Re: [clamav-users] using older clients to download from internal clam proxy

2021-12-09 Thread Joel Esler (jesler) via clamav-users
100 is end of life. 101 and 102 will be EOL on Jan 3. You need to be on 103 or higher. The rest will be dead in January. — Sent from my  iPhone > On Dec 9, 2021, at 15:25, novpenguincne via clamav-users > wrote: > > Thanks for the feedback and advice. I understand what you are

Re: [clamav-users] using older clients to download from internal clam proxy

2021-12-02 Thread Joel Esler (jesler) via clamav-users
enough to accept the new definition files but still old enough to > install on a SystemV-based o/s? > > James > > Sent with ProtonMail Secure Email. > > ‐‐‐ Original Message ‐‐‐ > >> On Thursday, December 2nd, 2021 at 10:49 AM, Joel Esler (jesler) >>

Re: [clamav-users] using older clients to download from internal clam proxy

2021-12-02 Thread Joel Esler (jesler) via clamav-users
James, Thanks for your email. ClamAV definitions won’t even work on those older versions anymore. The Flevel for the main.cvd and daily.cvd are now set higher than that, so those systems shouldn’t be able to load the newer definitions. — Sent from my  iPad > On Dec 2, 2021, at 11:08,

Re: [clamav-users] ClamAV detects XMR-Stak as malicious. Is this a false positive?

2021-11-19 Thread Joel Esler (jesler) via clamav-users
Al is right. If you don’t want to detect it ignore it. Using the ignore functions. — Sent from my  iPad On Nov 19, 2021, at 03:49, Al Varnell via clamav-users wrote:  I suspect that it's because there are several instances of malicious software that install xmr-stak unknowingly to the

Re: [clamav-users] Nonsensical noreplies from ClamAV team

2021-11-18 Thread Joel Esler (jesler) via clamav-users
We’re looking into this. — Sent from my  iPhone On Nov 18, 2021, at 14:56, Maarten Broekman via clamav-users wrote:  "If you provided a description that suggests otherwise..." is a past tense conditional referring to the form submission. That phrase is the equivalent to this longer "If

Re: [clamav-users] "403: Forbidden" from website

2021-11-18 Thread Joel Esler (jesler) via clamav-users
: I’m not sure what the file is. The URL in which I’m interested is http://www.clamav.net/downloads/. I tried to add index.html to the URL but that didn’t work but when wget retrieves just http://www.clamav.net/downloads/, the filename it uses is index.html. From: Joel Esler (jesler) mailto:jes...@cis

Re: [clamav-users] "403: Forbidden" from website

2021-11-18 Thread Joel Esler (jesler) via clamav-users
What files are you attempting to download? On Nov 18, 2021, at 09:33, John Pfuntner -X (jpfuntne - EASI LLC at Cisco) via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: I’m seeing errors trying to access the website programmatically: $ wget http://www.clamav.net/downloads URL

Re: [clamav-users] clamav DOA

2021-11-18 Thread Joel Esler (jesler) via clamav-users
101 should be fine. Try deleting your mirrors.dat file and see what happens? — Sent from my  iPad > On Nov 18, 2021, at 07:32, Cody Allen wrote: > >  its prepackaged on a mailcleaner appliance, not using any standard > locations for the binaries or configs and no updates available from

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-17 Thread Joel Esler (jesler) via clamav-users
It has been fixed. — Sent from my  iPad > On Nov 17, 2021, at 14:36, Paul Kosinski via clamav-users > wrote: > > On Mon, 15 Nov 2021 13:23:49 +0000 > "Joel Esler \(jesler\) via clamav-users" > wrote: > >> On Nov 14, 2021, at 19:11, Yasuhiro Kimur

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-15 Thread Joel Esler (jesler) via clamav-users
As a follow up to this thread, this has been fixed. — Sent from my  iPad > On Nov 15, 2021, at 10:09, Yasuhiro Kimura wrote: > > From: "Joel Esler (jesler)" > Subject: Re: [clamav-users] Fail to download source archive with 403 forbitten > Date: Mon, 15 Nov 2021 1

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-15 Thread Joel Esler (jesler) via clamav-users
On Nov 15, 2021, at 09:30, Joel Esler (jesler) via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: On Nov 15, 2021, at 08:39, Yasuhiro Kimura mailto:y...@utahime.org>> wrote: From: "Joel Esler \(jesler\) via clamav-users" mailto:clamav-users@lists.cl

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-15 Thread Joel Esler (jesler) via clamav-users
On Nov 15, 2021, at 08:39, Yasuhiro Kimura mailto:y...@utahime.org>> wrote: From: "Joel Esler \(jesler\) via clamav-users" mailto:clamav-users@lists.clamav.net>> Subject: Re: [clamav-users] Fail to download source archive with 403 forbitten Date: Mon, 15 Nov 2021 13:23:4

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-15 Thread Joel Esler (jesler) via clamav-users
On Nov 14, 2021, at 19:11, Yasuhiro Kimura mailto:y...@utahime.org>> wrote: These results means server checks User-Agent header of HTTP request and returns 403 forbitten if the value doesn't look like that of web browser. Then is it intened change? Yes, and it has been this way for over two

Re: [clamav-users] stuck at "Starting Clam AntiVirus Daemon" when rebooting.

