RE: [Clamav-users] User-agent: http://www.clamav.net ?

2006-06-08 Thread Matthew.van.Eerde
it on loaded servers. Default: disabled I can think of any number of reasons why this is a bad idea, Me too. if it is going to follow links, wouldn't it make sense to follow them correctly? Yes, it would. The relevant code is in ./libclamav/mbox.c, for the record. -- Matthew.van.Eerde

[Clamav-users] OT: police state

2006-05-24 Thread Matthew.van.Eerde
of Evil, where Charlton Heston's character says: A policeman's job is only easy in a police state. http://www.imdb.com/title/tt0052311/quotes -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Question About Quarantine

2006-05-17 Thread Matthew.van.Eerde
occasionally tempted to run ClamAV on the quarantine directory prior to archiving, just to make sure that I'm only archiving things that could be useful. But I haven't gone that far yet. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com

[Clamav-users] OOO (was: Question AboutQuarantine)

2006-05-17 Thread Matthew.van.Eerde
, though. Then the necessary notification could be picked up by the sending server, which presumably knows more about who should receive the notification than does the receiving server. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com

RE: [Clamav-users] clamd.log created as root

2006-05-08 Thread Matthew.van.Eerde
Steven Stern wrote: If I change ownership of clamd.log to clamav:clamav, clamav-milter is happy until the logs roll on monday morning. What am I missing? Configure your log rotation utility to chown the files to clamav:clamav. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554

RE: [Clamav-users] Error while loading shared libraries

2006-05-02 Thread Matthew.van.Eerde
Robert Isaac wrote: The libclamav.so.1 files are 777 Danger, Will Robinson! -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] Error while loading shared libraries

2006-05-02 Thread Matthew.van.Eerde
Matthew van Eerde wrote: Robert Isaac wrote: The libclamav.so.1 files are 777 Danger, Will Robinson! Hmmm, so are mine... Ah, I see, libclamav.so.1 is a symbolic link to libclamav.so.1.0.17 ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Version mismatches on supposedly up-to-date system

2006-04-14 Thread Matthew.van.Eerde
? You'll have to ask the package maintainer about that one. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Scanning large mails occupies very large memory

2006-04-05 Thread Matthew.van.Eerde
better to have a known limit with known consequences (REJECT) than an unknown limit with unknown consequences (server crash) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Scanning large mails occupies very large memory

2006-04-05 Thread Matthew.van.Eerde
on the MTAs and high-powered MUAs. But there should still be a line (probably measured in GB, for such a shop) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http

RE: [Clamav-users] Firewall's and freshclam

2006-02-21 Thread Matthew.van.Eerde
Ed Stover wrote: What tcp ports does freshclam use to update the virus database? DNS/UDP (53/udp) and HTTP/TCP (80/tcp) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Phishing detection

2006-02-16 Thread Matthew.van.Eerde
for a particular message content and added to the virus signature database. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] Clamav and qmail-scanner problem?

2006-02-14 Thread Matthew.van.Eerde
when qmail-scanner is invoked. But surely clam*d*scan doesn't use a database at all. Your problem may be cosmetic. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] RE: File Attachment Size Problem

2006-01-30 Thread Matthew.van.Eerde
MIMEDefang. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] OT: American date format(was:[EMAIL PROTECTED])

2006-01-20 Thread Matthew.van.Eerde
pointed out, in the US, half /past/ four is 4:30. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] No ClamAV LogWatch report

2006-01-06 Thread Matthew.van.Eerde
. Some of the things that match *clam* are part of logwatch. Try reinstalling logwatch. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list

RE: [Clamav-users] RE: Report infected mail to the user

2006-01-06 Thread Matthew.van.Eerde
if, instead of reporting to the envelope-sender, they did a WHOIS lookup on the sending IP and emailed the virus notification to the responsible party for the narrowest containing subnet. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com

RE: [Clamav-users] RE: Report infected mail to the user

2006-01-06 Thread Matthew.van.Eerde
Yes, please wikify it for posterity... http://wiki.clamav.net/ -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] clamav-milter sendmail: postmaster notificat ion

2006-01-06 Thread Matthew.van.Eerde
Chuck Swiger wrote: I require my users to zip or tarball attachments before they send them. Heh. I quarantine incoming zip attachments. :) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Phishing - ClamAV and version 0.9

2006-01-06 Thread Matthew.van.Eerde
://wiki.clamav.net/ -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Report infected mail to the user

2006-01-05 Thread Matthew.van.Eerde
yours. :) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Overriding the X-Virus-Scanned header

2005-12-15 Thread Matthew.van.Eerde
the email So I don't ever get any kind of Status header except for X-Virus-Status: Clean -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http

RE: [Clamav-users] Please help with this error...

