Re: [clamav-users] ClamAV 1.3.0 feature release and 1.2.2, 1.0.5 security patch release!

2024-02-07 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd) via clamav-users" : [...] * 0.104 (all patch versions) * 0.105 (all patch versions) * 1.0.0 through 1.0.4 (LTS) * 1.1 (all patch versions) * 1.2.0 and 1.2.1 Do I understand correctly that 0.103 LTS is not affected by this?

Re: [clamav-users] ClamAV 1.3.0 release candidate published

2024-01-30 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : Citeren "Micah Snyder (micasnyd) via clamav-users" : Tip: If you are downloading the source from the GitHub release page, the package labeled "clamav-1.3.0-rc.tar.gz" does not require an internet connection to build. All depen

Re: [clamav-users] ClamAV 1.3.0 release candidate published

2023-12-15 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd) via clamav-users" : Tip: If you are downloading the source from the GitHub release page, the package labeled "clamav-1.3.0-rc.tar.gz" does not require an internet connection to build. All dependencies are included in this package. But if you download the

Re: [clamav-users] Segfaults with database version 26908

2023-05-16 Thread Arjen de Korte via clamav-users
Citeren David Raynor : Based on these reports we've started a take-back of the signature, so it will be dropped in the next daily CVD publish. We'll also analyze to see why this signature is triggering that behavior on some platforms. Here freshclam (1.1.0) does complain about this signature,

Re: [clamav-users] Version .105

2022-06-29 Thread Arjen de Korte via clamav-users
Citeren "West, Hunter D [US] (ES) via clamav-users" : Hello, I am unsure if I've come to the right place, but I need to install ClamAV version .105. I work in a SAP environment with no internet connection to our machines. The current version of ClamAV is .99 - I went to

Re: [clamav-users] ClamAV 0.105 release candidate

2022-03-15 Thread Arjen de Korte via clamav-users
Citeren "Michael Peterson (mipeter2) via clamav-users" : Same behavior with previous version: ➜ ~ wget https://www.clamav.net/downloads/release_candidate/clamav-0.104.2.tar.gz --2022-03-14 17:34:36-- https://www.clamav.net/downloads/release_candidate/clamav-0.104.2.tar.gz Resolving

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Arjen de Korte via clamav-users
Citeren Joel Esler via clamav-users : On Jan 17, 2022, at 10:17, Maarten Broekman via clamav-users wrote: And, after 7 days, you'll see warning messages about outdated definitions when clam starts up. And Freshclam and cvdupdate will still download the right files. This largely

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Arjen de Korte via clamav-users
Citeren Nick Howitt via clamav-users : Not quite. I have taken over the packaging of this and the justification of packaging the sigs is partly that the tool will work and scan out of the box, partly for the offline consideration and partly because there will be a delay after installation

Re: [clamav-users] help with my system please hybrid os does not update signatures

2022-01-16 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte : Citeren colin course via clamav-users : last installment of log file is this regards colin Thu Jan 6 11:26:43 2022 -> Giving up on https://database.clamav.net... Thu Jan 6 11:26:43 2022 -> ERROR: Update failed for database: daily Thu Jan 6 11:26:43 2022 -> ERROR:

Re: [clamav-users] help with my system please hybrid os does not update signatures

2022-01-16 Thread Arjen de Korte via clamav-users
Citeren colin course via clamav-users : last installment of log file is this regards colin Thu Jan 6 11:26:43 2022 -> Giving up on https://database.clamav.net... Thu Jan 6 11:26:43 2022 -> ERROR: Update failed for database: daily Thu Jan 6 11:26:43 2022 -> ERROR: Database update process

Re: [clamav-users] help with my system please hybrid os does not update signatures

2022-01-14 Thread Arjen de Korte via clamav-users
Citeren colin course via clamav-users : long story short i cant update clamav i also have the tk version there is zero signatures on it ,so it cant find any dogey files , sigh :( Which version of ClamAV? Please post the output of 'clamscan -V' here. You'll need at least version 0.103 in