2021-11-14 Thread Joel Esler (jesler) via clamav-users
Windows 7 and newer includes windows 7. Also, is your problem separate from the original post about CentOS? If so, please start a new thread, don’t hijack someone else’s. — Sent from my  iPad > On Nov 14, 2021, at 18:03, RW Jones via clamav-users > wrote: > >  > I'm on a Win-DOS 10 box

Re: [clamav-users] Advertising Options / Sponsored Content Options on clamav.net

2021-11-12 Thread Joel Esler (jesler) via clamav-users
No. — Sent from my  iPad > On Nov 11, 2021, at 09:31, Doug Whittemore wrote: > >  > Hi, > > Just wanted to follow up on my advertising request? > > We’re interested in publishing content on your website, and I am keen to get > pricing/options etc. > > Please revert back with prices to

[clamav-users] ClamAV® blog: ClamAV 0.103.4 and 0.104.1 patch releases

2021-11-03 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2021/11/clamav-01034-and-01041-patch-releases.html ClamAV 0.103.4 and 0.104.1 patch releases ClamAV 0.103.4 LTS and 0.104.1 patch versions are out now. Both of these can be found on clamav.net/downloads, with 0.104.1 as the main release

Re: [clamav-users] Missing Mac OS .pkg installer

2021-10-29 Thread Joel Esler (jesler) via clamav-users
https://www.clamav.net/downloads Scroll down to “alternate versions of ClamAV” and click on macOS. — Sent from my  iPhone On Oct 28, 2021, at 13:40, Vaughn A. Hart wrote:  Hi Team Clamav, In your documentsation you state that there is a pkg installer for Mac OS that supports Intel and M1

Re: [clamav-users] Clam updates failing

2021-10-23 Thread Joel Esler (jesler) via clamav-users
> On Oct 23, 2021, at 11:49, Paul Kosinski wrote: > > On Fri, 22 Oct 2021 18:47:01 +0000 > "Joel Esler (jesler)" wrote: > >>>> On Oct 22, 2021, at 14:16, Paul Kosinski via clamav-users >>>> wrote: >>> >>> On Fri, 22

Re: [clamav-users] Clam updates failing

2021-10-22 Thread Joel Esler (jesler) via clamav-users
> On Oct 22, 2021, at 14:16, Paul Kosinski via clamav-users > wrote: > > On Fri, 22 Oct 2021 13:27:46 +0000 > "Joel Esler \(jesler\) via clamav-users" > wrote: > >>> On Oct 21, 2021, at 18:55, Kenneth Porter wrote: >>> >>> On

Re: [clamav-users] Clam updates failing

2021-10-22 Thread Joel Esler (jesler) via clamav-users
> On Oct 21, 2021, at 18:55, Kenneth Porter wrote: > > On 10/21/2021 10:14 AM, Paul Kosinski via clamav-users wrote: >> I've never seen a DNS age warning, but that might be because, for several >> years now, I only run freshclam when the DNS TXT record (which I check >> hourly) says there

Re: [clamav-users] Rate limit for signature

2021-10-07 Thread Joel Esler (jesler) via clamav-users
Mike I am the correct person. Updating requires the use of either cvdupdate (for distribution to internal systems) or FreshClam. Versions 0.103.3 or higher. — Sent from my  iPad > On Oct 5, 2021, at 20:49, Mike JJ Chen wrote: > >  > Hello Team, > > Could you help suggest appropriate

Re: [clamav-users] Rate limited

2021-10-05 Thread Joel Esler (jesler) via clamav-users
On Oct 5, 2021, at 4:41 AM, Adam Baliko via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: I have a private VLAN here, but my public IP is granted by my ISP. I'm assuming this is a dynamic IP but I have no idea how often that changes (maybe I should start noting the IPs which are

Re: [clamav-users] ClamAV is not respecting Phishing* settings.

2021-09-22 Thread Joel Esler (jesler) via clamav-users
I am sure someone will respond about your particular issue, but are you saying they are false positives? — Sent from my  iPhone > On Sep 22, 2021, at 22:04, Jim Popovitch via clamav-users > wrote: > > ClamAV is not respecting Phishing* settings. > > clamd.conf: > ... >

Re: [clamav-users] QNAP Antivirus Updates

2021-09-21 Thread Joel Esler (jesler) via clamav-users
And… there’s your answer. Thank you all! I think this thread is dead. > On Sep 21, 2021, at 2:42 PM, Liston, Daniel (DLISTON) via clamav-users > wrote: > > I have already forgotten the point, but I did do some DNS > queries from our datacenters in LON, TYO, and NYC. All > reported the

