Re: [clamav-users] clamsubmit error

2018-05-11 Thread Joel Esler (jesler) via clamav-users
--- Begin Message --- We may be able to provide you a better way to do this, if you have a massive amount? > On May 11, 2018, at 9:20 AM, Arnaud Jacques > wrote: > > Hello Jesler, > > >> Is that you sending us all those submissions?! Fantastic amount! > > Yes

Re: [clamav-users] clamsubmit error code 500

2018-05-15 Thread Joel Esler (jesler) via clamav-users
--- Begin Message --- One of the backend systems that handles the submissions was on the fritz. I kicked it. Should be okay now. -- Joel Esler Sr. Manager Open Source, Design, Web, and Education Talos Group http://www.talosintelligence.com On May 15, 2018, at 10:16 AM, Arnaud Jacques via

Re: [clamav-users] Mirrors not responding?

2018-05-18 Thread Joel Esler (jesler) via clamav-users
--- Begin Message --- db.gb was overlooked in the move of db.uk to our CDN for freshclam. We just moved db.gb over to our CDN. Problem should clear itself up shortly. On May 18, 2018, at 10:45 AM, Brian Morrison via clamav-users

[clamav-users] Test Message

2018-05-18 Thread Joel Esler (jesler) via clamav-users
--- Begin Message --- I made some alterations to this clamav-users list. Hopefully that stops the errors that people seem to be having? -- Joel Esler Sr. Manager Open Source, Design, Web, and Education Talos Group http://www.talosintelligence.com --- End Message ---

Re: [clamav-users] ClamAV 0.101.2 announcement?

2019-03-29 Thread Joel Esler (jesler) via clamav-users
This was my fault. Thanks JR. > On Mar 27, 2019, at 10:17 AM, J.R. via clamav-users > wrote: > > I saw 0.101.2 was released yesterday (3/26/2019) but I can't find an > announcement anywhere? > > Anything noteworthy on this release? > > ___ > >

Re: [clamav-users] Are signatures for Windows only?

2019-03-25 Thread Joel Esler (jesler) via clamav-users
ts for > many reasons, not least its extensibility! > > Graeme > > ________________ > From: clamav-users on behalf of Joel > Esler (jesler) via clamav-users > Sent: 25 March 2019 19:36 > To: ClamAV users ML > Cc: Joel Esler (jesler); G.W. Haywood > Subject: Re: [clamav-users] Are signatu

Re: [clamav-users] Are signatures for Windows only?

2019-03-25 Thread Joel Esler (jesler) via clamav-users
Our signature is cover all platforms. Sent from my Apple Watch On Mar 25, 2019, at 08:13, J.R. via clamav-users wrote: > I keep thinking about this from time to time, but keep forgetting to > post before I get sidetracked doing something else... > > Are the ClamAV default signature files

Re: [clamav-users] Are signatures for Windows only?

2019-03-25 Thread Joel Esler (jesler) via clamav-users
Our signatures cover all platforms. Sorry, can’t type on watch. :) Sent from my  iPad > On Mar 25, 2019, at 08:20, Joel Esler (jesler) via clamav-users > wrote: > > Our signature is cover all platforms. > > Sent from my Apple Watch > >> On Mar 25, 2019, at 0

Re: [clamav-users] Updating multiple servers

2019-04-04 Thread Joel Esler (jesler) via clamav-users
You can run a local mirror. That might be a good alternative. Sent from my  iPhone > On Apr 4, 2019, at 21:03, Tim Hawkins wrote: > > We have a large number of services running inside kubernetes that need to > have access to clamav, given the sheer number, i dont want to have to run >

Re: [clamav-users] Scan very slow

2019-04-05 Thread Joel Esler (jesler) via clamav-users
> On Apr 5, 2019, at 09:13, Mark Allan via clamav-users > wrote: > > Also CC'ing Micah directly as the mailing list would appear to be offline (at > least lists.clamav.net isn't responding to http requests anyway May want to try https. smime.p7s Description: S/MIME cryptographic signature

Re: [clamav-users] Clamav for educational institutions ?

2019-04-05 Thread Joel Esler (jesler) via clamav-users
That’s the content on the website. ClamAV, the software, is governed by the GPLv2 and other associates licenses as indicated by the LICENSE file contained therein. Sent from my  iPhone > On Apr 5, 2019, at 17:18, J.R. via clamav-users > wrote: > > At the bottom of the page on the

Re: [clamav-users] Clamav for educational institutions ?

2019-04-05 Thread Joel Esler (jesler) via clamav-users
Correct. Which is why we recommend people compile from source for full functionality. Sent from my  iPhone > On Apr 5, 2019, at 20:12, Scott Kitterman via clamav-users > wrote: > > The unrar stuff is still free to use. > > Due to modification restrictions Debian splits it off into the

Re: [clamav-users] Clamav for educational institutions ?