Re: [clamav-users] clamac + amavis database reload

2021-11-10 Thread Arjen de Korte via clamav-users
Citeren Philipp Ewald : if the databases from clamav has changed clam-av is reloading by himself. I have configured to check every 5 min. That's a bit excessive. The DNS record that freshclam checks has a TTL of 1800 seconds, so checking more often than every minutes is a waste of

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd)" : I've run into this issue with the fixed port # on our test systems occasionally as well. I think I can identify an open port in the python code to make it more reliable, but haven't have time to try it. I'm not sure if it is worth the effort. It seems

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Arjen de Korte via clamav-users
Citeren "Joel Esler (jesler) via clamav-users" : I’m a fan of the thought of removing the user manual completely from the downloaded packages and including a link to docs.ClamAV.net. Since that’s more dynamic. I wouldn't be too heartbroken if that happened. For the 0.104.0 release,

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : Hi there, On Sun, 22 Aug 2021, Joel Esler (jesler) via clamav-users wrote: I’m a fan of the thought of removing the user manual completely from the downloaded packages and including a link to docs.ClamAV.net. Since that’s more dynamic. But not so

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-20 Thread Arjen de Korte via clamav-users
Citeren "Joel Esler (jesler) via clamav-users" : https://blog.clamav.net/2021/08/clamav-01040-second-release-candidate.html ClamAV 0.104.0 Second Release Candidate is here! Today we are publishing a second

Re: [clamav-users] Opinion wanted: Change default config directory usr/clamav

2021-07-31 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd) via clamav-users" : Hi all, I could use your opinion about a change we'd planned to make in 0.104. By request, I'd made this pull request to change the default directory for the config files from /etc to /etc/clamav. The purpose being to de-clutter

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-30 Thread Arjen de Korte via clamav-users
Citeren Paul Kosinski via clamav-users : LTS sounds like a great idea! Recently, the bandwidth hogging episodes have resulted in rapid changes to ClamAV versions, followed by EOL of versions that many people (not including me) were still using. So recently I have had to spend far more

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-30 Thread Arjen de Korte via clamav-users
Citeren Gene Heskett via clamav-users : Well, I've screwed around with this for 3 days now, that's long enough. First gotcha for debian people is cmake is not installed, and when installed, it is NOT installed in a directory accessible to the user with a default $PATH, so the first thing I

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-25 Thread Arjen de Korte via clamav-users
Citeren Frans de Boer : On 7/25/21 8:50 PM, Arjen de Korte via clamav-users wrote: Citeren Frans de Boer : I get things compiled etc., but testing clamd keeps on failing. I tried three different machines/CPU's to no avail. I use OpenSUSE Tumbleweed with newest cmake etc. I have

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-25 Thread Arjen de Korte via clamav-users
Citeren Frans de Boer : I get things compiled etc., but testing clamd keeps on failing. I tried three different machines/CPU's to no avail. I use OpenSUSE Tumbleweed with newest cmake etc. I have an experimental version available in

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-25 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : [6s] -- Performing Test Iconv_IS_BUILT_IN [6s] -- Performing Test Iconv_IS_BUILT_IN - Failed [6s] CMake Error at /usr/share/cmake/Modules/FindPackageHandleStandardArgs.cmake:230 (message): [6s] Could NOT find Iconv (missing

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-25 Thread Arjen de Korte via clamav-users
Citeren "Gary R. Schmidt" : On 24/07/2021 17:01, Gary R. Schmidt wrote: [SNIP] Next I will try with GCC/G++, wonder where it will fail... [ snip ] Fails for me in pretty much the same way on Linux: [4s] -- The C compiler identification is GNU 11.1.1 [4s] -- The CXX compiler