Re: [clamav-users] QNAP Antivirus Updates

2021-09-21 Thread Joel Esler (jesler) via clamav-users
Cool  — Sent from my  iPhone > On Sep 20, 2021, at 20:17, Paul Kosinski wrote: > > On Mon, 20 Sep 2021 17:17:34 +0000 > "Joel Esler (jesler)" wrote: > >>>> On Sep 20, 2021, at 13:08, Paul Kosinski via clamav-users >>>> wrote: >&

Re: [clamav-users] QNAP Antivirus Updates

2021-09-20 Thread Joel Esler (jesler) via clamav-users
> On Sep 20, 2021, at 13:08, Paul Kosinski via clamav-users > wrote: > > These two IPs are Anycast addresses, and have been unchanged for well over 2 > years. (Anycast addresses don't have to change even if the physical servers > change, that's their point!) They are: > > 104.16.218.84 >

Re: [clamav-users] Virus DB updates?

2021-09-19 Thread Joel Esler (jesler) via clamav-users
Following up, looks like this has been fixed. A new daily should ship tonight. — Sent from my  iPhone > On Sep 19, 2021, at 17:31, G.W. Haywood via clamav-users > wrote: > > Hi there, > >> On Sun, 19 Sep 2021, Paul Kosinski via clamav-users wrote: >> >> I haven't seen any virus

Re: [clamav-users] Virus DB updates?

2021-09-19 Thread Joel Esler (jesler) via clamav-users
A new main was built that day and pushed. The daily may not have been re-enabled. I’ll double check. — Sent from my  iPhone > On Sep 19, 2021, at 17:31, G.W. Haywood via clamav-users > wrote: > > Hi there, > >> On Sun, 19 Sep 2021, Paul Kosinski via clamav-users wrote: >> >> I

Re: [clamav-users] IP List for Virus Definition Domain

2021-09-15 Thread Joel Esler (jesler) via clamav-users
It’s dynamic baed on your location in the world. Do a dns lookup for database.clamav.net from your location and you should get your answer. > On Sep 15, 2021, at 12:52 PM, James Freeman wrote: > > ALCON, > > Is there a list of IPs that the ClamAV domain used to

Re: [clamav-users] error code 429

2021-09-05 Thread Joel Esler (jesler) via clamav-users
Now? — Sent from my  iPad > On Sep 5, 2021, at 12:51, Paul Kosinski wrote: > > On Sun, 5 Sep 2021 02:45:25 +0000 > "Joel Esler \(jesler\) via clamav-users" > wrote: > >> We are experimenting with a feature that we’ve been working with Cloudflare

Re: [clamav-users] Clamav download problems

2021-09-05 Thread Joel Esler (jesler) via clamav-users
is up-to-date (version: 333, sigs: 92, f-level: 63, > builde > r: awillia2) > > Regards Paul > >> On 05/09/2021 16:08, Joel Esler (jesler) via clamav-users wrote: >> This is useful. Thank you. >> >> Each host should have a different rate limit under the new system

Re: [clamav-users] error code 429

2021-09-05 Thread Joel Esler (jesler) via clamav-users
l. > > I'm not complaining - you've clearly had a lot of problems with the CDN being > abused (intentionally or otherwise) and need to try these things. Just trying > to give you whatever information might be useful :) > > Thanks, > Mark. > > > Joel Esler jesle

Re: [clamav-users] error code 429

2021-09-05 Thread Joel Esler (jesler) via clamav-users
This is useful. Thank you. Each host should have a different rate limit under the new system (I turned it back off last night, which is why everyone got everything). Right now, the rate limit is “per IP”. So, if you have several Hosts behind a NAT, so you’ll get blocked. The new system, you

Re: [clamav-users] error code 429

2021-09-04 Thread Joel Esler (jesler) via clamav-users
We are experimenting with a feature that we’ve been working with Cloudflare on, trying to isolate violators on a per host basis for the newest versions of ClamAV, instead of IP. — Sent from my  iPhone > On Sep 4, 2021, at 18:52, Jim Popovitch via clamav-users > wrote: > > On Sat,

[clamav-users] ClamAV® blog: Changes to ClamAV end-of-life policy and a new Long Term Support policy

2021-09-03 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2021/09/changes-to-clamav-end-of-life-policy.html > > > Changes to ClamAV end-of-life policy and a new Long Term Support policy > > Today, we're announcing changes to the ClamAV End-of-Life

[clamav-users] ClamAV® blog: ClamAV 0.104.0 released

2021-09-03 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2021/09/clamav-01040-released.html > > > ClamAV 0.104.0 released > > ClamAV 0.104.0 is available as an official release as of today. > > We are also announcing a new Long Term Support (LTS) program today

Re: [clamav-users] Please unsubscribe me from all emails

2021-08-31 Thread Joel Esler (jesler) via clamav-users
Thank you for writing in. Go to this URL to change user options or unsubscribe: https://lists.ClamAV.net/mailman/listinfo/ClamAV-users or by sending an email to clamav-users-le...@lists.clamav.net Thanks! > On Aug 31, 2021, at 10:17 AM, Cândido Sales Gomes via clamav-users > wrote: > > Hi,

