Re: [Clamav-users] how do you start clamav-milter

2004-11-02 Thread Meni Shapiro
Tom D`Asto wrote: I'm following the instructions in clamav-0.80/clamav-milter/INSTALL. My first problem is that the following file does not exist so I can't add the variable CLAMAV_FLAGS: Add to /etc/sysconfig/clamav-milter CLAMAV_FLAGS="local:/var/run/clamav/clmilter.sock" vim /etc/

[Clamav-users] how do you start clamav-milter

2004-11-02 Thread Tom D`Asto
I'm following the instructions in clamav-0.80/clamav-milter/INSTALL.  My first problem is that the following file does not exist so I can't add the variable CLAMAV_FLAGS: Add to /etc/sysconfig/clamav-milter           CLAMAV_FLAGS="local:/var/run/clamav/clmilter.sock" The next problem is th

Re: [Clamav-users] configure failure: libmilter directory not found?

2004-11-02 Thread Dale Walsh
Tom, you've probably tried using Stuffit to extract the archive. Try tar -xzf sendmail.8.13.1.tar.gz This should extract it properly. -- Dale ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread clamav
On Wed, 3 Nov 2004, Tomasz Kojm wrote: > > > You can probably all see the problem already. IfRaMe is not cought > > > by our sig. Does this mean 6! (factorial) additional signatures are > > Just for the record: the above calculation is also incorrect. There are > 2^6 (= 64) possibilities (and no

Re: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread clamav
On Wed, 3 Nov 2004, Tomasz Kojm wrote: > > Matches a case-sensitive regex of: IFRAME={256,} > > Exploit.IFRAME.foo:*:494652414d453d??{256-} > > Bad format. Thank you for pointing that out, I greatly appreciate your help. Perhaps I misunderstood what the format meant when I posted the message the

Re: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread Tomasz Kojm
On Wed, 3 Nov 2004 01:35:39 +0100 Tomasz Kojm <[EMAIL PROTECTED]> wrote: > On Tue, 2 Nov 2004 16:11:30 -0800 (PST) > [EMAIL PROTECTED] wrote: > > > Matches a case-sensitive regex of: IFRAME={256,} > > > > Exploit.IFRAME.foo:*:494652414d453d??{256-} > > Bad format. > > > You can probably all se

Re: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread Tomasz Kojm
On Tue, 2 Nov 2004 16:11:30 -0800 (PST) [EMAIL PROTECTED] wrote: > Matches a case-sensitive regex of: IFRAME={256,} > > Exploit.IFRAME.foo:*:494652414d453d??{256-} Bad format. > You can probably all see the problem already. IfRaMe is not cought by > our sig. Does this mean 6! (factorial) addi

RE: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread clamav
und (http://www.k-otik.com/exploits/20041102.InternetExploiter.htm.php), the following signature should work if I understand correctly. This isn't perfect and there are many javascripty ways arround it so please add your thoughts. Matches a case-sensitive regex of: IFRAME={256

RE: [Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread Minica, Nelson (EDS)
Looks like there is proof of concept code here: http://felinemenace.org/~nd/crash_ie/ file 2446.html http://www.securityfocus.com/bid/11515/exploit/ Nelson Minica ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

[Clamav-users] [SA12959] Internet Explorer IFRAME Buffer Overflow Vulnerability (fwd)

2004-11-02 Thread clamav
This just came across the wire and if anyone can find a working exploit to make a signature for this latest iframe we can jump ahead of new exploits which are fast coming. I will continue to look for a working exploit and post a sig when available. We are on the edge of a big outbreak and exampl

Re: [Clamav-users] Exploit-Mime.gen.c detection

2004-11-02 Thread Joe Maimon
Cali Federico wrote: Hi all, analyzing the same e-mail with two different antivirus software I have different results: -- ClamAv detects Worm.SomeFool.p virus -- McAfee WebShield detects both W32/[EMAIL PROTECTED] and Exploit-MIME.gen.c I know that Worm.SomeFool.p and W32/[EMAIL PROTECTED] are

Re[2]: [Clamav-users] Clamd process

2004-11-02 Thread Henri van Riel
Hello Trog, Tuesday, November 2, 2004, 8:47:26 PM, you wrote: > On Tue, 2004-11-02 at 19:39, Henri van Riel wrote: > I'm just wondering why there are two processes... > They aren't processes, they are threads. Clamd spawns new threads to do > the actual work, and when a worker thread has been id