2019-04-05 Thread Joel Esler (jesler) via clamav-users
Sorry if I implied otherwise. I meant Fedora and their difficulties with unrar. I am a big supporter of your Scott, this you know. Sent from my  iPad > On Apr 5, 2019, at 20:53, Scott Kitterman via clamav-users > wrote: > > On a Debian system with non-free enabled, it only takes "apt

Re: [clamav-users] Scan very slow

2019-04-07 Thread Joel Esler (jesler) via clamav-users
Let us take a look at separating them. Sent from my  iPhone > On Apr 7, 2019, at 14:03, Steve Basford > wrote: > >> On 7 April 2019 17:25:56 Arnaud Jacques wrote: >> >> >> ... and one day I created a *huge* ign2 file and it crashed clamd. Ign2 >> files may not be appropriate to ignore

Re: [clamav-users] Are signatures for Windows only?

2019-03-25 Thread Joel Esler (jesler) via clamav-users
Actually, from what we understand, ClamAV is mostly used to scan email. Sent from my  iPhone > On Mar 25, 2019, at 12:22, G.W. Haywood via clamav-users > wrote: > > Although we share files with Windows platforms we really > only use ClamAV to scan mail. I guess we're as untypical of a

[clamav-users] Freshclam / mirror updates

2019-02-28 Thread Joel Esler (jesler) via clamav-users
Yesterday we made some updates to our CDN that distributes our CVD / CLD / CDIFF files. These changes should result in a faster and more reliable download of these files. Please let me know if you see any issues positive or negative! Thanks! -- Joel Esler Manager, Communities Division Cisco

Re: [clamav-users] Eingangsbestätigung IT-Service

2019-02-20 Thread Joel Esler (jesler) via clamav-users
Removed from list. Sent from my  iPhone > On Feb 20, 2019, at 18:12, IT-Service Theatergemeinde Köln > wrote: > > Vielen Dank für Ihre Nachricht. Sie ist bei uns ordnungsgemäß eingegegangen > und wird so schnell wie möglich bearbeitet. > > Mit freundlichen Grüßen > > Ihr IT-Service der

Re: [clamav-users] Testing

2019-02-26 Thread Joel Esler (jesler) via clamav-users
This should be corrected now. -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com > On Feb 20, 2019, at 5:19 PM, Benny Pedersen wrote: > > Joel Esler (jesler) skrev den 2019-02-20 23:14: >> Testing! > > DKIM and DMARC still fails > > no

Re: [clamav-users] Testing

2019-02-20 Thread Joel Esler (jesler) via clamav-users
We are working on this currently. Sent from my  iPhone > On Feb 20, 2019, at 18:05, Benny Pedersen via clamav-users > wrote: > > Scott Kitterman skrev den 2019-02-20 23:34: > >> I'm not sure why anyone expects anything different. > > you are not on maillist with original senders get dmarc

Re: [clamav-users] Mailman web UI for ClamAV currently inaccessible

2019-03-16 Thread Joel Esler (jesler) via clamav-users
Thank you. Sent from my  iPhone On Mar 14, 2019, at 11:40, Ralph Seichter via clamav-users wrote: >> https://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users returns >> "403 Forbidden". > > I should probably mention that the above URL is sent to subscribers in > the 'Welcome to the

Re: [clamav-users] Database updated over unencrypted connection?

2019-03-17 Thread Joel Esler (jesler) via clamav-users
As Micah said, when we roll out the new version of freshclam that supports https, this will be a done deal. Technically, https on the cdn is available now. Freshclam just doesn’t know how to use it. We want people to freshclam. As the way it functions does so in a way that reduces load on

Re: [clamav-users] Slow reload

2019-03-20 Thread Joel Esler (jesler) via clamav-users
All these times, I would imagine, would be based on the amount of CPU and RAM, even disk read speed, available to the machine loading. So these times are relative. Sent from my  iPhone > On Mar 20, 2019, at 07:48, Steve Basford > wrote: > >> On 2019-03-19 14:35, Bowie Bailey wrote: >>

Re: [clamav-users] ClamAV reputation rating

2019-06-24 Thread Joel Esler (jesler) via clamav-users
No. But can you share an example? And what you’d like to do? Sent from my  iPhone > On Jun 23, 2019, at 23:59, Epicon Elysium via clamav-users > wrote: > > Hi, > > Hoping someone could help with the info I'm looking for. > > Does ClamAV support in enabling the reputation rating? Seems I

Re: [clamav-users] ClamAV Info

2019-05-22 Thread Joel Esler (jesler) via clamav-users
It can. –move will do it. -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com From: clamav-users on behalf of Christopher Do - IQ-C via clamav-users Reply-To: ClamAV users ML Date: Wednesday, May 22, 2019 at 10:52 AM To: ClamAV users

Re: [clamav-users] 403 on clamav-virusdb webpage

2019-05-19 Thread Joel Esler (jesler) via clamav-users
Nope. Just going to the wrong server. https://lists.clamav.net is where everything is at. From: clamav-users on behalf of Al Varnell via clamav-users Sent: Thursday, May 16, 2019 8:35 PM To: ClamAV users ML Cc: Al Varnell Subject: Re: [clamav-users] 403 on