Re: [clamav-users] Authenticity token element not found

2021-08-25 Thread Joel Esler (jesler) via clamav-users
I think this was fixed in 103.3 — Sent from my  iPhone > On Aug 25, 2021, at 04:26, Philipp Ewald wrote: > >  >> > clamsubmit -e "philipp.ewald[at]digionline.de" -n > "29668235ea685b3e84309b9585dc71e7" -N "DigiOnline" > > Authenticity token element not found. > > This is my

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Joel Esler (jesler) via clamav-users
I could worry about the .0001% of the time* — Sent from my  iPhone > On Aug 22, 2021, at 13:48, Joel Esler (jesler) wrote: > > I could work about the .0001% or the time that github is inaccessible in > a given time, or I could save maintaining the docs i

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Joel Esler (jesler) via clamav-users
22 Aug 2021, Arjen de Korte via clamav-users wrote: >> Citeren "G.W. Haywood via clamav-users" : >>> On Sun, 22 Aug 2021, Joel Esler (jesler) via clamav-users wrote: >>>> I’m a fan of the thought of removing the user manual completely from >>>> the d

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Joel Esler (jesler) via clamav-users
I’m a fan of the thought of removing the user manual completely from the downloaded packages and including a link to docs.ClamAV.net. Since that’s more dynamic. — Sent from my  iPhone > On Aug 22, 2021, at 04:22, G.W. Haywood via clamav-users > wrote: > > Hi there, > >> On Sun, 22

[clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-19 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2021/08/clamav-01040-second-release-candidate.html ClamAV 0.104.0 Second Release Candidate is here! Today we are publishing a second release candidate for 0.104.0. Please help us verify that

Re: [clamav-users] database updates blocked

2021-08-17 Thread Joel Esler (jesler) via clamav-users
t; 13:26:24.653 5 EXTFILTER(CGPClamAV) inp(104): * WARNING: Download failed >> (77) * WARNING: Message: Problem with the SSL CA cert (path? access rights?) >> >> 13:26:24.653 5 EXTFILTER(CGPClamAV) inp(078): * WARNING: Can't download >> daily.cvd from https://database.clamav.ne

Re: [clamav-users] database updates blocked

2021-08-17 Thread Joel Esler (jesler) via clamav-users
Curl is not authorized to be used to download updates. Please use Freshclam or cvdupdate to download updates. — Sent from my  iPhone On Aug 17, 2021, at 08:33, Jona Tallieu wrote:  Dear all, Since a few days, our database updates are blocked: HTTP 403 (forbidden) > Cloudflare Error 1020:

Re: [clamav-users] Local web server

2021-08-12 Thread Joel Esler (jesler) via clamav-users
What’s the question? Can you use ClamAV in a commercial environment? Sure. As long as you adhere to the GPLv2, you’re good to go. But yes, Ged is right, if you have more than say, two or three hosts behind a NAT address? Set up a private mirror. > On Aug 12, 2021, at 2:15 PM, Johnson,

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-30 Thread Joel Esler (jesler) via clamav-users
> On Jul 30, 2021, at 14:41, Paul Kosinski via clamav-users > wrote: > > (I don't see exactly how a LTS would have helped with the bandwidth issue, > but I suppose it wouldn't have made it any more disruptive.) 103.2 and 103.3 are much more respectful to bandwidth than any past version.

Re: [clamav-users] ClamAVR blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-29 Thread Joel Esler (jesler) via clamav-users
> On Jul 28, 2021, at 6:09 PM, Rick Cooper wrote: > >> On Jul 28, 2021, at 7:17 AM, Rick Cooper > > wrote: >> >> total disregard for the user base, not so much as a poll or query on the >> lists, enjoy your new cutting edge toys >> >> Corporate BS rears it's ugly

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-29 Thread Joel Esler (jesler) via clamav-users
To be extremely specific, the LTS version would start with 0.103.3. So that would be the base version we’d support for LTS. > On Jul 29, 2021, at 10:06 AM, Andrew C Aitchison via clamav-users > wrote: > > > Executive Summary: > An LTS release every two years, supported for three, starting

Re: [clamav-users] Freshclam - can't apply latest patch 26246

2021-07-28 Thread Joel Esler (jesler) via clamav-users
> On Jul 28, 2021, at 12:30 PM, Andrew C Aitchison via clamav-users > wrote: > > This sounds about right. > A lot of signatures in daily 26231 were removed from daily 26232 or 26233 > and added to main 60. There was a glitch and main 61 was created to flush > caches on some of the mirrors. >

Re: [clamav-users] can not download updates

2021-07-28 Thread Joel Esler (jesler) via clamav-users
> On Jul 28, 2021, at 4:04 AM, Matus UHLAR - fantomas wrote: > > On 27.07.21 18:51, fxkl47BF via clamav-users wrote: >> for many years it's worked fine with timeout set at 30 seconds > > for many years it worked with people fetching via wget/curl, but it does not > apply now. > So true. >

