Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Rémy DODIN via clamav-users

Now, I give a try on clamwin ! 



You have the latest version of ClamWin Free Antivirus (0.99.4). 
ClamWin Free Antivirus is a free software project 


So, it is outdated too ! 
No windows recent build too ! 


No windows, no ArcaOS... only linux based system seems to be updated 
Is ClamAV now linux only program ? 


" 

ClamAV update process started at Sat Mar 13 19:35:44 2021 
main.cld is up to date (version: 59, sigs: 4564902, f-level: 60, builder: 
sigmgr) 
WARNING: getfile: Unknown response from database.clamav.net (IP: 104.16.218.84) 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: getfile: Unknown response from database.clamav.net (IP: 104.16.219.84) 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: Can't download daily.cvd from database.clamav.net 
Trying again in 5 secs... 
ClamAV update process started at Sat Mar 13 19:35:51 2021 
main.cld is up to date (version: 59, sigs: 4564902, f-level: 60, builder: 
sigmgr) 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: Can't download daily.cvd from database.clamav.net 
Trying again in 5 secs... 
ClamAV update process started at Sat Mar 13 19:35:58 2021 
main.cld is up to date (version: 59, sigs: 4564902, f-level: 60, builder: 
sigmgr) 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
WARNING: getpatch: Can't download daily-26080.cdiff from database.clamav.net 
ERROR: Can't download daily.cvd from database.clamav.net 
Giving up on database.clamav.net... 
Update failed. Your network may be down or none of the mirrors listed in 
o:\utilis~1\temp\clamwinportabletemp\tmpgtif1i is working. Check 
http://www.clamav.net/doc/mirrors-faq.html for possible reasons. 

-- 
Completed 
-- 

" 






"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 
- Mail original -----

De: "Rémy DODIN via clamav-users"  
À: "ClamAV users ML"  
Cc: "Rémy DODIN"  
Envoyé: Samedi 13 Mars 2021 14:30:31 
Objet: Re: [clamav-users] Restriction of downloads 



I'll contact Synology support team. 


Regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 
- Mail original -

De: "Eero Volotinen"  
À: "ClamAV users ML"  
Envoyé: Samedi 13 Mars 2021 14:19:22 
Objet: Re: [clamav-users] Restriction of downloads 


Synology. 


Eero 


On Sat, Mar 13, 2021 at 3:09 PM Rémy DODIN via clamav-users < 
clamav-users@lists.clamav.net > wrote: 





My synology Clamav is at "Upgraded ClamAV engine to 0.102.3" 
As it is written here and my packets are at latest update level. 

https://www.synology.com/fr-fr/releaseNote/AntiVirus?model=DS713%2B 



But virus signature is unabled to be refreshed as I wrote it ! 
It worked until last refresh from 03/06/21 and then, high CPU and storage 
utilisation and no refresh. 
It looks like it is going into a loop trying to get virus database updates 
(If it goes into a loop, then the refresh tool may have issue ! and may be you 
expected abuse due to high freshclam or virus database update is into a loop 
due incorrect process ? 


If a loop exist, who's the culprit ? (I'm not a developper and just end user 
with no skills) 
synology ? or Clamav ? 

I just run again database update option and after more than 4 minutes, it was 
always runing and I have to force a stop to not have it running 24/24h. 
Consuming a lot of CPU, energy (not eco friendly) - It is acting like a virus 
trying to kill a system, strange ! 



Very strange 



Regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, me

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Rémy DODIN via clamav-users

I'll contact Synology support team. 


Regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 
- Mail original -

De: "Eero Volotinen"  
À: "ClamAV users ML"  
Envoyé: Samedi 13 Mars 2021 14:19:22 
Objet: Re: [clamav-users] Restriction of downloads 


Synology. 


Eero 


On Sat, Mar 13, 2021 at 3:09 PM Rémy DODIN via clamav-users < 
clamav-users@lists.clamav.net > wrote: 





My synology Clamav is at "Upgraded ClamAV engine to 0.102.3" 
As it is written here and my packets are at latest update level. 

https://www.synology.com/fr-fr/releaseNote/AntiVirus?model=DS713%2B 



But virus signature is unabled to be refreshed as I wrote it ! 
It worked until last refresh from 03/06/21 and then, high CPU and storage 
utilisation and no refresh. 
It looks like it is going into a loop trying to get virus database updates 
(If it goes into a loop, then the refresh tool may have issue ! and may be you 
expected abuse due to high freshclam or virus database update is into a loop 
due incorrect process ? 


If a loop exist, who's the culprit ? (I'm not a developper and just end user 
with no skills) 
synology ? or Clamav ? 

I just run again database update option and after more than 4 minutes, it was 
always runing and I have to force a stop to not have it running 24/24h. 
Consuming a lot of CPU, energy (not eco friendly) - It is acting like a virus 
trying to kill a system, strange ! 