Re: [clamav-users] Getting 403 error : cvshealth

2021-04-14 Thread Arjen de Korte via clamav-users
Citeren "Puri, Rohit via clamav-users" : Hi Team Can you please help support on this , I am getting the following errors . ^downloadFile: Unexpected response (403) from https://database.clamav.net/safebrowsing.cvd https://blog.clamav.net/2021/04/are-you-still-attempting-to-download.html

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-07 Thread Arjen de Korte via clamav-users
clamav.net/downloads and trimming the HTML code, a straight download link for the keyfile would make it easier to verify it. On Apr 7, 2021, at 4:29 PM, Arjen de Korte via clamav-users wrote: Citeren "Joel Esler (jesler) via clamav-users" : It seems the package is now signed

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-07 Thread Arjen de Korte via clamav-users
Citeren "Joel Esler (jesler) via clamav-users" : It seems the package is now signed with a different PGP key. Is there a location from where I can directly download the public key, rather than copying it from the webpage? Best regards, Arjen

Re: [clamav-users] ClamAV 0.103.1 on RHEL 6.7 x32

2021-04-06 Thread Arjen de Korte via clamav-users
Citeren Eero Volotinen : Well redhat backports some fixes usually as you can see: https://access.redhat.com/blogs/766093/posts/1976123 Backporting fixes/features, doesn't make openssl-1.0.1 equivalent to openssl-1.0.2. If that was the case, it wouldn't make sense to backport the

Re: [clamav-users] ClamAV 0.103.1 on RHEL 6.7 x32

2021-04-06 Thread Arjen de Korte via clamav-users
Citeren Eero Volotinen : Well. I think that it just works as RHEL 6.7 supports tls v1.2 TLS 1.2 was first available in openSSL 1.0.1 and ClamAV requires at least 1.0.2 now, so there is no guarantee. As someone else already mentioned, RHEL 6.10 (which was EOL'd in Novemver 2020) comes with

Re: [clamav-users] Need help | Install clamav from source package

2021-03-28 Thread Arjen de Korte via clamav-users
Citeren Andrew C Aitchison via clamav-users : Could you take the latest OpenSuSE source package and build that ? Probably not. There have been quite some changes since 0.99 and I doubt SLE 12 SP2 will satisfy all of them. For instance, you'll need a newer libcurl than is available. This

Re: [clamav-users] Need help | Install clamav from source package

2021-03-28 Thread Arjen de Korte via clamav-users
Citeren "amit.a.singh--- via clamav-users" : Hello Eero, Thanks for your email, we have suse12 sp2 while installing using zypper install clamav its shows available package is clamav 0.99 version which pretty old so we choose to install from source which have updated one 103. The LTSS

Re: [clamav-users] Freshclam Update Error

2021-03-25 Thread Arjen de Korte via clamav-users
Citeren Wayne Florence via clamav-users : Paul, Turns out I had 2 versions installed and was using 0.98 when I switched to version 102.4 I get a certificate error now. * Peer's certificate issuer has been marked as not trusted by the user. * Closing connection 1 WARNING:

Re: [clamav-users] help my IP address has been blocked

2021-03-21 Thread Arjen de Korte via clamav-users
Citeren Diego D'Amico : I am using few synology at home and since I installed a new one, my IP address 80.254.190.8 has been blocked and I cannot update any more the signature on all of them. In that case, you're either running an outdated version of ClamAV (< 0.100) or you're not using

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Arjen de Korte via clamav-users
Citeren Rémy DODIN via clamav-users : Now, I give a try on clamwin ! If you had checked the archives, you would have known in advandce this is a waste of time. You have the latest version of ClamWin Free Antivirus (0.99.4). Version 0.99.4 < 0.100 which means it is no longer supported.

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Arjen de Korte via clamav-users
Citeren Matus UHLAR - fantomas : On 13.03.21 14:39, Arjen de Korte via clamav-users wrote: Which would be the decent way too. If QNAP/Synology is monetizing on a product that is provided to them free of charge, the least they could do is to take the burden of the updates of the signatures

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Arjen de Korte via clamav-users
In order to discourage downloading the main.cld and daily.cld files, would it be an option to only update them on the download servers when a new ClamAV release is made? This might nudge people that choose to not use one of the recommended options to download signatures, to reconsider.