2005-12-01 Thread Matthew.van.Eerde
that it's really a .zip file. As a workaround, ask the customer to rename the file to have an extension .zip-remove and see if that gets through. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Re: Worm.Sober.U not being recognized

2005-12-01 Thread Matthew.van.Eerde
. That starts another instance of clamd with the unrecognized argument QUIT. The socket commands (QUIT) are not command-line arguments. You have to echo them to the socket. Try sending clamd a kill signal instead. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic

RE: [Clamav-users] Re: Worm.Sober.U not being recognized

2005-12-01 Thread Matthew.van.Eerde
Matthew.van.Eerde wrote: The Disc Shop wrote: [EMAIL PROTECTED] wrote: clamdscan --config-file=/usr/local/etc/clamd.conf abc Hmm... why is there a --config-file switch for clamdscan? I see it's in the man page... does it really work for all options? -- Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] Re: Worm.Sober.U not being recognized

2005-11-30 Thread Matthew.van.Eerde
is detecting the virus, but clamdscan is not? Please confirm. When was the last time you restarted clamd? Perhaps it's not reloading the virus database whenever freshclam downloads a new update. Can you post your freshclam config as well (without blank lines and comments) -- Matthew.van.Eerde

RE: [Clamav-users] Re: Worm.Sober.U not being recognized

2005-11-30 Thread Matthew.van.Eerde
Kill all your freshclam and clamd processes. Put your .pid and socket files in a place that clamd can write. clamd starts as root, but if it needs to SIGHUP, it needs to recreate the .pid files and reinitialize the socket as clamd. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554

RE: [Clamav-users] Re: Worm.Sober.U not being recognized

2005-11-29 Thread Matthew.van.Eerde
accept a --database=/var/db/clamav command-line option. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Exploit IE CVE CAN-2005-1790

2005-11-28 Thread Matthew.van.Eerde
really, REALLY don't want to click on whatever that is. Want to provide some more detail? It's Secunia's top-ranking vulnerability at the moment: http://secunia.com/advisories/15546/ http://secunia.com/ -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] Worm.Sober.U not being recognized

2005-11-21 Thread Matthew.van.Eerde
-mitler (I've never used the milter, so I'm not sure what's necessary) and see if that does it. I've already tried a couple of restarts to no avail. What are your clamd and clamav-milter options? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] freshclam daemon dying

2005-11-16 Thread Matthew.van.Eerde
-- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] clamav-0.87.1 / SunOS 5.8: goes nuts when sent SIGHUP

2005-11-08 Thread Matthew.van.Eerde
nocompress create 640 clamav defang postrotate /bin/kill -HUP `cat /var/run/clamav/freshclam.pid 2 /dev/null` 2 /dev/null || true endscript } -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com

RE: [Clamav-users] clamav-0.87.1 / SunOS 5.8: goes nuts when sentSIGHUP

2005-11-08 Thread Matthew.van.Eerde
Brian C. Hill wrote: wrote: But that must be on a Linux system (I am assuming because you are running logrotate). Yup -- Slackware -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Problem with ArchiveMaxCompressionRatio

2005-11-04 Thread Matthew.van.Eerde
/root/aaa /root/aaa: Oversized.Zip FOUND clamscan doesn't look at clamd.conf IIRC. clamd does. clamdscan relies on clamd... do you have clamd running? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Re: clamav-milter error in logs: no: command notfound

2005-10-24 Thread Matthew.van.Eerde
for no and see what options you get. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Re: clamav-milter error in logs: no:commandnotfound

2005-10-24 Thread Matthew.van.Eerde
-milter -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Re: clamav-milter error in logs: no:commandnotfound

