Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread rafa
Sunny K wrote: > Hi, > > Is there any way to use clamav on an internet gateway (linux based) to > protect connected hosts from virus/malicious content? > > (Internet)-| Internet Gateway (linux on x86) | Host-1 > | > | Host-2 > > Thanks, > Sa

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread reiner otto
--- Dennis Peterson schrieb am Fr, 6.2.2009: Von: Dennis Peterson Betreff: Re: [Clamav-users] Using clamav on internet gateway An: "ClamAV users ML" Datum: Freitag, 6. Februar 2009, 19:58 Sunny K wrote: > Hi, > > Is there any way to use clamav on an internet gateway (linux based) to > protec

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread Andy
Another is SafeSquid, which now does not require Squid itself to be installed and or running if it is installed. http://www.howtoforge.com/gateway-level-virus-security-clamav-safesquid-proxySafeSquid has windows and *nix support. I believe Snort can even use ClamAV http://en.wikipedia.org/wiki/Snor

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread Steve
On Sat, 7 Feb 2009 00:11:10 +0530 Sunny K wrote: > Hi, > > Is there any way to use clamav on an internet gateway (linux based) to > protect connected hosts from virus/malicious content? > > (Internet)-| Internet Gateway (linux on x86) | Host-1 > | > |--

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread Dennis Peterson
Sunny K wrote: > Hi, > > Is there any way to use clamav on an internet gateway (linux based) to > protect connected hosts from virus/malicious content? > > (Internet)-| Internet Gateway (linux on x86) | Host-1 > | > | Host-2 ClamAV is used su

[Clamav-users] Using clamav on internet gateway

2009-02-06 Thread Sunny K
Hi, Is there any way to use clamav on an internet gateway (linux based) to protect connected hosts from virus/malicious content? (Internet)-| Internet Gateway (linux on x86) | Host-1 | | Host-2 Thanks, Sam

Re: [Clamav-users] Is there any maintenance

2009-02-06 Thread Nigel Horne
McDonald, Dan wrote: > On Fri, 2009-02-06 at 10:08 -0800, Madhuri Somavarapu wrote: >> Hi, >> >> I installed clamav on my machine. I am using it for scanning files not >> for my mail server I want to know what kind of maintainence needed for >> this software (Like upgrades). > > Upgrades are not a

Re: [Clamav-users] Is there any maintenance

2009-02-06 Thread McDonald, Dan
On Fri, 2009-02-06 at 10:08 -0800, Madhuri Somavarapu wrote: > Hi, > > I installed clamav on my machine. I am using it for scanning files not > for my mail server I want to know what kind of maintainence needed for > this software (Like upgrades). Upgrades are not automatic, so watch the user lis

Re: [Clamav-users] Is there any maintenance

2009-02-06 Thread david
Hello, this was just discussed: http://tools.declude.com. Apparently only the first two on the pull-down menu are of any value. HTH, David. Madhuri Somavarapu wrote .. > Hi, > > I installed clamav on my machine. I am using it for scanning files not for my > mail > server I want to know what ki

[Clamav-users] Is there any maintenance

2009-02-06 Thread Madhuri Somavarapu
Hi, I installed clamav on my machine. I am using it for scanning files not for my mail server I want to know what kind of maintainence needed for this software (Like upgrades). Does it scan all kind of basic document types like Microsoft products, Adobe, Txt files? Where can I find the virus

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread david
Hello Noel, yep it worked. The eicar message was found but not before a user with enough time to open the mail message and the attachement. And, it is difficult to tell exactly which message is the culprit because all I see from the CRON log email is: /Maildir/cur/1233939406.Vfd00I270080M968444

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread david
Hello Alex, I don't have a definitive test either. I have recently installed ClamAV on my gateway/router/firewall/smtp Linux box. I tried the canned test as suggested in the ClamAV doco but I could not see anything definitive. I agree that a real email from the would be a definitive test. Since

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Noel Jones
Alex Davidson wrote: > Interesting...if I create a plain text email with the eicar text in > it, ClamAV detects it successfully. > > Can anyone suggest another way to send myself a > non-password-protected/encrypted attachment that ClamAV might have a > chance at detecting? There is a test tool a

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Dennis Peterson
Andy wrote: > You'll need to find a nastie that your local/server AV don't detect, but > ClamAV does. Or make an exception for a file extention... rename eicar.txt > to eicar.z43 (something random) and make sure your server and local av will > ignore that file extention. > It's not that difficult

Re: [Clamav-users] clamd fails to detect structured data after running for 10 minutes

2009-02-06 Thread Török Edwin
On 2009-02-06 17:37, Tim Maletic wrote: > I'm seeing some strange behavior in the latest svn, where clamd stops > detecting certain structured data test files after the daemon has been > running for about 10 minutes. (See syslog sample below.) Not sure if > this is specific to structured data or

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Andy
You'll need to find a nastie that your local/server AV don't detect, but ClamAV does. Or make an exception for a file extention... rename eicar.txt to eicar.z43 (something random) and make sure your server and local av will ignore that file extention. On Fri, Feb 6, 2009 at 10:45 AM, Alex Davidson

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Alex Davidson
Interesting...if I create a plain text email with the eicar text in it, ClamAV detects it successfully. Can anyone suggest another way to send myself a non-password-protected/encrypted attachment that ClamAV might have a chance at detecting? It's either that or disable my workstation AV and server

[Clamav-users] clamd fails to detect structured data after running for 10 minutes

2009-02-06 Thread Tim Maletic
I'm seeing some strange behavior in the latest svn, where clamd stops detecting certain structured data test files after the daemon has been running for about 10 minutes. (See syslog sample below.) Not sure if this is specific to structured data or not. Anyone else seeing anything similar. Is t

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Noel Jones
Steve Basford wrote: > > Alex Davidson wrote: > >> send myself EICAR test >> virus strings but firstly only 3 of the 7 tests hit my mail server, >> and secondly ClamAV doesn't detect anything, yet the next-level AV >> detects it just fine. > > I tried to send the 7 tests to my main address... on

Re: [Clamav-users] How to test ClamAV

2009-02-06 Thread Steve Basford
Alex Davidson wrote: >send myself EICAR test >virus strings but firstly only 3 of the 7 tests hit my mail server, >and secondly ClamAV doesn't detect anything, yet the next-level AV >detects it just fine. I tried to send the 7 tests to my main address... only 3 arrived (the clean one - and 2 o