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : QNAP runs freshclam. checked now with my 419P+: ClamAV update process started at Sat Mar 13 12:47:36 2021 WARNING: getpatch: Can't download main-55.cdiff from database.clamav.net ERROR: getpatch: Can't download main-55.cdiff from database.clamav.net That

Re: [clamav-users] Private Mirror Via Artifactory

2021-03-12 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : One might still workaround this issue, by setting up a private mirror *outside* of your network perimeter ... I think the OP was saying that he's not allowed to do that. The way things are for him at the moment, the path of least resistance might be a

Re: [clamav-users] Private Mirror Via Artifactory

2021-03-12 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : If your only option is to use artifactory, then you need to contact JFrog's technical support because they're the only people who can fix that. After all, that's what you're paying them for. I'm sure they'll be working on (or will already have) an

Re: [clamav-users] Unable to download clamav cvd file using google cloud python function

2021-03-11 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : You *may* be forgetting NAT. Eg, it's possible the first one is a network of a few thousand computers going through a NAT firewall where each of them has had an old daily.cvd copied onto them in an internal release cycle or something, so each of the

Re: [clamav-users] looks like I have a problem too

2021-03-10 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : That's certainly how it seems to behave here. If the DNS record hasn't changed, then it just says "everything's fine" and does nothing else. So, if you ran Freshclam every minute, it wouldn't download anything except lots of DNS queries (which would be

Re: [clamav-users] Unable to download clamav cvd file using google cloud python function

2021-03-10 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : Indeed. There does seem to be a view from some people here that anyone using ClamAV should be regularly updating, monitoring this list, monitoring blogs, etc. Ordinary people just don't do that. I wonder how many ordinary users are actually *not* using

Re: [clamav-users] freshclam getfile failed - and clamav links Cloudfare 1020 error.

2021-03-10 Thread Arjen de Korte via clamav-users
Citeren "r.dodin via clamav-users" : This didn't tell me why I have " Error 1020 Ray ID: 62de621bbe42b787 • 2021-03-10 17:50:04 UTC Access denied " Accessing through firefox 45.9.0 https://www.clamav.net ? Regards Rémy Your IP is probably blocked. But really, Firefox 45.9.0? I

Re: [clamav-users] Database update downloads blocked with 403 error

2021-03-10 Thread Arjen de Korte via clamav-users
Citeren Matt Forsdike via clamav-users : We are unable to use Freshclam but instead have 4 servers which download the main.cvd, daily.cvd and bytecode.cvd files daily at around 4am GMT. Since 5 March we have been getting a 403 error. I understand that you have a serious problem to

Re: [clamav-users] QNAP - Cannot update virus definition & cannot wget *.cvd (receive error 403 forbidden)

2021-03-07 Thread Arjen de Korte via clamav-users
Citeren Thomas Guerlinze via clamav-users : I restarted an old QNAP NAS (TS419P). I updated the firmware to the latest version available for this model (4.3.3.1432 build 20200106). I tried to use the GUI provided by QNAP to update the ClamAV on the NAS. I received "update failed" message.

Re: [clamav-users] I can't update Clamav database for 5 days

2021-03-07 Thread Arjen de Korte via clamav-users
Citeren Paul Smith via clamav-users : A sudden configuration change (due to excessive updates by some parties) on the ClamAV servers has broken updates for any EOL versions of ClamAV. (It's caught quite a few of us out!) This was announced almost a month ago on on both the clamav-announce

Re: [clamav-users] I can't update Clamav database for 5 days

2021-03-07 Thread Arjen de Korte via clamav-users
Citeren Jérôme Giry via clamav-users : I use it with Clamwin-0.99.4 downloaded on his official site. This is a third-party product that uses an older version of ClamAV. As it is the last version of Clamwin, I assume it uses the last version of Clamav too (0.103.1) See

Re: [clamav-users] I can't update Clamav database for 5 days

2021-03-07 Thread Arjen de Korte via clamav-users
Citeren Jérôme Giry via clamav-users : I can't update Clamav database for 5 days. I'm Windows 10 user. Attached the update log. I tried to uninstall and re-install it, but there are still the same errors and warnings. Thank you for your help. Which version of ClamAV is this?

