06-30 Thread Jim Maul
Casey Allen Shobe wrote: Why do we have to recompile clamav all the time to get updates? I thought that's what freshclam was for. Because something is broken? I've never had to to do that. We were running clamav 0.86 with freshclam, and Worm.Mytob.FM was making it past the filter.

Re: [Clamav-users] Why no actual data in mail header?

2005-06-30 Thread Thomas Booms
Jim Maul schrieb: Thomas Booms wrote: Hi all, I got the newest signatures automatic and the last one from today downloading manually: Received signal: wake up ClamAV update process started at Wed Jun 29 07:22:37 2005 main.cvd is up to date (version: 32, sigs: 34720, f-level: 5, builder:

Re: [Clamav-users] clamav-milter logging habbits

2005-06-30 Thread Nigel Horne
On Thursday 30 Jun 2005 19:28, Panagiotis Christias wrote: On 6/30/05, Nigel Horne [EMAIL PROTECTED] wrote: From /var/log/mail: Jun 30 03:38:28 diomedes clamav-milter[60071]: j5U0cN65081507: /var/tmp/clamav/msg.G8CVC4: HTML.Phishing.Bank-1 Intercepted virus from [EMAIL PROTECTED] to

Re: [Clamav-users] clamav-milter logging habbits

2005-06-30 Thread Todd Lyons
Nigel Horne wanted us to know: This is a feature request. The first line in the log carries a lot of useful information, almost everything. Would it be possible to also include the sender's IP address? It would save us a few lines of scripting when analyzing the logs. Given the number of

Re: [Clamav-users] clamav-milter logging habbits

2005-06-30 Thread Damian Menscher
On Thu, 30 Jun 2005, Nigel Horne wrote: On Thursday 30 Jun 2005 19:28, Panagiotis Christias wrote: From /var/log/mail: Jun 30 03:38:28 diomedes clamav-milter[60071]: j5U0cN65081507: /var/tmp/clamav/msg.G8CVC4: HTML.Phishing.Bank-1 Intercepted virus from [EMAIL PROTECTED] to [EMAIL PROTECTED]

Re: [Clamav-users] Milter problem

2005-06-30 Thread Stephen Gran
On Thu, Jun 30, 2005 at 04:32:49PM +0200, Richard Pijnenburg said: Hi Brett, It seems your server has reached the limit of open files: LibClamAV Error: Can't create temporary file /export/home/var/tmp/clamav-ae56442370c55c7c/textportion8sL6E1: Too many open files -- It could be that it