Re: [clamav-users] ClamAV to detect exploits for the Equation Editor vulnerability in DOC files

2021-01-23 Thread G.W. Haywood via clamav-users
Hello again, On Sat, 23 Jan 2021, Chaminda Indrajith via clamav-users wrote: ... I have the evidence that Clamd finds threats, but it cannot detect some of the threats As I said this is not unusual. From my experience I would say that of all the threats that I see, ClamAV will typically

Re: [clamav-users] ClamAV to detect exploits for the Equation Editor vulnerability in DOC files

2021-01-23 Thread Chaminda Indrajith via clamav-users
Hi , > Mainly, we get these virus via E-mail. ... Can I assume that it's clamd which scans these emails? Yes. Clamd scans the e-mails > OLE2BlockMacros = "yes" There are other settings which you might want to investigate. See for example the 'Alert...' options in the clamd.conf man page which

Re: [clamav-users] ClamAV to detect exploits for the Equation Editor vulnerability in DOC files

2021-01-23 Thread G.W. Haywood via clamav-users
Hi there, On Fri, 22 Jan 2021, Chaminda Indrajith via clamav-users wrote: Mainly, we get these virus via E-mail. ... Can I assume that it's clamd which scans these emails? OLE2BlockMacros = "yes" There are other settings which you might want to investigate. See for example the

Re: [clamav-users] adding additional database

2021-01-23 Thread G.W. Haywood via clamav-users
Hi there, On Fri, 22 Jan 2021, Joe Acquisto-j4 wrote: looking for how to add additional (3rd party?) database(s) to clamav install. 1. Find the desired third-party database(s) and download them. [*] 2. Place the file(s) in the same directory as the official databases. 3. Restart clamd if

[clamav-users] Fwd: Re: Trying to use daemon service to scan on demand with php

2021-01-23 Thread Paul Claridge
The php lib uses socket commands and accesses the socket directly and then sends the command "SCAN fullfilepath" We have a policy of not using "exec" currently so I'm not sure how I would invoke clamdscan? Thx, Paul--- Begin Message --- On Sat, 23 Jan 2021, Paul Claridge wrote: Hi Team,

Re: [clamav-users] Trying to use daemon service to scan on demand with php

2021-01-23 Thread Andrew C Aitchison via clamav-users
On Sat, 23 Jan 2021, Paul Claridge wrote: My current project is a web service on Ubuntu LAMP (20.02LTS). I have installed the clamav-daemon package successfully. My php scripts run as www-data:www-data and I have changed the user and group in /etc/clamav/clamd.conf to www-data:www-data so

[clamav-users] Trying to use daemon service to scan on demand with php

2021-01-23 Thread Paul Claridge
Hi Team, I have been playing with unix systems for a long time. My current project is a web service on Ubuntu LAMP (20.02LTS). I have installed the clamav-daemon package successfully. My php scripts run as www-data:www-data and I have changed the user and group in /etc/clamav/clamd.conf to