2005-10-24 Thread Matthew.van.Eerde
Matthew.van.Eerde wrote: John Belamaric wrote: Try grepping for no and see what options you get. Hi Matthew, Unfortunately that didn't do it: Maybe it's not in the .conf file, but is instead being passed as a command-line argument. Check these files: /etc/rc.d/init.d/clamav

RE: [Clamav-users] cvd timestamps question

2005-10-19 Thread Matthew.van.Eerde
Joanna Roman wrote: What is the time zone of the timestamps in main.cvd and daily.cvd ? I believe timestamps are stored internally in seconds-since-the-epoch. So whatever your ls -l command says in your time zone, that's the correct time. -- Matthew.van.Eerde (at) hbinc.com

RE: RE : [Clamav-users] Timout problem with clamav and amavisd on bigcompressed file

2005-10-14 Thread Matthew.van.Eerde
and forwarding... Outlook QuoteFix, for example http://home.in.tum.de/~jain/software/outlook-quotefix/ -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net

RE: [Clamav-users] Some basic questions

2005-10-14 Thread Matthew.van.Eerde
mails or wahetever) to postmaster or my linux user everytime it detects a virus in a mail man clamav-milter -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http

RE: [Clamav-users] Issues with ClamAV and RedHat Enterprise 2

2005-09-28 Thread Matthew.van.Eerde
:%{_localstatedir}/clamav/clmilter.socket Note that the -b is short for --bounce. Missed that one. So he has both --bounce and --noreject??? LOL -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] Issues with ClamAV and RedHat Enterprise 2

2005-09-28 Thread Matthew.van.Eerde
system, --quiet wins. So the net effect seems to be that this config should silently absorb viruses - accept, destroy, don't deliver. Or did I miss something else? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software

RE: [Clamav-users] Version 0.87 installed, outdated message claims 0.86.2

2005-09-28 Thread Matthew.van.Eerde
Don Levey wrote: WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.86.2 Recommended version: 0.87 So why am I being told that this is outdated? Any ideas? Have you killed the running clam processes since you upgraded? -- Matthew.van.Eerde

RE: [Clamav-users] Issues with ClamAV and RedHat Enterprise 2

2005-09-28 Thread Matthew.van.Eerde
use the MIMEDefang thread somewhere else (like running a SpamAssassin check, for example.) I occasionally consider writing a Mail::SpamAssassin::Client module to lighten up the MIMEDefang threads, too... just run a few spamd threads and have the MIMEDefang threads share... -- Matthew.van.Eerde

RE: [Clamav-users] Issues with ClamAV and RedHat Enterprise 2

2005-09-27 Thread Matthew.van.Eerde
should ### read the documentation and tweak it as you wish. ... --noreject ... he has it set to absorb viruses (don't reject, don't deliver, don't bounce) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] clamav-milter seems unstable with 0.87

2005-09-23 Thread Matthew.van.Eerde
incoming mail they scan. Maybe that would be useful... you might install one of these archive milters, making sure it appears before clamav-milter in the list of milters... then when a thread goes haywire, check the last few emails in the archive for fishyness. -- Matthew.van.Eerde

RE: [Clamav-users] clamdscan doens't recognize virus

2005-09-22 Thread Matthew.van.Eerde
a fresh install or an upgrade or an uninstall/install? Are you using precisely this release? http://sourceforge.net/project/showfiles.php?group_id=86638release_id=356974 -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software

RE: [Clamav-users] clamav-milter seems unstable with 0.87

2005-09-22 Thread Matthew.van.Eerde
, I may need to downgrade back to 0.86. Have you tried running clamd and using --external on clamav-milter? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http

RE: [Clamav-users] zip files and clamav-milter

2005-09-21 Thread Matthew.van.Eerde
using --external? How does clamav-milter know when new virus definitions are available? I assume freshclam doesn't notify clamav-milter threads. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] zip files and clamav-milter

2005-09-21 Thread Matthew.van.Eerde
important. How/when does clamav-milter find out about virus definition updates? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] suspicious classification resulting in false postives

2005-09-09 Thread Matthew.van.Eerde
action_discard to action_bounce for suspicious characters. That at least takes care of false positives. YMMV. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http

RE: [Clamav-users] suspicious classification resulting in falsepostives

2005-09-09 Thread Matthew.van.Eerde
as suspicious. Bingo... Fortunately, MIMEDefang allows multiple virus scanners. Fortunately, MIMEDefang logs virus detections. Unfortunately, MIMEDefang doesn't include which scanner caught the virus. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] Performance Tuning Clamd?