Re: [clamav-users] Clamav-milter finds postive, goes to hold queue

2021-02-24 Thread Arjen de Korte via clamav-users
Citeren Matus UHLAR - fantomas : you can use amavisd-new, as milter (using amavisd-milter) or maybe postfix content_filter (but that's post-queue which means you can't reject it anymore and sending bounces is not safe) Postfix has also a smtpd_proxy_filter, which does basically the same as

Re: [clamav-users] Clamav-milter finds postive, goes to hold queue

2021-02-23 Thread Arjen de Korte via clamav-users
Citeren Joe Acquisto-j4 : Another question from the peanut gallery (a kids TV show reference from the 1950's. Which should tell you something) . . . With a local test email EICAR is detected and fed back to postfix. Ends up in hold queue as you would expect as per below as /var/log/mail says:

Re: [clamav-users] clamav-milter start or restart changes owner/group

2021-02-23 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : This is not to say that it can't be worked around by the configuration of clamav-milter directly, of course it can, but if he does that he'll be confused by the next update, when it bleats about files having been changed from the versions which were

Re: [clamav-users] clamav-milter start or restart changes owner/group

2021-02-23 Thread Arjen de Korte via clamav-users
Citeren Joe Acquisto-j4 : Citeren "G.W. Haywood via clamav-users" : Hi there, On Tue, 23 Feb 2021, Joe Acquisto-j4 wrote: Seems starting or restarting clamav-milter (systemctl restart clamav-milter.service) changes owner and group of /var/run/clamav-milter.socket to root which make the

Re: [clamav-users] clamav-milter start or restart changes owner/group

2021-02-23 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : Hi there, On Tue, 23 Feb 2021, Joe Acquisto-j4 wrote: Seems starting or restarting clamav-milter (systemctl restart clamav-milter.service) changes owner and group of /var/run/clamav-milter.socket to root which make the socket inaccessible to

Re: [clamav-users] ClamAVPlugin

2021-02-19 Thread Arjen de Korte via clamav-users
Citeren Joe Acquisto-j4 : Sorry I did not think to explain properly. Using Postfix and Spamassassinm on an OpenSuse version of Linux (15.1 or something) wanting to add AV scanning to incoming mail. Started attempting Sophos for Linux (savd ?) but they have or soon will abandon the product.

Re: [clamav-users] Memory usage going up until OOM

2020-12-02 Thread Arjen de Korte via clamav-users
Citeren PenguinWhispererThe via clamav-users : Hi, I have a webserver with 4GB of memory that also functions as a mailserver. The mail volume is rather low (perhaps a few hundred mails/day). Almost every day around the same time I get a swap usage warning and once in a while clamd crashes

Re: [clamav-users] False positive (?) in check6_clamd_vg test

2020-09-18 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd)" : Hi Arjen, I see what you're talking about. It is a little confounding. We have a valgrind suppression rule for this specific issue: https://github.com/Cisco-Talos/clamav-devel/commit/8cfec0b245abfac9564c11012d67b19da004e927 {

[clamav-users] False positive (?) in check6_clamd_vg test

2020-09-18 Thread Arjen de Korte via clamav-users
Three of the four valgring tests fail, with what seems to be false positives: ==18703== ERROR SUMMARY: 12 errors from 1 contexts (suppressed: 0 from 0) ==18703== ==18703== 12 errors in context 1 of 1: ==18703== Source and destination overlap in memcpy_chk(0x1ffeffd1e0, 0x1ffeffd1fe, 549)