Very strange 



Regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 


De: "Joel Esler (jesler) via clamav-users" < clamav-users@lists.clamav.net > 
À: "ClamAV users ML" < clamav-users@lists.clamav.net > 
Cc: "Joel Esler (jesler)" < jes...@cisco.com > 
Envoyé: Samedi 13 Mars 2021 13:47:08 
Objet: Re: [clamav-users] Restriction of downloads 

Team— 


The qnap and synology issues are a result of the EOL of <0.100. Not as a result 
of the abusive downloaders. Two separate issues. 


Our EOL policy that has been in place is “current version with all minor 
patches and one back with all minor patches”. This has been our policy for 
about 8–10 years. Our current version is 0.103.1, which means according to our 
EOL policy, we should allow .103, and .102. Everything below that we should 
block. 


It is becoming more and more necessary to enforce these cut off points because 
of many reasons. Load to the mirror network being one. So, .100, and .101 will 
continue to be supported for a bit, but soon, we’re going to have to cut those 
off too. 


The vast majority of ClamAV users are on 0.102.4. The outliners are people that 
haven’t upgraded to a latest version should start upgrading to get ahead of the 
curve. 




Sent from my  iPhone 



On Mar 13, 2021, at 05:52, Matus UHLAR - fantomas < uh...@fantomas.sk > wrote: 













I just found that my "antivirus essentiel" installed package 












provided by Synology is unable to update virus definition file since 












03/06/2021 ! 









On 13/03/2021 00:47, G.W. Haywood via clamav-users wrote: 






Then should you not be talking to Synology? 





On 13.03.21 11:16, Paul Smith via clamav-users wrote: 


Maybe Synology and QNAP, etc could run private mirrors for their devices which 
they don't provide up-to-date Freshclam for... 



QNAP runs freshclam. checked now with my 419P+: 

ClamAV update process started at Sat Mar 13 12:47:36 2021 
WARNING: getpatch: Can't download main-55.cdiff from database.clamav.net 
ERROR: getpatch: Can't download main-55.cdiff from database.clamav.net 
WARNING: Incremental update failed, trying to download main.cvd 
ERROR: Can't download main.cvd from database.clamav.net 
Giving up on database.clamav.net... 
Update failed. Your network may be down or none of the mirrors listed in 
/etc/config/freshclam.conf is working. Check 
http://www.clamav.net/doc/mirrors-faq.html for possible reasons. 


However, many of QNAP devices have obsolete clamav version: 

[~] # freshclam -V 
ClamAV 0.99.3

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Rémy DODIN via clamav-users

My synology Clamav is at "Upgraded ClamAV engine to 0.102.3" 
As it is written here and my packets are at latest update level. 

https://www.synology.com/fr-fr/releaseNote/AntiVirus?model=DS713%2B 



But virus signature is unabled to be refreshed as I wrote it ! 
It worked until last refresh from 03/06/21 and then, high CPU and storage 
utilisation and no refresh. 
It looks like it is going into a loop trying to get virus database updates 
(If it goes into a loop, then the refresh tool may have issue ! and may be you 
expected abuse due to high freshclam or virus database update is into a loop 
due incorrect process ? 


If a loop exist, who's the culprit ? (I'm not a developper and just end user 
with no skills) 
synology ? or Clamav ? 

I just run again database update option and after more than 4 minutes, it was 
always runing and I have to force a stop to not have it running 24/24h. 
Consuming a lot of CPU, energy (not eco friendly) - It is acting like a virus 
trying to kill a system, strange ! 



Very strange 



Regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 
- Mail original -

De: "Joel Esler (jesler) via clamav-users"  
À: "ClamAV users ML"  
Cc: "Joel Esler (jesler)"  
Envoyé: Samedi 13 Mars 2021 13:47:08 
Objet: Re: [clamav-users] Restriction of downloads 

Team— 


The qnap and synology issues are a result of the EOL of <0.100. Not as a result 
of the abusive downloaders. Two separate issues. 


Our EOL policy that has been in place is “current version with all minor 
patches and one back with all minor patches”. This has been our policy for 
about 8–10 years. Our current version is 0.103.1, which means according to our 
EOL policy, we should allow .103, and .102. Everything below that we should 
block. 


It is becoming more and more necessary to enforce these cut off points because 
of many reasons. Load to the mirror network being one. So, .100, and .101 will 
continue to be supported for a bit, but soon, we’re going to have to cut those 
off too. 


The vast majority of ClamAV users are on 0.102.4. The outliners are people that 
haven’t upgraded to a latest version should start upgrading to get ahead of the 
curve. 




Sent from my  iPhone 



On Mar 13, 2021, at 05:52, Matus UHLAR - fantomas  wrote: 













I just found that my "antivirus essentiel" installed package 












provided by Synology is unable to update virus definition file since 












03/06/2021 ! 









On 13/03/2021 00:47, G.W. Haywood via clamav-users wrote: 






Then should you not be talking to Synology? 





On 13.03.21 11:16, Paul Smith via clamav-users wrote: 


Maybe Synology and QNAP, etc could run private mirrors for their devices which 
they don't provide up-to-date Freshclam for... 