2005-09-06 Thread Matthew.van.Eerde
for your load as disk I/O is a real bottleneck. Are you doing synchronous syslogging? Try asynchronous (just add a - in the right place in syslog.conf) -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer

RE: [Clamav-users] --max-children

2005-09-06 Thread Matthew.van.Eerde
]; then echo Starting clamav-milter: /usr/local/sbin/clamav-milter -eCfq /var/run/c lamav/milter.sock /usr/local/sbin/clamav-milter -eCfq /var/run/clamav/milter.sock # give it time to start up and let the socket create itself sleep 2 fi } Note -e is --external -- Matthew.van.Eerde

RE: [Clamav-users] --max-children

2005-09-06 Thread Matthew.van.Eerde
, and I like clamav-milter to use the pre-existing pool rather than forming its own. clamav-milter uses /etc/clamd.conf to a certain extent, but has many other options that can only be specified at the command line. man clamav-milter for the gory details. -- Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] AV relay + MX backup question

2005-08-30 Thread Matthew.van.Eerde
. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Sendmail X and clamav-milter

2005-08-30 Thread Matthew.van.Eerde
Thomas Cameron wrote: 2005-08-27 smX-0.0.Beta0.0 has been released. Do you have a plans on adaptation clamav-milter for smX ? What is Sendmail X? Enquiring minds want to know! http://www.sendmail.org/sm-X/ -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic

RE: [Clamav-users] uncompressed zip size of Zero

2005-07-27 Thread Matthew.van.Eerde
viruses by default. If there is an option to turn this on, fine, but this is pushing the envelope a bit too far for me. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift

RE: [Clamav-users] uncompressed zip size of Zero

2005-07-27 Thread Matthew.van.Eerde
- ? 1 - ? 1 - ? Your sig doesn't seem to match the published doc format. What does sigtool -i ./local/empty.zmd say? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi

RE: [Clamav-users] uncompressed zip size of Zero

2005-07-27 Thread Matthew.van.Eerde
q# wrote: Wrong signature format: zmd != ndb Alright - where's the documentation of the zmd database format? Does sigtool --list-sigs | grep Zip.Empty have any output? That should at least verify whether the sig is being loaded. -- Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] clamd PING

2005-07-26 Thread Matthew.van.Eerde
. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] Clamd processes and memory

2005-07-26 Thread Matthew.van.Eerde
(without the -d.) Do not run freshclamd -d through cron or you'll be running multiple daemons and eventually bring your machine to its knees. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k

RE: [Clamav-users] newbie setup question - Solaris 9 + sendmail

2005-07-22 Thread Matthew.van.Eerde
some of these have obvious purposed (graphing or log file processing), are there any of these necessary for me to get up and going in my environment? No. TIA for any pointers or URL's where I can RTFM. www.mimedefang.com www.spamassassin.org www.clamav.net -- Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] Libclamav and zip files

2005-07-21 Thread Matthew.van.Eerde
) Recognize the initial packet of the zip file 2) Accumulate all future packets of that stream 3) Put all the packets together to get the complete zip file 4) Decompress the zip file 5) Scan the decompressed contents -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic

RE: [Clamav-users] Libclamav and zip files

2005-07-21 Thread Matthew.van.Eerde
is really committed to infecting themselves, and astoundingly resourceful. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg

RE: [Clamav-users] WARNING: Local version: 0.86 Recommended version:0.85.1

2005-06-23 Thread Matthew.van.Eerde
, with malicious virus definitions. I'll let everyone imagine the worst-case consequences of that. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga

RE: [Clamav-users] WARNING: Local version: 0.86 Recommendedversion:0.85.1

2005-06-23 Thread Matthew.van.Eerde
this concern. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] ClamAV on Exchange 200x

2005-06-21 Thread Matthew.van.Eerde
access database script There's a version for Exchange 2000 and another for Exchange 5.5 -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg

RE: [Clamav-users] Password protected ZIP's---howto?