Re: [clamav-users] how to verify if a malware signature is in DB & adding hash

2019-05-05 Thread Joel Esler (jesler) via clamav-users
Run clamscan against the file? Or if you want to see what is published each release, you should subscribe to the clamav-virusdb list. Sent from my  iPad > On May 5, 2019, at 19:40, Sunhux G via clamav-users > wrote: > > Hi > > How can I check if a a specific malware (by providing a

Re: [clamav-users] ClamAV reputation rating

2019-06-27 Thread Joel Esler (jesler) via clamav-users
The short answer is "No". ClamAV does not do reputation ratings, unless you are talking about a scale of not malicious, heuristic, PUA, and full on malicious. But there is not a reputation system, no. > On Jun 26, 2019, at 7:25 PM, Epicon Elysium via clamav-users > wrote: > > Thank you

Re: [clamav-users] Update Failure

2019-04-23 Thread Joel Esler (jesler) via clamav-users
We should probably remove that "official-mirror-faq" link from freshclam. There are no "mirrors" anymore. :) -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com On Apr 22, 2019, at 5:43 PM, Michael Newman via clamav-users

Re: [clamav-users] reg clamav un-Authenticated Command Exception Vulnerablity

2019-04-22 Thread Joel Esler (jesler) via clamav-users
What CVE are you referring to? > On Apr 18, 2019, at 2:18 PM, Manasa Rupireddy via clamav-users > wrote: > > Hi All, > > I have installed latest version of ClamAV which is 0.101.2 version,but i was > still facing the clamav un-Authenticated Command Exception Vulnerablity. > > Could anyone

Re: [clamav-users] Packaging ClamAV

2019-08-13 Thread Joel Esler (jesler) via clamav-users
> On Aug 13, 2019, at 7:46 AM, Tuomo Soini wrote: > > On Mon, 12 Aug 2019 15:37:47 + > Graeme Fowler via clamav-users > wrote: > >> On 12/08/2019, 16:21, "Nick Howitt" > > wrote: >>> >>> Then you can't start clamd on

Re: [clamav-users] clamsubmit error

2019-08-13 Thread Joel Esler (jesler) via clamav-users
102.0-beta seems to be working correctly, haven't established why exactly. Jerry, can you replicate? > On Aug 13, 2019, at 9:06 AM, Arnaud Jacques > wrote: > > Hello Jerry, > > It works now for me (clamsubmit compiled from 0.102.0-beta sources). > It seems older version does not work

Re: [clamav-users] Update Frequency (15 min or 10 mins)

2019-08-13 Thread Joel Esler (jesler) via clamav-users
And to further answer your question, at present, we are only updating the daily.cvd daily. > On Aug 13, 2019, at 8:23 AM, Reio Remma via clamav-users > wrote: > > On 13/08/2019 15:17, Manna, Mohammed via clamav-users wrote: >> Hello, >> >> From the docs – it says that the most frequent

Re: [clamav-users] Packaging ClamAV

2019-08-12 Thread Joel Esler (jesler) via clamav-users
I would suggest not packaging them at all, and they should be downloaded from the update servers the first time the update is ran. > On Aug 12, 2019, at 9:47 AM, Nick Howitt wrote: > > On 12/08/2019 13:25, J.R. via clamav-users wrote: >> main.cvd rarely changes (last update was Jan 2018), it

Re: [clamav-users] clamsubmit error

2019-08-12 Thread Joel Esler (jesler) via clamav-users
av.net/presigned. > Unable to continue submission. > > Where does this message come from ? Communication between client and server ? > Datas submitted ? Server side error ? > > > > Le 09/08/2019 à 07:53, Joel Esler (jesler) via clamav-users a écrit : >> We’re looking in

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Joel Esler (jesler) via clamav-users
> On Jul 31, 2019, at 11:04 AM, Henrik K wrote: > > On Wed, Jul 31, 2019 at 02:49:33PM +0000, Joel Esler (jesler) via > clamav-users wrote: >> >> The only problem with the local mirrors, from our point of view are a couple >> things: >> >> 1. I do

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-31 Thread Joel Esler (jesler) via clamav-users
> On Jul 31, 2019, at 9:52 AM, J.R. via clamav-users > wrote: > >> Then, when we had trouble with Cloudflare's BOS server often being out >> of sync (for CVDs) with the DNS TXT record, I removed it. Now, I am >> dismayed that I have to give our file server a bit of Internet access so >> that

Re: [clamav-users] ClamAV: Local Private Mirror

2019-08-02 Thread Joel Esler (jesler) via clamav-users
Inline below: > On Aug 1, 2019, at 11:33 PM, J.R. via clamav-users > wrote: > >> I think that's the intended purpose of the local private mirror in this case. >> > > I realize that, but I believe in that person's case back the he was > doing a basic web server to re-distributed the full .cvd

Re: [clamav-users] Creating basic signature files info missing?