Re: [Clamav-users] Clamd process

2004-11-02 Thread Trog
On Tue, 2004-11-02 at 19:39, Henri van Riel wrote: > Hello all, > > I'm new to ClamAV and this list and I have the following `problem`. > > I use clamav together with p3scan but that is irrelevant to my > question. I first start the clamd deamon and then the p3scan deamon. > Everything starts jus

[Clamav-users] Clamd process

2004-11-02 Thread Henri van Riel
Hello all, I'm new to ClamAV and this list and I have the following `problem`. I use clamav together with p3scan but that is irrelevant to my question. I first start the clamd deamon and then the p3scan deamon. Everything starts just fine. But when I use clamdscan to scan a directory for instance

[Clamav-users] Exploit-Mime.gen.c detection

2004-11-02 Thread Cali Federico
Hi all, analyzing the same e-mail with two different antivirus software I have different results: -- ClamAv detects Worm.SomeFool.p virus -- McAfee WebShield detects both W32/[EMAIL PROTECTED] and Exploit-MIME.gen.c I know that Worm.SomeFool.p and W32/[EMAIL PROTECTED] are the same but what a

Re: [Clamav-users] please fix your freshclam setup

2004-11-02 Thread Luca Gibelli
Hello [EMAIL PROTECTED], > Here is the output from mine run a few minutes ago. > > Current working dir is /var/www/html/clamav > Max retries == 3 > ClamAV update process started at Mon Nov 1 14:21:33 2004 > TTL: 880 > main.cvd version from DNS: 27 > Software version from DNS: 0.80 > Connecting

Re: [Clamav-users] please fix your freshclam setup

2004-11-02 Thread Luca Gibelli
Hello, > I got this instead. Meaning i do not have DNSDatabaseInfo? if you are running ClamAV 0.80 please edit freshclam.conf (usually installed under /etc/clamav/ or /usr/local/etc/clamav/) and add the following line: DNSDatabaseInfo current.cvd.clamav.net Then run # freshclam -v from the

Re: [Clamav-users] please fix your freshclam setup

2004-11-02 Thread Luca Gibelli
Hello Steven Stern, > >1) if you run freshclam from crontab, check that you have an entry like > >the following: > > > >N * * * * /usr/local/bin/freshclam --quiet [snip] > Are you OK with this? > > 12 */2 * * * sleep `expr $RANDOM \% 1800` && /usr/bin/freshclam --quiet > > Every other hou

Re: [Clamav-users] cygwin clamscan hangs

2004-11-02 Thread Tomasz Papszun
On Fri, 29 Oct 2004 at 11:51:50 +0200, Bogusław Brandys wrote: > David Nicol wrote: > >I decided to test cygwin clamscan and it hung after a few hundred files > > > >Going to see if winclam has the same difficulties > > > [...] > What is it "winclam" ? I didn't hear about it. Most probably David

Re: [Clamav-users] TCP and UDP ports used by clamd

2004-11-02 Thread Laurent Wacrenier
Le Ven 29 oct 15:46:44 2004, René Berber écrit: > I found this by accident, trying to run TrippLite's PowerAlert the program > reported that the port was in use, I checked and clamd was using that TCP > port. So I checked some more, with Sysinternals' tcpvcon to see what ports > was the clamd proc

Re: [Clamav-users] How to disable an option?

2004-11-02 Thread Odhiambo Washington
* Roman Suzi <[EMAIL PROTECTED]> [20041102 12:37]: wrote: > > Hi, > > >From clamd man it is not clear how to disable options which are > "enabled" by default. Can somebody tell me how to do it? > > I want to disable ScanOLE2. What I need

[Clamav-users] How to disable an option?

2004-11-02 Thread Roman Suzi
Hi, >From clamd man it is not clear how to disable options which are "enabled" by default. Can somebody tell me how to do it? I want to disable ScanOLE2. What I need to put into config _exactly_? Thank you! Sincerely yours, Roman A.Suzi -- - Petrozavodsk - Karelia - Russia - mailto:[EMAIL PR