2005-06-20 Thread Matthew.van.Eerde
] and Archive::Zip [1] www.mimedefang.com -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http

RE: [Clamav-users] ClamAV on Exchange 200x

2005-06-17 Thread Matthew.van.Eerde
-- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav-users.html

RE: [Clamav-users] How to use clamav-milter?

2005-06-15 Thread Matthew.van.Eerde
-milter thread handling that caused it to time out if it did the work itself. I was forced to start it with --external which passes the work to running clamd daemons. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software

RE: [Clamav-users] odd problem w/clamd

2005-06-10 Thread Matthew.van.Eerde
a problem at all. None of my machines is as high specs as his. Easy, cowboy. When he says that problems are confined to FreeBSD, that does not imply that all FreeBSD installations will have problems. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] odd problem w/clamd

2005-06-10 Thread Matthew.van.Eerde
analizing that big email. Mounting /tmp as a tmpfs file system can be a real performance lifesaver for a busy clamd setup. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print

RE: [Clamav-users] Question about clamd commands

2005-06-07 Thread Matthew.van.Eerde
clamd.sock than it would be to connect to a TCP socket. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg

RE: [Clamav-users] clamdscan vs clamscan - detection

2005-05-31 Thread Matthew.van.Eerde
accomplish all that is asked without having to potentially damage the flow of mail across your machine. Or just use clamscan --debug? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k

RE: [Clamav-users] clamav build for WinNT

2005-05-31 Thread Matthew.van.Eerde
.rp wrote: Is there a build anywhere that will run under NT4 ? This is a good place to start looking: http://www.clamav.net/binary.html#pagestart -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap

RE: [Clamav-users] Re: Virus naming conventions?

2005-05-26 Thread Matthew.van.Eerde
to agree on what to call each virus. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http

[Clamav-users] clamd reload causing mail server to tempfail

2005-05-18 Thread Matthew.van.Eerde
it is configured identically :-?) I'm using both clamav-milter and MIMEDefang (which prints directly to clamd.sock) This behavior is new as of 0.85.1 What could I be doing wrong and how do I fix it? -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] clamd reload causing mail server to tempfail

2005-05-18 Thread Matthew.van.Eerde
NotifyClamd -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] clamd reload causing mail server to tempfail

2005-05-18 Thread Matthew.van.Eerde
Matthew.van.Eerde wrote: Damian Menscher wrote: On Wed, 18 May 2005 [EMAIL PROTECTED] wrote: LibClamAV Warning: Not reloading database until idle - waiting for 2 children Could you tell us how you're running clamav-milter? Specifically, I'd like to know if you're using --external /usr

RE: [Clamav-users] 0.85 0.81.1 tha same troubles with milter

2005-05-17 Thread Matthew.van.Eerde
|| true endscript } I use defang as a generic mail administration group, which is why that group gets read access. -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi

RE: [Clamav-users] sober.p and german adverts?

2005-05-17 Thread Matthew.van.Eerde
aspell thinks that is a word... and probably some spammers do, rofl. It IS a word...just not the one you wanted. swine spellchekers On that note: http://jobsearch.monster.com/jobsearch.asp?q=manger -- Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] DNS server used for dynamic resolution

2005-05-11 Thread Matthew.van.Eerde
BIND: 9.3.1 Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] Re: Exit code with password protected zip file

2005-05-04 Thread Matthew.van.Eerde
tell because I wasn't able to allocate memory and I can't tell because...) You could adopt a policy that yes, password-protected zip files can be assumed to be viruses with the following clamd.conf option: ArchiveBlockEncrypted Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902

RE: [Clamav-users] Re: Exit code with password protected zip file

2005-05-04 Thread Matthew.van.Eerde
, it should never be 2. Matter of opinion. I wish ArchiveBlockEncrypted were the default. Guess it depends on what you use ClamAV for. I guess an additional ArchiveIgnoreEncrypted (return 0) option would make us both happy. Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic

RE: [Clamav-users] problems after .84 upgrade

2005-05-03 Thread Matthew.van.Eerde
the way sockets work. Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list

RE: [Clamav-users] Can phishing be considered one kind of spam ?