2019-08-02 Thread Joel Esler (jesler) via clamav-users
I believe it still works, but yes, you shouldn't use it. > On Aug 2, 2019, at 3:51 PM, J.R. via clamav-users > wrote: > > When browsing the page on creating signatures for clamav, I couldn't > find info on the *.db format > > https://www.clamav.net/documents/creating-signatures-for-clamav >

Re: [clamav-users] Packaging ClamAV

2019-08-12 Thread Joel Esler (jesler) via clamav-users
Probably need to kick off freshclam as part of the install. Sent from my  iPhone > On Aug 12, 2019, at 17:00, Scott Kitterman via clamav-users > wrote: > > On Monday, August 12, 2019 4:49:01 PM EDT Nick Howitt wrote: >> On 12/08/2019 19:16, J.R. via clamav-users wrote: I would suggest

Re: [clamav-users] Fwd: [clamav-virusdb] Signatures Published daily - 25538

2019-08-11 Thread Joel Esler (jesler) via clamav-users
I’m working on it. Been at Blackhat/defcon Sent from my  iPhone > On Aug 11, 2019, at 07:32, Al Varnell via clamav-users > wrote: > >  > Any idea what happened here? I see details do show up in the file downloaded > from the hyperlink. > > -Al- >> Begin forwarded message: >> >> From:

[clamav-users] ClamAV® blog: ClamAV 0.101.4 security patch release has been published

2019-08-21 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2019/08/clamav-01014-security-patch-release-has.html > > > ClamAV 0.101.4 security patch release has been published > > Today we have published the ClamAV 0.101.4 security patch release.

Re: [clamav-users] How do you add specific files to white list ?

2019-08-20 Thread Joel Esler (jesler) via clamav-users
> On Aug 20, 2019, at 1:22 PM, Noel Jones wrote: > > On 8/20/2019 11:51 AM, Asok Kumar via clamav-users wrote: >> i am using ClamAV version 0.101.3 and using the parameters below and >> Heuristics.Limits.Exceeded FOUND because i have enabled it in scanning. how >> do i add specific files to

Re: [clamav-users] Disable official database

2019-08-24 Thread Joel Esler (jesler) via clamav-users
I mean, it's possible not to download the official definitions and just point at a custom file right? > On Aug 24, 2019, at 10:29 AM, G.W. Haywood via clamav-users > wrote: > > Hi there, > > On Sat, 24 Aug 2019, azu...@pobox.sk wrote: > >> is it possible to disable official virus database?

Re: [clamav-users] How to boost clamav? Reloading database results in a talking timeout?

2019-09-01 Thread Joel Esler (jesler) via clamav-users
Alright. I think we’ve beat the proverbial dead horse here. The devs know this is a request and they will get it into their dev queue for examination. Sent from my  iPhone > On Sep 1, 2019, at 13:21, G.W. Haywood via clamav-users > wrote: > > Hi there, > >> On Sun, 1 Sep 2019, Thomas

Re: [clamav-users] freshclam incremental update

2019-09-01 Thread Joel Esler (jesler) via clamav-users
Good question. Sent from my  iPhone > On Sep 1, 2019, at 13:04, Matus UHLAR - fantomas wrote: > >  >> >>> On Sun, 1 Sep 2019, Birger Birger via clamav-users wrote: >>> Deleted the mirrors.dat file and tried a new freshclam with result: >>> getpatch: can't download daily-25559.cdiff from

Re: [clamav-users] freshclam incremental update

2019-09-01 Thread Joel Esler (jesler) via clamav-users
Db.se.clamav.net just points to database.clamav.net. In fact, all of the country domain names point to database now. Sent from my  iPhone > On Sep 1, 2019, at 09:58, Birger Birger via clamav-users > wrote: > >  > Deleted the mirrors.dat file and tried a new freshclam with result: >

Re: [clamav-users] Automated submissions to third party databases?

2019-09-03 Thread Joel Esler (jesler) via clamav-users
On 9/3/19, 4:15 AM, "clamav-users on behalf of G.W. Haywood via clamav-users" wrote: Hi Joel, On Mon, 2 Sep 2019, Joel Esler (jesler) wrote: > >> On Sep 2, 2019, at 05:11, G.W. Haywood via clamav-users ... wrote: >> >> ... I'm flagging up quite a few messages

Re: [clamav-users] Automated submissions to third party databases?

2019-09-02 Thread Joel Esler (jesler) via clamav-users
Have you automated their upload to ClamAV.net using clamsubmit? Sent from my  iPhone > On Sep 2, 2019, at 05:11, G.W. Haywood via clamav-users > wrote: > > Hi there, > > If you've been paying even scant attention to the list mail you'll > know that I've been doing some testing,

Re: [clamav-users] Pure Perl milter for clamd.

2019-08-22 Thread Joel Esler (jesler) via clamav-users
What I have found is: If a project has usefulness for you, and you are willing to open it up to others, it probably has usefulness to someone else. > On Aug 22, 2019, at 12:48 PM, G.W. Haywood via clamav-users > wrote: > > Hi there, > > Anyone interested in a pure Perl ClamAV milter? > >

Re: [clamav-users] Fwd: Fwd: freshclam incremental update

2019-09-04 Thread Joel Esler (jesler) via clamav-users
This looks promising to troubleshoot. Sent from my  iPhone > On Sep 4, 2019, at 03:01, Birger Birger via clamav-users > wrote: > > Sep 4 08:40:01 zentyal kernel: [345190.998397] audit: type=1400 > audit(1567579201.044:83): apparmor="DENIED" operation="connect" >