Re: [clamav-users] Clamav signature

2020-09-17 Thread Arjen de Korte via clamav-users
Citeren Jeff Koch : Thanks. The freshclam logs show daily.cvd signature file version 25930 is installed but simscan: clamscan currently shows version 25920 being used. How do I get clamscan to use the latest version downloaded? Could be a different location is configured where freshclam

Re: [clamav-users] Clamav signature

2020-09-17 Thread Arjen de Korte via clamav-users
Citeren Jeff Koch : HI Looking through our scanning logs we see what appears to be a signature that looks like this clamav: 0.102.4/m:59/d:25920 '0.102.4' refers to the clamav version but what does the rest mean - m:59/d:25920 ? If you look at the freshclam logs, the pattern is fairly

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.0 released!

2020-09-15 Thread Arjen de Korte via clamav-users
ClamAV 0.103.0 builds (and runs) fine most of the time, but I do see (infrequent) failing checks on the build servers for openSUSE. This could be a race condition in the tests and might depend on the number of cores or CPU of the buildserver it runs on. One thing that does concern me

Re: [clamav-users] ClamAV 0.103.0 rc2

2020-09-11 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : I've seen no evidence of a memory leak at all. The 0.103.0-rc2 daemon has been running for eight days continuously. It's currently using (top, RSS) about 8.6 MBytes of RAM - and 6.9 MBytes of that is shared. I used systemd-cgtop

Re: [clamav-users] [SUSPECTED SPAM] Re: ClamAV 0.103.0 rc2

2020-09-09 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : Citeren Arjen de Korte via clamav-users : Patch applies cleanly, running ./autogen.sh is successful and logging of freshclam is back to what it used to be. Thanks! See https://build.opensuse.org/package/show/home:adkorte/clamav

Re: [clamav-users] [SUSPECTED SPAM] Re: ClamAV 0.103.0 rc2

2020-09-09 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : Patch applies cleanly, running ./autogen.sh is successful and logging of freshclam is back to what it used to be. Thanks! See https://build.opensuse.org/package/show/home:adkorte/clamav DefaultMemoryAccounting is enabled in openSUSE Tumbleweed. One

Re: [clamav-users] [SUSPECTED SPAM] Re: ClamAV 0.103.0 rc2

2020-09-09 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd) via clamav-users" : Kevin, Arjen, all: If you're interested, we found the cause of the freshclam SysLog issue. The source ended up being an issue with our autotools build system and how we link freshclam. If any of you are willing to try this patch, it'd

Re: [clamav-users] TIME-WAIT connections when scanning with clamdscan

2020-09-08 Thread Arjen de Korte via clamav-users
Citeren Giovanni Bechis : Hi, I have setup a clamav server listening on 0.0.0.0:3310 and a client that runs "clamdscan --no-summary --infected --stream --fdpass $FILE" to remotely scan files/emails for viruses. When clamdscan exits and the report is printed on the screen the connection on

Re: [clamav-users] ClamAV 0.103.0 rc2

2020-09-03 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : I seem to have missed the announcement of clamav-0.103.0-rc2. The problems I reported earlier with clamav-0.103.0-rc seem to be resolved now. All is well again. Correction: *almost* all is well again. Freshclam doesn't log anything to syslog

[clamav-users] ClamAV 0.103.0 rc2

2020-09-02 Thread Arjen de Korte via clamav-users
I seem to have missed the announcement of clamav-0.103.0-rc2. The problems I reported earlier with clamav-0.103.0-rc seem to be resolved now. All is well again. ___ clamav-users mailing list clamav-users@lists.clamav.net

Re: [clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
Citeren Michael Orlitzky via clamav-users : Well empirically that's not true, because it isn't working. Add PIDFile entries to your service files when using Type=forking, and synchronize them with the PidFile lines in clamd.conf and freshclam.conf. Makes no difference at all. Even without