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-28 Thread Joel Esler (jesler) via clamav-users
> On Jul 28, 2021, at 7:17 AM, Rick Cooper wrote: > > total disregard for the user base, not so much as a poll or query on the > lists, enjoy your new cutting edge toys > > Corporate BS rears it's ugly head again, First snort, then centos and now > clamav. I think this is unfair. This is

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-28 Thread Joel Esler (jesler) via clamav-users
We are planning on making LTS versions for distros again. — Sent from my  iPad > On Jul 28, 2021, at 07:45, Andrew C Aitchison via clamav-users > wrote: > > On Wed, 28 Jul 2021, Rick Cooper wrote: > >> total disregard for the user base, not so much as a poll or query on the >> lists, >

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-27 Thread Joel Esler (jesler) via clamav-users
> On Jul 27, 2021, at 11:27 AM, Paul Kosinski via clamav-users > wrote: > > On Mon, 26 Jul 2021 11:35:29 -0400 > "Rick Cooper" mailto:rcoo...@dwford.com>> wrote: > >> And what, exactly, is the reason for moving to cmake? I am sure you know >> it's going to be problematic for thousands of

Re: [clamav-users] can not download updates

2021-07-27 Thread Joel Esler (jesler) via clamav-users
‐ Original Message ‐‐‐ > > On Tuesday, July 27th, 2021 at 9:43 AM, Joel Esler (jesler) <mailto:jes...@cisco.com>> wrote: > >>> On Jul 27, 2021, at 10:34 AM, fxkl47BF via clamav-users >>> wrote: >>> >>> ‐‐‐ Original Message ‐‐‐

Re: [clamav-users] Cooldown much too long

2021-07-27 Thread Joel Esler (jesler) via clamav-users
> On Jul 26, 2021, at 6:02 PM, Markus Egg via clamav-users > wrote: > > I had that problem with "Incremental update failed, trying to download > main.cvd" also in > version 0.103.2 of clamav on Ubuntu 18.04 . > > So I waited and updated with the hope that 0.103.3 would solve it. > But still

Re: [clamav-users] can not download updates

2021-07-27 Thread Joel Esler (jesler) via clamav-users
> On Jul 27, 2021, at 10:34 AM, fxkl47BF via clamav-users > wrote: > > ‐‐‐ Original Message ‐‐‐ > On Tuesday, July 27th, 2021 at 9:29 AM, Joel Esler (jesler) <mailto:jes...@cisco.com>> wrote: > >>> On Jul 27, 2021, at 10:22 AM, f

Re: [clamav-users] can not download updates

2021-07-27 Thread Joel Esler (jesler) via clamav-users
> On Jul 27, 2021, at 10:22 AM, fxkl47BF via clamav-users > wrote: > > On Tuesday, July 27th, 2021 at 8:56 AM, Matus UHLAR - fantomas > mailto:uh...@fantomas.sk>> wrote: > >> On 27.07.21 12:47, fxkl47BF via clamav-users wrote: >>> for a couple of weeks i've not been able to download

[clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-22 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2021/07/clamav-01040-release-candidate-is-here.html > > > ClamAV 0.104.0 Release Candidate is here! > > We are pleased to announce the ClamAV 0.104.0 release candidate >

Re: [clamav-users] problems with freshclam: Incremental update failed

2021-07-15 Thread Joel Esler (jesler) via clamav-users
Christian, The below is correct. We published a new main.cvd and daily.cvd yesterday, and in order to make your FreshClam instance force download the new files, we have to publish a “blank” file, so that FreshClam sees it as an error, and then fails over to pick up the full file. From that

Re: [clamav-users] New Main & Daily CVD's are incoming

2021-07-13 Thread Joel Esler (jesler) via clamav-users
chanism for performing daily incremental updates via cdiff > files rather than downloading the whole cvd. > > Are you providing cdiff files for both main.cvd and daily.cvd or just the cvd > files? > > Regards > Mark > >> On 13 Jul 2021, at 3:55 pm, Joel Esler

Re: [clamav-users] New Main & Daily CVD's are incoming

2021-07-13 Thread Joel Esler (jesler) via clamav-users
> On Jul 13, 2021, at 18:08, Paul Kosinski via clamav-users > wrote: > > On Tue, 13 Jul 2021 14:05:53 +0000 > "Joel Esler \(jesler\) via clamav-users" > wrote: > >> Tomorrow, Wednesday July 14th, we are planning on publishing a brand new >> ma

Re: [clamav-users] New Main & Daily CVD's are incoming

2021-07-13 Thread Joel Esler (jesler) via clamav-users
daily.cvd or just the > new cvd files in their entirety? I seem to remember processing the cdiff > files caused a lot of problems for people the last time main.cvd was updated. > > Mark > >> On 13 Jul 2021, at 3:05 pm, Joel Esler (jesler) via clamav-users >>

[clamav-users] New Main & Daily CVD's are incoming

2021-07-13 Thread Joel Esler (jesler) via clamav-users
Tomorrow, Wednesday July 14th, we are planning on publishing a brand new main.cvd and daily.cvd, as we do periodically to move more of the long term signatures into the main.cvd and make the daily.cvd smaller again. This will have an impact on your downloads of these files (as every ClamAV

Re: [clamav-users] How do I get the last update to 103-3 installed on stretch?