Re: [clamav-users] Fwd: Fwd: Fwd: freshclam incremental update

2019-09-05 Thread Joel Esler (jesler) via clamav-users
How did you get this? Sent from my  iPad > On Sep 5, 2019, at 05:06, Birger Birger via clamav-users > wrote: > >  > This might provide additional information. > > /usr/bin/freshclam > *Trying to retrieve CVD header of http://%s/%s > %cremote_cvdhead: write failed > %cremote_cvdhead:

Re: [clamav-users] Broken link

2019-09-10 Thread Joel Esler (jesler) via clamav-users
This has been fixed. > On Sep 10, 2019, at 11:52 AM, Joel Esler (jesler) via clamav-users > wrote: > > Thank you Jerry. > >> On Sep 10, 2019, at 10:09 AM, Jerry via clamav-users >> wrote: >> >> I am not sure who to report his to,so I figured I woul

Re: [clamav-users] Broken link

2019-09-10 Thread Joel Esler (jesler) via clamav-users
Thank you Jerry. > On Sep 10, 2019, at 10:09 AM, Jerry via clamav-users > wrote: > > I am not sure who to report his to,so I figured I would start here. > > The following link: > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-virusdb > > on https://www.clamav.net/reports/fp > >

[clamav-users] ClamAV® blog: ClamAV 0.102.0 Release Candidate is now available

2019-09-16 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2019/09/clamav-01020-release-candidate-is-now.html ClamAV 0.102.0 Release Candidate is now available Today we are publishing the release candidate for ClamAV 0.102.0 (clamav-0.102.0-rc). There have been some bug fixes and minor improvements since the 0.102.0 beta. We

Re: [clamav-users] Programmatic determination of latest stable version

2019-09-16 Thread Joel Esler (jesler) via clamav-users
Freshclam* Sent from my  iPhone > On Sep 16, 2019, at 16:11, jes...@cisco.com wrote: > > Either navigating to clamav’s download site, or using something like fresh > Lan’s code to check the DNS entry for latest stable version. > > Sent from my  iPhone > >>> On Sep 16, 2019, at 16:09,

Re: [clamav-users] Programmatic determination of latest stable version

2019-09-16 Thread Joel Esler (jesler) via clamav-users
Either navigating to clamav’s download site, or using something like fresh Lan’s code to check the DNS entry for latest stable version. Sent from my  iPhone > On Sep 16, 2019, at 16:09, Callahan, Michael (M.) via clamav-users > wrote: > >  > Is there an endpoint or preferred method of

Re: [clamav-users] Freshclam "Can't query daily" due to DNS issue

2019-07-27 Thread Joel Esler (jesler) via clamav-users
Let me have a look... Sent from my  iPhone > On Jul 27, 2019, at 13:14, Robert L Mathews wrote: > > For a few days, I've been seeing new messages like this in the logs, > once per day per server: > > freshclam[1133]: Sat Jul 27 01:49:03 2019 -> *Can't query >

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-30 Thread Joel Esler (jesler) via clamav-users
Part I needed: > On Jul 30, 2019, at 1:25 PM, Henrik K wrote: > > Control. Part I didn't need: > Is it really necessary to go over basic IT management practises here? smime.p7s Description: S/MIME cryptographic signature ___ clamav-users

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-30 Thread Joel Esler (jesler) via clamav-users
gt; that ensured redundant systems were not all reloading signatures at the same > time. > > dp > >> On 7/30/19 10:13 AM, Joel Esler (jesler) via clamav-users wrote: >> I'm interested as to why people want to do private mi

Re: [clamav-users] ClamAV: Local Private Mirror

2019-07-30 Thread Joel Esler (jesler) via clamav-users
I'm interested as to why people want to do private mirrors? Other than to save bandwidth going to "the internet"? > On Jul 30, 2019, at 9:40 AM, J.R. via clamav-users > wrote: > >> Can you please tell me the H/W and S/W Specification >> of the Private local Mirror Server as a best practice

[clamav-users] ClamAV® blog: ClamAV 0.101.3 security patch release and 0.102.0-beta have been published

2019-08-05 Thread Joel Esler (jesler) via clamav-users
> > https://blog.clamav.net/2019/08/clamav-01013-security-patch-release-and.html > > > ClamAV 0.101.3 security patch release and 0.102.0-beta have been published > > We are pleased to introduce the ClamAV 0.101.3

Re: [clamav-users] [Clamav-devel] ClamAV® blog: ClamAV 0.101.3 security patch release and 0.102.0-beta have been published

2019-08-06 Thread Joel Esler (jesler) via clamav-users
Yeah, we have to update that bit. Sent from my  iPad > On Aug 5, 2019, at 23:44, Gary R. Schmidt wrote: > > On 06/08/2019 05:32, Joel Esler (jesler) wrote: >>> >>> https://blog.clamav.net/2019/08/clamav-01013-security-patch-release-and.html >>> >>>

Re: [clamav-users] clamsubmit error

2019-08-08 Thread Joel Esler (jesler) via clamav-users
We’re looking into this Arnaud. Sent from my  iPad > On Aug 8, 2019, at 11:09, Arnaud Jacques wrote: > > Hello Micah, > > Still got the same error on each submitted file. > > >> Le 08/08/2019 à 17:18, Micah Snyder (micasnyd) via clamav-users a écrit : >> Clamsubmit currently uses web

Re: [clamav-users] Freshclam seems locked and can not be unlocked.