Re: [clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
Citeren Michael Orlitzky via clamav-users : On 2020-08-21 08:11, Arjen de Korte via clamav-users wrote: Not unconditionally. See the following from 'man 5 systemd.service': "The PID file does not need to be owned by a privileged user, but if it is owned by an unprivileged

Re: [clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
Citeren Michael Orlitzky via clamav-users : On 2020-08-21 08:11, Arjen de Korte via clamav-users wrote: Citeren Michael Orlitzky via clamav-users : On 2020-08-21 04:45, Arjen de Korte via clamav-users wrote: It is not clear to me what problem this patch intends to solve (for a systemd

Re: [clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
Citeren Michael Orlitzky via clamav-users : On 2020-08-21 04:45, Arjen de Korte via clamav-users wrote: It is not clear to me what problem this patch intends to solve (for a systemd service it is absolute not required from a security point of view). The PIDFile should be writable by vscan

Re: [clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
Citeren Arjen de Korte via clamav-users : OS: openSUSE Tumbleweed I have found (like others) that the ClamAV 0.103.0-rc service doesn't start. When running the binary in a console, it doesn't daemonize, but keeps running. PID file and socket are created however. That should have read

[clamav-users] ClamAV 0.103.0 release candidate - systemd service start fails

2020-08-21 Thread Arjen de Korte via clamav-users
OS: openSUSE Tumbleweed I have found (like others) that the ClamAV 0.103.0-rc service doesn't start. When running the binary in a console, it doesn't daemonize, but keeps running. PID file and socket are created however. I bisected this problem and found the commit bb12435: Create PID

Re: [clamav-users] [External] Re: [External] ClamAV® blog: ClamAV 0.103.0 release candidate

2020-08-20 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : Hi there, On Wed, 19 Aug 2020, Kevin A. McGrail via clamav-users wrote:  ./configure --prefix=/usr/local/clamav --with-user=defang --with-group=defang --enable-llvm=no --with-openssl=/usr/local/ssl --with-pcre=/usr/local/pcre2 --disable-clamonacc

Re: [clamav-users] [External] ClamAV® blog: ClamAV 0.103.0 release candidate

2020-08-19 Thread Arjen de Korte via clamav-users
Citeren "Micah Snyder (micasnyd) via clamav-users" : Hi Kevin, Do I understand you correctly that clamd is hanging indefinitely? A few things that may help… 1. Lets track this in a Bugzilla ticket: https://bugzilla.clamav.net/enter_bug.cgi?product=ClamAV 2. Can you provide the

Re: [clamav-users] create /var/run/clamav on reboot in Fedora, otherwise Pulseaudio errors occur

2020-08-05 Thread Arjen de Korte via clamav-users
Citeren Robert Kudyba : Using Fedora 31, this has been happening for quite a while. After reboot /var/run/clamav is removed, which is expected. However, wehn ClamAV was installed the user created in /etc/passwd looks like this: clamav:x:985:981::/var/run/clamav:/sbin/nologin So Pulseaudio

Re: [clamav-users] issues with EICAR-test-file

2020-05-10 Thread Arjen de Korte via clamav-users
Citeren Christian : Hi altogether, in order to test clamscan/clamdscan I used the *EICAR-Testfile* provided on https://de.wikipedia.org/wiki/EICAR-Testdatei . I named it /EICAR-Testdatei.txt/. Yet scanning it with either *clamscan* or *clamdscan* gave me different results: - _with

Re: [clamav-users] clamscan vs clamdscan

2020-05-10 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : Hi there, On Sat, 9 May 2020, Paul Kosinski via clamav-users wrote: On our mailserver, we run clamdscan, since mail arrives frequently (!). On a mail server most people would use a milter, e.g. clamav-milter, which is part of the ClamAV package.