2005-04-15 Thread Matthew.van.Eerde
] urban myths [x] (company) will pay you $ for every person you forward this to [x] cute puppies [x] sob stories ... Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg

RE: [Clamav-users] remove scanner serve

2005-04-14 Thread Matthew.van.Eerde
Nigel Horne wrote: On Thursday 14 Apr 2005 01:12, [EMAIL PROTECTED] wrote: You're correct, clamav-milter won't listen on a TCP port, only on a local socket. Wrong. *removes foot from mouth* oops, sorry... Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic

RE: [Clamav-users] remove scanner serve

2005-04-13 Thread Matthew.van.Eerde
machine? Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg, ___ http://lurker.clamav.net/list/clamav

RE: [Clamav-users] New Virus?

2005-03-31 Thread Matthew.van.Eerde
: [Clamav-users] New Virus? Thread-Index: AcU2HfVJlXoUlYzJRuC2osx2VBm8CwABWsIg Looks like you have reason to deploy security by obscurity. FWIW recent versions of Outlook block user access to received attachments of the form .exe .com .bat .pif .scr Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] Report Phishing attacks?

2005-03-22 Thread Matthew.van.Eerde
itself to detecting (and rejecting) threats of the first kind by default. If an option is added to detect and reject threats of the second kind, that can only be a good thing - so long as it is an option. Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc

RE: [Clamav-users] Report Phishing attacks?

2005-03-22 Thread Matthew.van.Eerde
from registering a domain like onlinebanking.example and then sending out - perfectly legitimately - from [EMAIL PROTECTED] Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi

RE: [Clamav-users] Report Phishing attacks?

2005-03-21 Thread Matthew.van.Eerde
a feature request to me... can we have a user.cvd file (in addition to main.cvd and daily.cvd) Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg

RE: [Clamav-users] Report Phishing attacks?

2005-03-21 Thread Matthew.van.Eerde
. You need not to sign the .db file. I presume clamd needs to be HUP'd? Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k/;print}shift Jjhi pcdiwtg Ptga wprztg

RE: [Clamav-users] use of clamav-milter

2005-03-17 Thread Matthew.van.Eerde
in spam scanning a file if it has been identified as a virus. Of the two processes (spam scanning and virus scanning), spam scanning is more resource-intensive (at least the way I do it) - so I virus scan first, and spam-scan second. Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902

RE: [Clamav-users] use of clamav-milter

2005-03-17 Thread Matthew.van.Eerde
with the idea of writing a SpamAssassin::Client module to emulate spamc, but haven't done anything serious with it. I know someone else got a working prototype together. Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software

RE: [Clamav-users] Disabling ScanArchive ?

2005-02-24 Thread Matthew.van.Eerde
Dennis Peterson wrote: Now if we can make people aware of the evils of out-of-office auto-responders... I know! Why isn't there an SMTP code for this? - RCPT TO: [EMAIL PROTECTED] - 2?0 OK, but he's out of the office right now - RSET never mind then Matthew.van.Eerde (at) hbinc.com

RE: [Clamav-users] Worm.Sober.K getting through...

2005-02-24 Thread Matthew.van.Eerde
Tim Howell wrote: Several of my users have received the virus classified by ClamAV as Worm.Sober.K today... How should I go about tracking this down? Find a particular infected message and check the logs for errors or warnings around the time the message went through Matthew.van.Eerde

RE: [Clamav-users] EICAR signature update: second attempt

2005-02-23 Thread Matthew.van.Eerde
ahellary wrote: i STILL cannont get either version .81 or .82 to detect any virus Try 0.83? its slackware I've got 0.83 running OK on slackware... but I had to upgrade zlib... do you get any make errors? Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business

RE: [Clamav-users] Re: clamscan and blackhole errors

2005-02-23 Thread Matthew.van.Eerde
Keith Patton wrote: ahellary wrote: ... on our qmail... Look at http://www.mimedefang.org But MIMEDefang is a sendmail-only milter... Matthew.van.Eerde (at) hbinc.com 805.964.4554 x902 Hispanic Business Inc./HireDiversity.com Software Engineer perl -emap{y/a-z/l-za-k

  1   2   >