2019-08-04 Thread Joel Esler (jesler) via clamav-users
That’s a pretty broad statement. As a security minded person, I’d think you’d want software that was the most patched against any possible vulnerabilities. Sent from my  iPhone > On Aug 4, 2019, at 10:15, Matus UHLAR - fantomas wrote: > > There is no point of havine newest version of any

Re: [clamav-users] Win.Malware.Krucky-7009041-0 false positive

2019-07-20 Thread Joel Esler (jesler) via clamav-users
Signature has already been dropped. Sent from my  iPhone > On Jul 20, 2019, at 07:37, Groach via clamav-users > wrote: > > Already have done. But I have never (no exaggeration) had any success with it > being actioned when reported only on that website. So I am also sending this >

Re: [clamav-users] ClamAV independent assessment?

2019-07-24 Thread Joel Esler (jesler) via clamav-users
ClamAV is an open source project. Anyone can examine the code at any time and many continually do. Do you mean in terms of security of the code base or in terms of efficacy. Either way, the answer is the same. Sent from my  iPhone > On Jul 24, 2019, at 15:00, David Cantrell via

Re: [clamav-users] ClamAV independent assessment?

2019-07-24 Thread Joel Esler (jesler) via clamav-users
I am currently unaware of any third party assessments of the ClamAV code. Sent from my  iPhone > On Jul 24, 2019, at 19:36, David Cantrell wrote: > > Yes I'm aware of its open source status that's why I'm asking here. I'm > specifically asking if anyone is aware of any independent third

Re: [clamav-users] Win.Malware.Krucky-7009041-0 false positive

2019-07-22 Thread Joel Esler (jesler) via clamav-users
It may be waiting on peer review internally. Sent from my  iPhone > On Jul 21, 2019, at 08:04, Arnaud Jacques wrote: > > Yes, confirmed > >> Le 21/07/2019 à 13:05, Groach via clamav-users a écrit : >> Confirmed.? Updated and rescanned: >> Scan Started Sun Jul 21 12:02:25 2019 >>

Re: [clamav-users] [Clamav-devel] ClamAV(R) blog: ClamAV 0.102.0 Release Candidate is now available

2019-10-01 Thread Joel Esler (jesler) via clamav-users
On Oct 1, 2019, at 10:29 AM, J.R. via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: ClamAV isn't responsible for maintaining spec files, those are DISTRO-SPECIFIC... Imagine if they were supposed to maintain packages for every distro out there... That would basically bring

[clamav-users] ClamAV® blog: ClamAV 0.102.0 has been released!

2019-10-02 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2019/10/clamav-01020-has-been-released.html ClamAV 0.102.0 has been released! Today we are excited to release ClamAV 0.102.0! Users that have tested the 0.102.0 release candidate may note that the 0.102.0 release includes a handful of minor bug fixes and improvements

Re: [clamav-users] [Clamav-devel] ClamAV(R) blog: ClamAV 0.102.0 Release Candidate is now available

2019-10-02 Thread Joel Esler (jesler) via clamav-users
> > > Rick > > From: clamav-users [mailto:clamav-users-boun...@lists.clamav.net] On Behalf > Of Joel Esler (jesler) via clamav-users > Sent: Tuesday, October 01, 2019 11:00 AM > To: ClamAV users ML > Cc: Joel Esler (jesler); J.R. > Subject: Re: [clamav-users]

Re: [clamav-users] performance degradation of clamscan

2019-07-09 Thread Joel Esler (jesler) via clamav-users
This has been fixed for some time has it not? > On Jul 9, 2019, at 3:38 PM, Paul Kosinski via clamav-users > wrote: > > The CVD version delivered by Cloudflare's "BOS" > Anycast server was often behind the version advertised by the DNS TXT. smime.p7s Description: S/MIME cryptographic

Re: [clamav-users] performance degradation of clamscan

2019-07-09 Thread Joel Esler (jesler) via clamav-users
You are right. They can change. But it’s dependent on your location. So as long as you don’t move your position on earth ;), you should be fine. Unless cloudflare drastically changes things. Sent from my  iPhone > On Jul 9, 2019, at 18:58, Paul Kosinski wrote: > > I hadn't looked

Re: [clamav-users] ClamAV not listed at VirusTotal anymore

2019-11-06 Thread Joel Esler (jesler) via clamav-users
I just uploaded a file, and I see it > On Nov 6, 2019, at 9:04 AM, MAYER Hans via clamav-users > wrote: > > > Dear All, > > I uploaded a file for testing at VirusTotal just now. > I am wondering that ClamAV is not listed anymore. Some hours earlier it was. > Does anyone know about