Re: [clamav-users] Heuristics.Limits.Exceeded FOUND

2020-04-03 Thread Arjen de Korte via clamav-users
Citeren Kris Deugau : Arjen de Korte via clamav-users wrote: Citeren Paul Kosinski via clamav-users : However, applying clamscan to this file (which was slightly renamed by my download script to be more readable) results in the following output: clamscan --alert-exceeds-max=yes --max

Re: [clamav-users] Heuristics.Limits.Exceeded FOUND

2020-04-03 Thread Arjen de Korte via clamav-users
Citeren Paul Kosinski via clamav-users : I am puzzled (and dismayed) by the following behavior of ClamAV. When I scan some archive files, I often get "Heuristics.Limits.Exceeded FOUND". This makes me wonder about ClamAV's utility in protecting our systems against malware. I'm not talking about

Re: [clamav-users] PrivateMirror set on client machine. Disable cld downloads

2020-03-23 Thread Arjen de Korte via clamav-users
Citeren "Scott A. Wozny via clamav-users" : One caveat with that suggestion is that if you move off of freshclam to do your signature retrieval with wget, you give up the efficiencies of just downloading the first 512 bytes of each DB file to see if it's been updated and, if not, going

Re: [clamav-users] CLAMAV 0.99.2 question about last valid definition

2020-02-26 Thread Arjen de Korte via clamav-users
Citeren 99r c via clamav-users : I am in a situation (just started working here last month) where I have an install of a few RHEL 5.5 machines that are an embedded (and on a non internet connected network) and are scheduled for replacement, the clamav on these machines is 0.99.2 and the

[clamav-users] Your ClamAV installation is OUTDATED!

2020-01-30 Thread Arjen de Korte via clamav-users
Since midnight, freshclam is complaining: Your ClamAV installation is OUTDATED! Local version: 0.102.1 Recommended version: 0.102.2 However, the recommended version is nowhere to be found. Is the new version announced too soon, or was the release stalled somewhere?

Re: [clamav-users] clamav-0.102.x annoying behavior

2019-11-21 Thread Arjen de Korte via clamav-users
Citeren Frans de Boer : On 21-11-2019 21:49, Arjen de Korte via clamav-users wrote: Citeren Frans de Boer : LS, Alas, I get a bit tired: every time we make an update, all the service files are overwritten with the files the clamav team thinks it's the best. So, every time I have to copy

Re: [clamav-users] clamav-0.102.x annoying behavior

2019-11-21 Thread Arjen de Korte via clamav-users
Citeren Frans de Boer : LS, Alas, I get a bit tired: every time we make an update, all the service files are overwritten with the files the clamav team thinks it's the best. So, every time I have to copy my proper/working/correct files over the unwanted updates. Rather annoying.

Re: [clamav-users] clamav-0.102.1 error

2019-11-21 Thread Arjen de Korte via clamav-users
Citeren Frans de Boer : LS, I get the next report (all systems):   /configure: line 30094: auto=yes: command not found Also, check_clamav failed on 2 different systems (openSUSE 15.1). It did not failed on openSUSE Tumbleweed. Can't replicate. See

Re: [clamav-users] Administrivia.

2019-11-09 Thread Arjen de Korte via clamav-users
Citeren "G.W. Haywood via clamav-users" : Hi there, Many people use aliases for mailing list correspondence, so that the bots which scrape list archives for email addresses and then send spam to those addresses get the aliases and not the real addresses. It's a simple matter to permit mail to

Re: [clamav-users] clamav-milter not being built for 0.102.0

2019-11-06 Thread Arjen de Korte via clamav-users
Citeren Yasuhiro KIMURA : Hello Micah, From: "Micah Snyder \(micasnyd\) via clamav-users" Subject: Re: [clamav-users] clamav-milter not being built for 0.102.0 Date: Tue, 5 Nov 2019 18:19:21 + Thanks for reaching out. I’m also CC’ing the binary package maintainers mailing list on