2021-07-07 Thread Joel Esler (jesler) via clamav-users
Freshclam keeps your definitions up to date, the engine is very much dependent on the OS. > On Jul 6, 2021, at 6:18 AM, G.W. Haywood via clamav-users > wrote: > > Hi there, > > On Tue, 6 Jul 2021, Gene Heskett via clamav-users wrote: > >> How do I get the last update to 103-3 installed on

Re: [clamav-users] Not able to communicate on port 443(https) when running freshclam

2021-07-06 Thread Joel Esler (jesler) via clamav-users
That appears to be a private mirror. You should check with the administrator of your private mirror. — Sent from my  iPhone On Jul 6, 2021, at 18:31, Lopez, Carmelo via clamav-users wrote:  I am trying to communicate over port 443 to download freshclam database from the clamav mirror

Re: [clamav-users] Scanning PDF for phishing links

2021-07-01 Thread Joel Esler (jesler) via clamav-users
> On Jul 1, 2021, at 8:25 AM, Matus UHLAR - fantomas wrote: > > On 30.06.21 20:41, Joel Esler (jesler) via clamav-users wrote: >> Yes. I was just addressing everyone > > I have used to forward spam to spamcop, maybe I should start again? > > I'm thinking about phis

Re: [clamav-users] Scanning PDF for phishing links

2021-06-30 Thread Joel Esler (jesler) via clamav-users
h to phishtank (among > others). But it's low volume, just from my wife and my's accounts. > > Sent from my iPad > > -Al- > >>> On Jun 29, 2021, at 12:48, Joel Esler (jesler) via clamav-users >>> wrote: >>> >> How many of you are present me

Re: [clamav-users] Scanning PDF for phishing links

2021-06-29 Thread Joel Esler (jesler) via clamav-users
Awesome — Sent from my  iPad > On Jun 29, 2021, at 18:04, G.W. Haywood via clamav-users > wrote: > > Hi there, > >> On Tue, 29 Jun 2021, Joel Esler (jesler) via clamav-users wrote: >> >> How many of you are present members of either phishtank.com or >&

[clamav-users] ClamAV® blog: ClamAV EOL of 0.100.x versions

2021-06-29 Thread Joel Esler (jesler) via clamav-users
 https://blog.clamav.net/2021/06/clamav-eol-of-0100x-versions.html Effective Oct. 29, 2021, ClamAV 0.100.0 (and all patch versions) will no longer be supported in accordance with ClamAV's EOL policy. End of life (EOL) for ClamAV means:

Re: [clamav-users] Scanning PDF for phishing links

2021-06-29 Thread Joel Esler (jesler) via clamav-users
How many of you are present members of either phishtank.com or spamcop.net? Both of which are ran by Talos, and both of which feed the same intel system that ClamAV can read from? -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group https://www.talosintelligence.com |

Re: [clamav-users] question about a malware submission

2021-06-23 Thread Joel Esler (jesler) via clamav-users
You should submit the suspected malware here: https://www.clamav.net/reports/malware — Sent from my  iPhone On Jun 22, 2021, at 22:01, vze1amckv--- via clamav-users wrote: Hello, I recently submitted a suspicious file via the ClamAV website submission form, and got a response back

[clamav-users] ClamAV® blog: ClamAV 0.103.3 patch release

2021-06-21 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2021/06/clamav-01033-patch-release.html > > > ClamAV 0.103.3 patch release > > ClamAV 0.103.3 is out now. Users can head over to clamav.net/downloads > to download

[clamav-users] ClamAV moves to Discord!

2021-06-15 Thread Joel Esler (jesler) via clamav-users
ClamAV (‪@clamav‬) 6/15/21, 14:23 Since Freenode has decidedly driven off the proverbial cliff, we’ve moved to Discord for our chats: discord.gg/DAW9qWqFzt Join us! We realize

Re: [clamav-users] KACE false positive

2021-06-11 Thread Joel Esler (jesler) via clamav-users
Douglas, Thank you for your email. Here is a good place to file false positives: https://www.clamav.net/reports/fp for future reference. -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group https://www.talosintelligence.com |

Re: [clamav-users] Running ClamAV for production workloads

2021-06-08 Thread Joel Esler (jesler) via clamav-users
If you are setting up lots of machines, make sure you set up a private mirror using cvdupdate first for all of your machines to pull updates from. Have a script/plan for upgrading ClamAV. Super important to keep the engine up to date. Have a plan for what you are going to do when it detects

Re: [clamav-users] since nearly a week unable to update signatures using freshclam ...