[clamav-users] ClamAV® blog: ClamAV is planning on publishing a new main.cvd

2019-11-22 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2019/11/clamav-is-planning-on-publishing-new.html ClamAV is planning on publishing a new main.cvd This serves as notice that we are planning on publishing a new main.cvd and a cdiff Monday, November 25, 2019. In the past we notified our mirror maintainers to let them

Re: [clamav-users] ClamAV® blog: ClamAV is planning on publishing a new main.cvd

2019-11-22 Thread Joel Esler (jesler) via clamav-users
On Nov 22, 2019, at 1:45 PM, Matus UHLAR - fantomas mailto:uh...@fantomas.sk>> wrote: On 22.11.19 15:39, Joel Esler (jesler) via clamav-users wrote: https://blog.clamav.net/2019/11/clamav-is-planning-on-publishing-new.html ClamAV is planning on publishing a new main.cvd This serves as

Re: [clamav-users] Why virus definition DB download url is not https?

2019-12-13 Thread Joel Esler (jesler) via clamav-users
The definitions are cached by our CDN now. Https just makes the transport layer encrypted. The definitions are already signed, as you all know. Sent from my  iPhone > On Dec 13, 2019, at 04:43, Matus UHLAR - fantomas wrote: > > On 12.12.19 22:15, Joel Esler (jesler) via cla

Re: [clamav-users] Why virus definition DB download url is not https?

2019-12-12 Thread Joel Esler (jesler) via clamav-users
They are served over https. But only 102.x supports https. So as soon as everyone moves to https, I’ll gladly decommission http. Sent from my  iPhone > On Dec 12, 2019, at 15:01, Nick Howitt wrote: > > But If you are behind another virus scanner, it can't so easily be > intercepted and

[clamav-users] ClamAV® blog: ClamAV 0.102.1 and 0.101.5 patches have been released!

2019-11-20 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2019/11/clamav-01021-and-01015-patches-have.html ClamAV 0.102.1 and 0.101.5 patches have been released! Today we are publishing two patch versions, 0.102.1 and 0.101.5. Both of these can be found on ClamAV's downloads page, with

Re: [clamav-users] Sigtool problem

2019-11-27 Thread Joel Esler (jesler) via clamav-users
What happens if you issue the full part in the sigtool command? Sent from my  iPhone > On Nov 27, 2019, at 13:08, Paul via clamav-users > wrote: > > Hi > > Am I missing something here or is sigtool broken in 101.5 > > > root@larch:/tmp/paul# ls /var/lib/clamav/*.cld -lh > -rw-r--r-- 1

Re: [clamav-users] Continuous increase of startup time (is daily.cld broken?)

2019-10-07 Thread Joel Esler (jesler) via clamav-users
On Oct 7, 2019, at 6:39 AM, Vladislav Kurz via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: On 07/10/2019 08:57, Sergey wrote: On Friday 13 September 2019, Markus Kolb via clamav-users wrote: I've opened an enhacement bug for this:

Re: [clamav-users] [Clamav-devel] ClamAV(R) blog: ClamAV 0.102.0 Release Candidate is now available

2019-10-05 Thread Joel Esler (jesler) via clamav-users
This is super critical to the future of where ClamAV is headed. So, while I understand it’s a pain in the butt, we need to work out, as a community, maybe with an faq page contributed by all of us, how to get past this hurdle. Sent from my  iPhone > On Oct 5, 2019, at 09:41, Dennis Peterson

Re: [clamav-users] Question

2019-10-03 Thread Joel Esler (jesler) via clamav-users
You mean on clamav.net/downloads? -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com From: clamav-users on behalf of alex mc via clamav-users Reply-To: ClamAV users ML Date: Thursday, October 3, 2019 at 12:31 PM To:

Re: [clamav-users] messages in freshclam.log

2019-12-23 Thread Joel Esler (jesler) via clamav-users
These don’t exist. All of these addresses simply point at database.clamav.net. So, it makes no sense to point them to anything else. Sent from my  iPad > On Dec 23, 2019, at 04:19, Sohin Vyacheslav via clamav-users > wrote: > > DatabaseMirror db.nl.ipv6.clamav.net > DatabaseMirror

Re: [clamav-users] CLAMAV 0.99.2 question about last valid definition

2020-02-26 Thread Joel Esler (jesler) via clamav-users
Agreed. You need to upgrade the engine. Sent from my  iPad > On Feb 26, 2020, at 10:12, Arjen de Korte via clamav-users > wrote: > > Citeren 99r c via clamav-users : > >> I am in a situation (just started working here last month) where I have an >> install of a few RHEL 5.5 machines that

[clamav-users] ClamAV® blog: ClamAV 0.102.2 security patch released

2020-02-05 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html Today, we're publishing 0.102.2. Navigate to ClamAV's downloads page to download the release materials. 0.102.2 ClamAV 0.102.2 is a security patch release to address the following issues.

