Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-07-08 Thread Al Varnell
So you’ve tried the beta and it didn’t fix the issue? One of the reasons for announcing the beta was so folks like you can play in the bug fixing process. There are dozens of changes to each version and only a few of the major items are ever mentioned in the announcements. There are far too ma

Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-07-08 Thread Henrik K
It's been two mondays now and no news... a new beta is posted but nothing about the issue is mentioned? On Thu, Jun 26, 2014 at 12:52:47PM -0400, Shawn Webb wrote: > Hey Paul, > > The reason for that is likely due to my usage of ctors and dtors with > 0.98.3. In that version, I had added a ctor

[clamav-users] ClamAV®: ClamAV 0.98.5 beta has been posted!

2014-07-08 Thread Joel Esler (jesler)
ClamAV 0.98.5 beta has been posted! The ClamAV team is proud to announce the availability of ClamAV 0.98.5 beta ready for testing! http://blog.clamav.net/2014/07/clamav-0985-beta-has-been-posted.html -- Joel Esler Open Source Manager Threat Intelligence Team Lead Vulnerability Research Team ___

Re: [clamav-users] clamav 0.98.4 on Centos4

2014-07-08 Thread René Bellora
El 04/07/14 18:22, Greg Folkert escribió: FYI, CentOSv4 Support Ended Feb 2012. It is over 2 years out of date. The newest I've been able to get to work is 0.98.1 with Stock Stuff. Install/Compile a newer version of OpenSSL in /usr/local/openssl-(version)/ and point your ClamAV compile towards i

Re: [clamav-users] Custom signature question

2014-07-08 Thread Steve Basford
I guess, if you *really* wanted to block mp3's being emailed you could create a type4 ndb signature to match the mp3 base64 in the email ? eg... email format... == Content-Type: audio/mpeg; name="test.mp3" Content-Transfer-Encoding: base64 Content-Disposition: attachment;

Re: [clamav-users] Custom signature question

2014-07-08 Thread Steve Basford
On Tue, July 8, 2014 3:41 pm, a...@alb.de wrote: > alex:~$ dd if=mp3file.mp3 count=1 | sigtool --hex-dump > alex:~$ clamscan mp3file.exe Hi Alex, In the daily.ftm file, mp3 filetypes are ignored. 0:0:494433:MP3:CL_TYPE_ANY:CL_TYPE_IGNORED Cheers, Steve Sanesecurity

[clamav-users] Custom signature question

2014-07-08 Thread alex
Hello, I'm trying to create signatures for clamav, to detect exe and mp3 files. Seems to work for exe, but strangely not for mp3, despite the fact I did excatly the same in both cases: Getting signatures for both files: alex:~$ dd if=exefile.exe count=1 | sigtool --hex-dum 1+0 Datensätze ein 1+

Re: [clamav-users] Win.Trojan.Zwangi-432 / Osx.Exploit.CVE_2006_0848 / PHP.Shell-29

2014-07-08 Thread Joel Esler (jesler)
> On Jul 8, 2014, at 5:11, "DUCARROZ Birgit" wrote: > > Platform: You mean the platform where clamav is installed, not the platform > the virus is for, just? Yes. The platform where ClamAV is. > What do you mean I must attach with "raw message"? The output of the > virus-scan? Or the file

Re: [clamav-users] Win.Trojan.Zwangi-432 / Osx.Exploit.CVE_2006_0848 / PHP.Shell-29

2014-07-08 Thread DUCARROZ Birgit
Hi Alain, Just some questions about the form: Platform: You mean the platform where clamav is installed, not the platform the virus is for, just? What do you mean I must attach with "raw message"? The output of the virus-scan? Or the file containing the virus (or false positive)? - Birgit O