2021-06-08 Thread Joel Esler (jesler) via clamav-users
The problem is your installation is not identifying itself with the server and is blocked. Please see my previous email. > On Jun 8, 2021, at 12:48 PM, Walter H. via clamav-users > wrote: > > On 08.06.2021 14:57, Richard via clamav-users wrote: >> >>> Date: Tuesday, June 08, 2021 08:00:16

Re: [clamav-users] since nearly a week unable to update signatures using freshclam ...

2021-06-08 Thread Joel Esler (jesler) via clamav-users
Do you have the uuid library installed on your machine? > On Jun 8, 2021, at 2:00 AM, Walter H. via clamav-users > wrote: > > I'm using an old CentOS 6, not migrated to something newer > > On 06.06.2021 20:04, Walter H. via clamav-users wrote: >> # freshclam >> ClamAV update process started

Re: [clamav-users] since nearly a week unable to update signatures using freshclam ...

2021-06-08 Thread Joel Esler (jesler) via clamav-users
Definitely need to compile. — Sent from my  iPad > On Jun 8, 2021, at 08:57, Richard via clamav-users > wrote: > > > >> Date: Tuesday, June 08, 2021 08:00:16 +0200 >> From: "Walter H. >> >> I'm using an old CentOS 6, not migrated to something newer >> >>> On 06.06.2021 20:04, Walter

Re: [clamav-users] Clam AV Cost and support for enterprise

2021-06-07 Thread Joel Esler (jesler) via clamav-users
There’s no cost for use in the Enterprise. There is no support offering for ClamAV other than these mailing lists. Sent from my  iPhone On Jun 7, 2021, at 16:30, Karthik Iyer via clamav-users wrote:  Hi , We would like to use ClamAV for scanning files in our blob storage and would like

Re: [clamav-users] since nearly a week unable to update signatures using freshclam ...

2021-06-07 Thread Joel Esler (jesler) via clamav-users
What operating system are you using? Sent from my  iPhone > On Jun 6, 2021, at 14:06, Walter H. via clamav-users > wrote: > > # freshclam > ClamAV update process started at Sun Jun 6 19:58:06 2021 > Connecting via proxy > main.cld is up to date (version: 59, sigs: 4564902, f-level: 60,

Re: [clamav-users] ClamWin maintainers?

2021-06-06 Thread Joel Esler (jesler) via clamav-users
Win > missed the rest of the actual 0.103.2 changes, so in reality it's 0.103.1. > > I'll put in a ticket on the ClamWin repo. > >> -Original Message- >> From: clamav-users On Behalf Of >> Joel Esler (jesler) via clamav-users >> Sent: Saturday, June 5, 2021

[clamav-users] ClamWin maintainers?

2021-06-05 Thread Joel Esler (jesler) via clamav-users
I tried to register an account on the ClamWin forums, but I don’t see where to create a new account anywhere. I can see where to login, and see where to reset my password. But I don’t have one, and I don’t see a place to create one. That being said. It seems that ClamWin users have been

Re: [clamav-users] To unblock ip addresses for updating clamAV database/definations.

2021-06-03 Thread Joel Esler (jesler) via clamav-users
Hello Satwant, Moving off list. I’m going to need more info than the IPs. What error are you receiving? -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group https://www.talosintelligence.com | https://www.snort.org | https://www.clamav.net On May 27, 2021, at 5:18 PM,

Re: [clamav-users] ClamAV 0.103.0 takes longer

2021-05-21 Thread Joel Esler (jesler) via clamav-users
Also, upgrading to the current version is smarter. 0.103.2 Sent from my  iPhone > On May 21, 2021, at 08:45, Uskokovic, Sinisa via clamav-users > wrote: > > Hi Ged, > > Thank you for your answer, it is good enough for my dilemma. > > Best, > Sinisa > > -Original Message- >

Re: [clamav-users] Fwd: ClamAV®

2021-05-08 Thread Joel Esler (jesler) via clamav-users
No, this is the public git repository. Unless I am misunderstanding what you’re saying. Sent from my  iPhone On May 8, 2021, at 03:38, Frans de Boer wrote:  On 06/05/2021 01:19, ClamAV® blog wrote: "clamav-devel" GitHub repository name change to

[clamav-users] Update on rate limits and downloading

2021-05-06 Thread Joel Esler (jesler) via clamav-users
Overall — we’re doing much better. We’ve reduced the amount of bandwidth we’re serving by 4x, so we’ve made significant progress. However, we still have over 700 individual systems downloading the full daily.cvd over 200x a day. (This should be once a day, if that.) If you are not using

Re: [clamav-users] Request for guidelines to connect freshclam to Squid proxy

2021-04-30 Thread Joel Esler (jesler) via clamav-users
If the firewall administrator is that way about AV updates, how are they with YouTube? On Apr 30, 2021, at 12:43 PM, Dave Warren via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: A firewall's job is to regulate unwanted/undesired traffic and to enforce policy as defined by the

Re: [clamav-users] cdn :/

2021-04-28 Thread Joel Esler (jesler) via clamav-users
> On Apr 28, 2021, at 12:10 PM, Benny Pedersen wrote: > > On 2021-04-28 17:56, Joel Esler (jesler) wrote: >> I don’t think that’s a solution. > > https scales only if makeing private mirrors :/ > > design of torrents is ther more users the faster speeds all get

Re: [clamav-users] cdn :/

2021-04-28 Thread Joel Esler (jesler) via clamav-users
I don’t think that’s a solution. > On Apr 28, 2021, at 9:21 AM, Benny Pedersen via clamav-users > wrote: > > On 2021-04-28 14:42, Eero Volotinen wrote: > >> Please upgrade to supported version? > > i have that on gentoo, problem is fidxed now, finaly, how can this take so > long without

Re: [clamav-users] Can't download daily-25402.cdiff from db.local.clamav.net

2021-04-28 Thread Joel Esler (jesler) via clamav-users
Please upgrade to 103.2, as the error messages are more specific. Please change your Database settings to fetch from database.clamav.net instead of “db.local.clamav.net”. Daily-25402 is very out of date. On Apr 28, 2021, at 11:43 AM,

Re: [clamav-users] Problema antivirus su Nas QNAP

2021-04-26 Thread Joel Esler (jesler) via clamav-users
Hello Federico, Thank you for your email. As a result of events documented in places here and here, we’ve been forced to take emergency measures to

Re: [clamav-users] ClamAV(R) blog: Are you still attempting to download safebrowsing.cvd?

2021-04-22 Thread Joel Esler (jesler) via clamav-users
hursday, April 8, 2021 5:40 AM > To: clamav-users@lists.clamav.net<mailto:clamav-users@lists.clamav.net> > Subject: Re: [clamav-users] ClamAV® blog: Are you still attempting to > download safebrowsing.cvd? > > >Dne středa 7. dubna 2021 19:41:34 CEST, Joel Esler (jesler) v

Re: [clamav-users] Help, we are still seeing issues

2021-04-18 Thread Joel Esler (jesler) via clamav-users
Correct. Sent from my  iPhone > On Apr 18, 2021, at 13:55, Paul Kosinski via clamav-users > wrote: > > You're comparing daily.CLD with main.CVD: as I understand it, CVDs are > compressed, CLDs aren't. > > >> On Sat, 17 Apr 2021 21:15:29 +0200 (CEST) >> "Robert M. Stockmann via

[clamav-users] Help, we are still seeing issues

2021-04-17 Thread Joel Esler (jesler) via clamav-users
Please take a few moments to check your ClamAV freshclam installations. Are you removing your mirrors.dat file after every run of Freshclam or cvdupdate? We are seeing a few IPs, who have upgraded to 103.2 still downloading the entire daily.cvd and main.cvd every update. I am thinking this is

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-14 Thread Joel Esler (jesler) via clamav-users
me idea that the new key can be trusted > and was not put up by a malicous webmaster - possibly of a spoof website. > > Thanks, > > On Wed, 7 Apr 2021, Joel Esler (jesler) via clamav-users wrote: > >> We’ll look into that for a future update. >> >> Sent from

Re: [clamav-users] clamav on rhel 6.7 x32

2021-04-13 Thread Joel Esler (jesler) via clamav-users
I wouldn’t install something that old. I would go ahead and move on. Sent from my  iPhone On Apr 13, 2021, at 18:29, Eero Volotinen wrote:  Hi, I think that installing following files will fix your problem.

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-10 Thread Joel Esler (jesler) via clamav-users
Thanks for pointing that out. We’ve corrected it with mitre, but obviously, we can’t correct the news.md for now. — Sent from my  iPad > On Apr 10, 2021, at 08:14, Sergey wrote: > > On Wednesday 07 April 2021, Joel Esler (jesler) via clamav-users wrote: > >> CVE-2021

Re: [clamav-users] Error 429 when updating database

2021-04-10 Thread Joel Esler (jesler) via clamav-users
This. — Sent from my  iPad > On Apr 10, 2021, at 09:15, Gary R. Schmidt wrote: > > On 10/04/2021 22:59, Matus UHLAR - fantomas wrote: > [SNIP] >> it could help if we provided proper reason to upgrade tho. > Isn't, "It's security software", sufficient? > >Cheers, >GaryB-) >

Re: [clamav-users] freshclam issues

2021-04-09 Thread Joel Esler (jesler) via clamav-users
Absolutely correct Sent from my  iPhone > On Apr 9, 2021, at 10:07, Kris Deugau wrote: > > Wayne Florence via clamav-users wrote: >> Hello, >> I have recently updated my 4 ClamAV private mirrors to >> version 0.103.0 to fix issues downloading the cvd files. >>

Re: [clamav-users] Error 429 when updating database

2021-04-08 Thread Joel Esler (jesler) via clamav-users
Feel free if you have the ability to do so. We’re poking in all directions already. Sent from my  iPhone > On Apr 8, 2021, at 17:34, Andrew C Aitchison wrote: > >  >> On Thu, 8 Apr 2021, Joel Esler (jesler) via clamav-users wrote: >> Still, 102.4 should wor

  1   2   3   4   5   6   7   8   9   10   >