Re: [clamav-users] gui themes, stilllllllllll asking please

2020-02-06 Thread Joel Esler (jesler) via clamav-users
What GUI themes? Sent from my  iPhone On Feb 6, 2020, at 06:45, Jack via clamav-users wrote:  How are the gui themes coming pleasse?? Thanks! Jack in Idaho ___ clamav-users mailing list clamav-users@lists.clamav.net

Re: [clamav-users] update 25717 clamdmon showing NO OK

2020-02-07 Thread Joel Esler (jesler) via clamav-users
Any additional logs you can provide? -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com On 2/7/20, 7:59 AM, "clamav-users on behalf of Mark Moshe Kaye" wrote: Hi All, As of daily.cld update 25717 my clamdmon process no

[clamav-users] ClamAV® blog: ClamAV Bugzilla Upgrade

2020-02-17 Thread Joel Esler (jesler) via clamav-users
https://blog.clamav.net/2020/02/clamav-bugzilla-upgrade.html Attn: ClamAV users, we will be upgrading our version of bugzilla on Wednesday, February 19th, at 8:00 EST. The impact should be minimal, and should take no longer than a couple hours. We will notify you when it is back up. Thank

Re: [clamav-users] Clamav 0.99.2 and new virus definitions

2020-02-20 Thread Joel Esler (jesler) via clamav-users
I'm going to go with "No". Or they would have been written that way to begin with. We try to maximize compatibility with lowest known tested version as much as possible. Possibly what we should do is adjust the fLevel on those signatures. On Feb 20, 2020, at 12:11 PM, 99r c via clamav-users

Re: [clamav-users] unsubscribe

2020-02-11 Thread Joel Esler (jesler) via clamav-users
Thank you for writing in. Go to this URL to change user options or unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users or by sending an email to clamav-users-le...@lists.clamav.net Thanks! On 2/11/20, 12:18 PM, "clamav-users on behalf of Christiansen, Edward - 0992 - MITLL"

Re: [clamav-users] user list

2020-02-11 Thread Joel Esler (jesler) via clamav-users
Thank you for writing in. Go to this URL to change user options or unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users or by sending an email to clamav-users-le...@lists.clamav.net Thanks! From: clamav-users on behalf of fritz blum via clamav-users Reply-To: ClamAV

Re: [clamav-users] messages in freshclam.log

2019-12-23 Thread Joel Esler (jesler) via clamav-users
I think the status is currently “ignore this”. Sent from my  iPad > On Dec 23, 2019, at 10:52, Eric Tykwinski wrote: > > This was mentioned here before, and I can't remember what the status was. > > For this example: > A dig trace leads to: > ping.clamav.net.86400 IN NS

Re: [clamav-users] Gentoo Linux installation package for Fangfrisch is now available

2020-03-08 Thread Joel Esler (jesler) via clamav-users
This is cool. Thanks Ralph. Sent from my  iPad > On Mar 7, 2020, at 19:50, Ralph Seichter via clamav-users > wrote: > > It took a while for my submission to be processed, but the Gentoo Linux > installation package is finally available: > >

Re: [clamav-users] Squid + ClamAV

2020-04-07 Thread Joel Esler (jesler) via clamav-users
> On Apr 7, 2020, at 10:24 AM, Henrik K wrote: > > On Tue, Apr 07, 2020 at 11:27:50AM +0100, G.W. Haywood via clamav-users wrote: >> >> I certainly don't subscribe to the view expressed in this thread (if >> that's the view that was expressed, and I'm not simply misrepresenting >> it) that

Re: [clamav-users] ClamAV users

2020-04-11 Thread Joel Esler (jesler) via clamav-users
Thank you for writing in. Go to this URL to change user options or unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users or by sending an email to clamav-users-le...@lists.clamav.net Thanks! Sent from my  iPhone > On Apr 10, 2020, at 15:58, Stephen Baron via clamav-users >

Re: [clamav-users] Mirror at microsoft has obsolete cvd files

2020-03-27 Thread Joel Esler (jesler) via clamav-users
Yes. You should ask Microsoft to stop distributing mirror updates, and people should get the official mirror updates from Clamav itself. Sent from my  iPhone > On Mar 27, 2020, at 07:34, Henrik Hoeg Thomsen1 via clamav-users > wrote: > > Mirrror at Microsoft is obsolete? > >

Re: [clamav-users] Status of SafeBrowsing CVD

2020-04-02 Thread Joel Esler (jesler) via clamav-users
Erik, Thank you for asking. We have discontinued the distribution of safebrowsing.cvd, as Google is now charging for access to this API. We plan to open source the tool we made to create this CVD file so anyone can get their own API key from Google and do it themselves. We just haven’t been

Re: [clamav-users] IP Blacklisted by Mirror

2020-04-23 Thread Joel Esler (jesler) via clamav-users
Team — I control Cloudflare. Who is blocked and who is not is literally up to me. If you are being blocked, feel free to write me 1:1, share your IP with me, and I’ll tell you why you’re blocked. A ticket can also be filed on bugzilla.clamav.net under “mirrors”

Re: [clamav-users] clamsubmit error 500

2020-05-01 Thread Joel Esler (jesler) via clamav-users
Does it happen every time, or just once? On 5/1/20, 10:42 AM, "clamav-users on behalf of Arnaud Jacques" wrote: Hello, Using clamsubmit, I got : Unexpected POST submit response code: 500 -- Cordialement / Best regards, Arnaud Jacques Gérant de SecuriteInfo.com

  1   2   3   4   >