QNAP runs freshclam. checked now with my 419P+: 

ClamAV update process started at Sat Mar 13 12:47:36 2021 
WARNING: getpatch: Can't download main-55.cdiff from database.clamav.net 
ERROR: getpatch: Can't download main-55.cdiff from database.clamav.net 
WARNING: Incremental update failed, trying to download main.cvd 
ERROR: Can't download main.cvd from database.clamav.net 
Giving up on database.clamav.net... 
Update failed. Your network may be down or none of the mirrors listed in 
/etc/config/freshclam.conf is working. Check 
http://www.clamav.net/doc/mirrors-faq.html for possible reasons. 


However, many of QNAP devices have obsolete clamav version: 

[~] # freshclam -V 
ClamAV 0.99.3/17260/Wed May 22 12:40:22 2013 


-- 
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ 
Warning: I wish NOT to receive e-mail advertising to this address. 
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 
Microsoft dick is soft to do no harm 

___ 

clamav-users mailing list 
clamav-users@lists.clamav.net 
https://lists.clamav.net/mailman/listinfo/clamav-users 


Help us build a comprehensive ClamAV guide: 
https://github.com/vrtadmin/clamav-faq 

http://www.clamav.net/contact.html#ml 




___ 

clamav-users mailing list 
clamav-users@lists.clamav.net 
https://lists.clamav.net/mailman/listinfo/clamav-users 


Help us build a comprehensive ClamAV guide: 
https://github.com/vrtadmin/clamav-faq 

http://www.clamav.net/contact.html#ml 


___

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a 

Re: [clamav-users] Restriction of downloads

2021-03-12 Thread Rémy DODIN via clamav-users

Hi, 


I just found that my "antivirus essentiel" installed package provided by 
Synology is unable to update virus definition file since 03/06/2021 ! 
This package is build on ClamAV 


There are lot of products no more working yet ! 
Qnap, Synology etc 

Under ArcaOS etc 





Before blocking updates, I think that user had to be informed about changes a 
few month before 
This is a top severity unsecure issue. 

(putting so many people out of new viruses protection ! - All do not have 
skills to correct Like, I do not have needed skills) 


It would be nice providing a quick solution for those with any skills. 
I'm fully out of protection yet (unable to implement cvdupdate ! no skills for 
this) 



Best regards 
Rémy 




"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 
- Mail original -

De: "Joel Esler (jesler) via clamav-users"  
À: "ClamAV users ML"  
Cc: "Joel Esler (jesler)"  
Envoyé: Vendredi 12 Mars 2021 00:17:21 
Objet: Re: [clamav-users] Restriction of downloads 

You’ll have to work with qnap. We can’t update qnap. 


Sent from my  iPhone 



On Mar 11, 2021, at 13:39, Harv Azad via clamav-users 
 wrote: 








I’m a simple QNAP 509 (x2) user and having read the emails I’m a bit confused 
on how to resolve the issue of definitions not updating automatically. 

Having worked out yesterday that I could update manually I downloaded the 
latest cvd file and updated both my servers but then when I look today, I cant 
see the file download links anymore. 
I can see that there is some mention of Freshclam. Happy to use this but could 
someone please clarify if this is something that sits on my qnap or on my pc? 
Can I then use this to manually download the definition files to update my 
qnaps manually. 

Sorry if these are basic questions. 

Kind Regards 
Harv Azad 

Sent from Mail for Windows 10 

___ 

clamav-users mailing list 
clamav-users@lists.clamav.net 
https://lists.clamav.net/mailman/listinfo/clamav-users 


Help us build a comprehensive ClamAV guide: 
https://github.com/vrtadmin/clamav-faq 

http://www.clamav.net/contact.html#ml 




___ 

clamav-users mailing list 
clamav-users@lists.clamav.net 
https://lists.clamav.net/mailman/listinfo/clamav-users 


Help us build a comprehensive ClamAV guide: 
https://github.com/vrtadmin/clamav-faq 

http://www.clamav.net/contact.html#ml 


___

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml


[clamav-users] freshclam getfile failed - and clamav links Cloudfare 1020 error.

2021-03-10 Thread Rémy DODIN via clamav-users



Hi, 


Since several weeks (may be since clamav migrated to cloudflare), Freshclam is 
no more able to get updates and fails not been able to get any databases (main, 
daily etc..) - It stopped to work sudently making me think it could be a 
cloudflare issue. 

- Environment ArcaOS 

- latest available build 0.99 
- Trying to go to www.clamav.net, I have a cloudflare error message 1020 
showing my ip@ ! 
( doing the same under a windows session using the same ip@, it works ) 


Any idea how to resolve this ? 
Is the OS not recognized by Cloudflare ? (ArcaOS - same as OS/2) 


Regards 
R.D 





"Ce message et toutes ses pièces jointes sont établis à l'intention exclusive 
de son/ses destinataire(s) et sont confidentiels. Si vous recevez ce message 
par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. 
Toute utilisation de ce message et/ou de son contenu par une personne autre 
qu'un destinataire, et toute diffusion ou publication ultérieure du contenu de 
ce message, en totalité ou en partie, est interdite sauf autorisation préalable 
et écrite de l'émetteur" 


___

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml