Re: [clamav-users] Inquiry About Security Measures for Remote Scanning Using Clamdscan

2024-07-05 Thread Paul Kosinski via clamav-users
I don't think there is anything builtin to clamd, but you might consider setting up a secure tunnel(s) from the client machine(s) to the scanning machine. For example, each client machine has a little daemon that listens on a UNIX socket and is connected securely (SSH, OpenVPN etc.) to the scan

Re: [clamav-users] Debian 12.6 - clamav-deamon does not use a socket

2024-06-30 Thread Paul Kosinski via clamav-users
Did you check the permissions on the clamd socket to see if it allows access by rspamd? (I sometimes get burned by mismatched permissions.) On Sun, 30 Jun 2024 17:45:17 +0200 christian via clamav-users wrote: > Am 30.06.2024 um 17:28 schrieb Matus UHLAR - fantomas via clamav-users: > > > >

Re: [clamav-users] New Tool: ClamAV Large Archive Scanner

2024-06-04 Thread Paul Kosinski via clamav-users
A good start, and the ISO should be good for scanning CDs and such. I wonder if it could find (given the right signature) the malware on Sony's old music CDs that AV companies ignored, but some independent researcher discovered, and then the DHS (!) cited as being a nasty security issue. On T

Re: [clamav-users] ON-ACCESS MONITORING

2024-04-29 Thread Paul Kosinski via clamav-users
"I'm not familiar with KMail." Kmail is KDE's standard email client/MUA (like e.g., Thunderbird), while Sendmail is one of the earliest SMTP email servers/MTAs (like e.g., Postfix). So they are quite different pieces of software. Paul P.S. I use ClamAV with Postfix (but not with a milter inter

[clamav-users] An example of why ClamAV should be able to scan disk images (which are typically over 2 GB)

2024-01-05 Thread Paul Kosinski via clamav-users
CVE-2021-44879 Wenqing Liu reported a NULL pointer dereference in the f2fs implementation. An attacker able to mount a specially crafted image ^^^ can take advantage of this flaw for denial of service. >From "Debian S

Re: [clamav-users] Question About MaxFileSize / news of upcoming Large Archive Scanner tool

2023-11-13 Thread Paul Kosinski via clamav-users
Large archive files may be the most obvious case, especially if things like disk images and installation images are included, but make sure that large multimedia files are also handled. In today's Internet environment, there are probably far, far more large video files floating around than trad

Re: [clamav-users] first questioon????

2023-10-25 Thread Paul Kosinski via clamav-users
On Wed, 25 Oct 2023 17:18:46 +0100 (BST) Andrew C Aitchison via clamav-users wrote: > On Sun, 22 Oct 2023, Rahim Fakir via clamav-users wrote: > > > I would like to know if it is possible to have clamav on the desktop and > > remotely scan the phone. > > for example: clamscan -r -i remove=yes ip

Re: [clamav-users] Question About MaxFileSize

2023-06-09 Thread Paul Kosinski via clamav-users
You are right. But more than that, merely *reading* a file will exercise such code. I wonder if anybody has devised a file which exploits such a kernel bug? (Shudder.) After I wrote my objection, I realized that to be even more safe, one should scan removable disks at the block level before mou

Re: [clamav-users] Question About MaxFileSize

2023-06-09 Thread Paul Kosinski via clamav-users
I must say I strongly disagree with the approach of feeding files contained in a big archive file one at a time to ClamAV. That's because an archive is *itself* a file. I have on occasion heard of vulnerabilities in some archiving software, where the mere act of decompressing and extracting an

Re: [clamav-users] End of life (EOL) policy change, 0.103 one year extension, 0.105 past end of life

2023-05-18 Thread Paul Kosinski via clamav-users
On Tue, 16 May 2023 20:32:56 + "Micah Snyder (micasnyd)" wrote: > Hi Paul, > > Unlike Java or C#, Rust does not have any additional runtime library > requirement. > > Regards, > Micah > > > Micah Snyder > ClamAV Development > Talos > Cisco Systems, Inc. I'm somewhat surprised Rust doe

Re: [clamav-users] End of life (EOL) policy change, 0.103 one year extension, 0.105 past end of life

2023-05-08 Thread Paul Kosinski via clamav-users
Micah, Great decision! I was worried about needing Rust on some of our systems. Not only for compiling, but doesn't Rust also need its own run time libraries? I'm still trying to figure out how to move from iptables to nftables, so not having also to use Rust "immediately" is a relief. (They

Re: [clamav-users] Be wary of emails with attachments targeting clamav-users list members

2023-03-22 Thread Paul Kosinski via clamav-users
I have just started getting these claiming to be relevant to ClamAV, but I have *also* been receiving this sort of thing claiming to be from the Firefox ESR list for months now. I am posting (one of) the HTMLs "about" ClamAV to https://www.clamav.net/reports/malware. Should I also post (one of)

Re: [clamav-users] The database server doesn't have the latest patch

2023-03-16 Thread Paul Kosinski via clamav-users
My main point (which wasn't emphasized enough) was that one of the Cloudflare "anycast" mirrors (my local one, "BOS"), which host the ClamAV files, was often missing the *latest* version of the daily signature file. So I wondered if the same kind of Cloudflare problem might be affecting you. I

Re: [clamav-users] The database server doesn't have the latest patch

2023-03-15 Thread Paul Kosinski via clamav-users
A few years ago, when I was attempting local mirroring, I was having a recurring problem with my local Cloudflare "anycast" server ("BOS"). I wonder if you might be having a similar problem. I was running a crontab triggered procedure a few times an hour which would do a DNS TXT query to see wh

Re: [clamav-users] ClamAV 0.103.8, 0.105.2 and 1.0.1 patch versions published

2023-02-20 Thread Paul Kosinski via clamav-users
I am using ClamAV 0.103.6 on Buster, but I have always built it from source (since way before Cisco and even SourceFire), hence I'm a bit obsolete. I did this -- and still do it -- because ClamAV has always been a bit experimental. Thus I install each version under "/opt/clamav.d/version" so I

Re: [clamav-users] Subject: behaviour of clamAV with password protected pdf file.

2023-02-14 Thread Paul Kosinski via clamav-users
Compared to the following, encrypted PDFs are a very minor issue (in my opinion). Most websites these days use HTTPS ("for security"), and make extensive use of Javascript (find a site that doesn't). This means that browsers are always executing code that can't be scanned (at least by ClamAV).

Re: [clamav-users] About scanning files larger than 2 GB in size

2023-01-26 Thread Paul Kosinski via clamav-users
I don't think I implied that the 2 GiB limit was "artificial" in the sense of trivial, or made up. I think I very clearly stated that "It's a holdover from when 32-bit numbers were all that CPUs supported" and now "the 2 GiB limit is quite an anachronism". Note that this question has been around

Re: [clamav-users] About scanning files larger than 2 GB in size

2023-01-21 Thread Paul Kosinski via clamav-users
On Sun, 22 Jan 2023 05:40:18 +0900 Tsutomu Oyamada wrote: > How do I set up clamd? > Setting MaxFileSize to "0" is unlimited, but internally files larger than 2GB > in size cannot be scanned. > In this case, do you treat the file as clean without scanning it at all? I've complained about the

Re: [clamav-users] Anyone else having trouble reaching the ClamAV website?

2023-01-06 Thread Paul Kosinski via clamav-users
I occasionally see a similar message from sites other than clamav.net saying something equivalent to Cloudflare's "review the security of your connection". The phrasing is pure gaslighting. It isn't for *connection* security -- HTTPS provides *that*. What it really means is that the site is tryi

Re: [clamav-users] Inquire about clamav latest stable version -

2022-08-01 Thread Paul Kosinski via clamav-users
On Thu, 28 Jul 2022 17:38:20 -0400 Joel Esler wrote: > ClamAV is a Cisco project. There’s no arguing that. > > All of the original team are observed here: https://www.clamav.net/about > > So, not sure what you’re getting at. The phrase "*the* authors of the software" rather implies that Ci

Re: [clamav-users] No daily sig since July 28th

2022-08-01 Thread Paul Kosinski via clamav-users
On Mon, 1 Aug 2022 16:24:50 +0100 (BST) Andrew C Aitchison via clamav-users wrote: > On Mon, 1 Aug 2022, Shawn Iverson via clamav-users wrote: > > > Hello, > > > > I've noticed that a daily hasn't been posted since the 28th of July. Are > > daily sigs being posted? > > # clamscan --version >

Re: [clamav-users] Inquire about clamav latest stable version -

2022-07-28 Thread Paul Kosinski via clamav-users
> At the moment three versions are officially supported by Cisco's Talos, the > authors of the software. Cisco's Talos are the *current* authors of the software. ClamAV was started in 2001 by Tomasz Kojm and a group of Open Source enthusiasts. In 2007, they sold the software to Sourcefire (of S

[clamav-users] ClamAV's 'configure' doesn't seem to complain about invalid options

2022-07-21 Thread Paul Kosinski via clamav-users
Building 0.103.6, I ran 'configure' with the option "--disable-clamonaccess" (instead of "--disable-clamonacc") and got no error or warning that the option was not recognized. I did this because I realized that I had still been using the old "--disable-clamuko", which also had no effect, and g

Re: [clamav-users] clamdscan: Output detailed scan results to STDOUT or to configurable file?

2022-02-17 Thread Paul Kosinski via clamav-users
On Thu, 17 Feb 2022 14:08:45 +0100 An Schall via clamav-users wrote: > When using clamdscan, I would like to have verbose output logged to a > file. Specifically, the timestamp, file path and file name as well as > the scan results should be logged to a specified file. > > In comparison, clamsca

Re: [clamav-users] ClamAV 0.103.5 and 0.104.2 security patch release; 0.102 past EOL

2022-01-16 Thread Paul Kosinski via clamav-users
On Wed, 12 Jan 2022 20:12:42 + "Micah Snyder \(micasnyd\) via clamav-users" wrote: > Find this announcement online at: > https://blog.clamav.net/2022/01/clamav-01035-and-01042-security-patch.html > > > ClamAV versions 0.103.5 and 0.104.2 are now available for download on the > clamav.net

Re: [clamav-users] Problem installing ClamAV 104.1 on CentOS 7

2021-12-06 Thread Paul Kosinski via clamav-users
On Mon, 6 Dec 2021 16:41:51 -0500 Bowie Bailey via clamav-users wrote: > I followed the instructions to install the prerequisites and then went > through the > steps for the default build.  Everything went fine until I got to the last > step. > > $ sudo cmake --build . --target install > sudo

Re: [clamav-users] Fail to download source archive with 403 forbitten

2021-11-17 Thread Paul Kosinski via clamav-users
On Mon, 15 Nov 2021 13:23:49 + "Joel Esler \(jesler\) via clamav-users" wrote: > On Nov 14, 2021, at 19:11, Yasuhiro Kimura > mailto:y...@utahime.org>> wrote: > > These results means server checks User-Agent header of HTTP request > and returns 403 forbitten if the value doesn't look like t

Re: [clamav-users] Clam updates failing

2021-10-23 Thread Paul Kosinski via clamav-users
On Fri, 22 Oct 2021 18:47:01 + "Joel Esler (jesler)" wrote: > > On Oct 22, 2021, at 14:16, Paul Kosinski via clamav-users > > wrote: > > > > On Fri, 22 Oct 2021 13:27:46 + > > "Joel Esler \(jesler\) via clamav-users" > > wrote

Re: [clamav-users] Clam updates failing

2021-10-22 Thread Paul Kosinski via clamav-users
On Fri, 22 Oct 2021 13:27:46 + "Joel Esler \(jesler\) via clamav-users" wrote: > > On Oct 21, 2021, at 18:55, Kenneth Porter wrote: > > > > On 10/21/2021 10:14 AM, Paul Kosinski via clamav-users wrote: > >> I've never seen a DNS age warni

Re: [clamav-users] Clam updates failing

2021-10-22 Thread Paul Kosinski via clamav-users
On Thu, 21 Oct 2021 15:55:54 -0700 Kenneth Porter wrote: > On 10/21/2021 10:14 AM, Paul Kosinski via clamav-users wrote: > > I've never seen a DNS age warning, but that might be because, for several > > years now, I only run freshclam when the DNS TXT record (which I che

Re: [clamav-users] Clam updates failing

2021-10-21 Thread Paul Kosinski via clamav-users
On Thu, 21 Oct 2021 10:20:58 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Thu, 21 Oct 2021, Ben Argyle via clamav-users wrote: > > > Has anyone been having trouble downloading updates for the last 20 > > hours or so? ... > > Yesterday I saw a couple of warnings abou

Re: [clamav-users] QNAP Antivirus Updates

2021-09-21 Thread Paul Kosinski via clamav-users
weird, given the use of Anycast). So I tested it the best I could (without traveling a lot, or setting up VMs in different countries). On Tue, 21 Sep 2021 13:21:20 +0200 Matus UHLAR - fantomas wrote: > >On Mon, 20 Sep 2021 17:17:34 + > >"Joel Esler (jesler)&qu

Re: [clamav-users] QNAP Antivirus Updates

2021-09-20 Thread Paul Kosinski via clamav-users
On Mon, 20 Sep 2021 17:17:34 + "Joel Esler (jesler)" wrote: > > On Sep 20, 2021, at 13:08, Paul Kosinski via clamav-users > > wrote: > > > > These two IPs are Anycast addresses, and have been unchanged for well over > > 2 years. (Anycast ad

Re: [clamav-users] QNAP Antivirus Updates

2021-09-20 Thread Paul Kosinski via clamav-users
On Mon, 20 Sep 2021 08:18:01 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Sun, 19 Sep 2021, Gregory Poveda via clamav-users wrote: > > > I have several QNAPs > > It might be worth searching for 'QNAP' in the list archives. At least > some of those devices will strug

[clamav-users] Virus DB updates?

2021-09-19 Thread Paul Kosinski via clamav-users
I haven't seen any virus database update since the afternoon of Thu 16 Sep 2021, when it was updated to 26297. Are updates really this stagnant, or does the DNS TXT record at "current.cvd.clamav.net" no longer reflect the state of things? (For a bit more bandwidth savings, I only run freshclam

Re: [clamav-users] IP List for Virus Definition Domain

2021-09-15 Thread Paul Kosinski via clamav-users
When I do a DNS lookup I also get: 104.16.218.84 104.16.219.84 This is the same result that I got well over a year ago, when I had to add these IP addresses as holes in my firewall so that my normally isolated internal server could update its ClamAV instance. These are Anycast addresses, s

Re: [clamav-users] error code 429

2021-09-05 Thread Paul Kosinski via clamav-users
On Sun, 5 Sep 2021 18:27:09 + "Joel Esler (jesler)" wrote: > Now? - All 3 systems updated successfully as soon as our DNS TXT test said the 26285 update was available (see below). This is again as it is almost every time since the download limiting mechanism s

Re: [clamav-users] error code 429

2021-09-05 Thread Paul Kosinski via clamav-users
On Sun, 5 Sep 2021 02:45:25 + "Joel Esler \(jesler\) via clamav-users" wrote: > We are experimenting with a feature that we’ve been working with Cloudflare > on, trying to isolate violators on a per host basis for the newest versions > of ClamAV, instead of IP. - Maybe what we have se

Re: [clamav-users] error code 429

2021-09-04 Thread Paul Kosinski via clamav-users
On Sat, 4 Sep 2021 15:01:00 +0100 Paul Netpresto via clamav-users wrote: > Hi all > > Similar issue from Manchester UK. 4 mx's  all failing to collect today's > update apparently first available 9:50 am today Not rate limited (as we only check about once per hour, from each of 3 systems), bu

Re: [clamav-users] ClamAV® blog: Changes to ClamAV end-of-life policy and a new Long Term Support policy

2021-09-03 Thread Paul Kosinski via clamav-users
LTS is great! Earlier this year it seemed like I was spending 1 day per week trying to keep up with ClamAV updates, lockouts etc. Now I have time to do more forward looking software work. On Fri, 3 Sep 2021 15:52:10 + "Joel Esler \(jesler\) via clamav-users" wrote: > > > > https://blog.c

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-25 Thread Paul Kosinski via clamav-users
On Tue, 24 Aug 2021 23:08:52 + "Micah Snyder (micasnyd)" wrote: > This conversation is a fun read! But don't worry really no point removing > the docs from the source package or the pre-compiled packages. Including it > is painless at this point. If you're curious why, here's the process

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-24 Thread Paul Kosinski via clamav-users
On Tue, 24 Aug 2021 10:48:48 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Mon, 23 Aug 2021, Paul Kosinski via clamav-users wrote: > > > On Sun, 22 Aug 2021 14:42:06 + > > "Joel Esler via clamav-users" wrote: > >

Re: [clamav-users] Yara regular expression finds only first match in ClamAV ?

2021-08-22 Thread Paul Kosinski via clamav-users
On Sun, 22 Aug 2021 20:10:00 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Sun, 22 Aug 2021, Richard Graham via clamav-users wrote: > > On Sun, Aug 22, 2021 at 10:41 AM Zvi Kave wrote: > >> On 8/19/2021 9:33 PM, G.W. Haywood via clamav-users wrote: > >>> On Thu, 19 Au

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Second Release Candidate is here!

2021-08-22 Thread Paul Kosinski via clamav-users
On Sun, 22 Aug 2021 14:42:06 + "Joel Esler \(jesler\) via clamav-users" wrote: > I’m a fan of the thought of removing the user manual completely from the > downloaded packages and including a link to docs.ClamAV.net. Since that’s > more dynamic. I think that's a bad idea for three reas

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-08-03 Thread Paul Kosinski via clamav-users
On Tue, 3 Aug 2021 07:53:24 +0200 Damian via clamav-users wrote: > > The current "stable" Debian is 10/Buster. It has ClamAV 0.103.2, patched by > > Debian to "deb10u1" (whatever that implies) > > https://security-tracker.debian.org/tracker/source-package/clamav Interesting, but *much* more

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-08-02 Thread Paul Kosinski via clamav-users
On Sat, 31 Jul 2021 20:32:23 +0200 Matus UHLAR - fantomas wrote: > can't count on Debian? They are very conservative, which is usually nice. But for security software, not so nice. The current "stable" Debian is 10/Buster. It has ClamAV 0.103.2, patched by Debian to "deb10u1" (whatever that i

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-31 Thread Paul Kosinski via clamav-users
On Sat, 31 Jul 2021 02:37:53 + "Joel Esler (jesler)" wrote: > > On Jul 30, 2021, at 14:41, Paul Kosinski via clamav-users > > wrote: > > > > (I don't see exactly how a LTS would have helped with the bandwidth issue, > > but I suppose

Re: [clamav-users] Opinion wanted: Change default config directory usr/clamav

2021-07-31 Thread Paul Kosinski via clamav-users
On Sat, 31 Jul 2021 12:03:36 + "Micah Snyder \(micasnyd\) via clamav-users" wrote: > Hi all, > > I could use your opinion about a change we'd planned to make in 0.104. By > request, I'd made this pull request to change the default directory for the > config files from /etc to /etc/clamav.

Re: [clamav-users] [OT] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-30 Thread Paul Kosinski via clamav-users
On Thu, 29 Jul 2021 23:33:02 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Thu, 29 Jul 2021, Paul Kosinski via clamav-users wrote: > > > ... do any firewall distros address inter-LAN filtering? > > We're well off-topic here so

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-30 Thread Paul Kosinski via clamav-users
LTS sounds like a great idea! Recently, the bandwidth hogging episodes have resulted in rapid changes to ClamAV versions, followed by EOL of versions that many people (not including me) were still using. So recently I have had to spend far more time on updating ClamAV than updating anything els

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-29 Thread Paul Kosinski via clamav-users
On Thu, 29 Jul 2021 08:52:57 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Maybe there's no need to worry about that. I've seen cases where the > build process looks for a shared object, finds a 32 bit version when > it's building for 64 bit, and then complains that it doesn't exist. > It

Re: [clamav-users] [OT] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-29 Thread Paul Kosinski via clamav-users
On Wed, 28 Jul 2021 12:53:38 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > I'd recommend not using any big distro for your perimiter firewall. > I use one of the purpose-built stripped-down firewall distributions. "..our home firewall and gateway -- with iptables, multi-LAN routing (with

Re: [clamav-users] [OT] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-29 Thread Paul Kosinski via clamav-users
On Wed, 28 Jul 2021 23:31:05 +1000 "Gary R. Schmidt" wrote: > I second what Ged is saying here, for firewalls and so on the Raspberry > Pi and its ilk are a much better choice than a full-on system, they use > /much/ less power, and keeping a spare or three isn't a board- (or > wife-) level bu

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-28 Thread Paul Kosinski via clamav-users
On Wed, 28 Jul 2021 09:59:14 +0200 Matus UHLAR - fantomas wrote: > a bit OT, but I upgrade debian servers for years in a short steps, combining > > "apt-get upgrade" so only safe packages are upgraded > and manual upgrades a few at once via aptitude > (so packages with complicated dependencies a

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-27 Thread Paul Kosinski via clamav-users
On Tue, 27 Jul 2021 16:41:03 +0100 Mark Fortescue via clamav-users wrote: > Hi Joel, > > One quick answer to why people do not upgrade the OS is that the > hardware does not support the upgrade (mostly due to memory and x86_64). > > I work with embedded systems where the code is very specific

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-27 Thread Paul Kosinski via clamav-users
On Tue, 27 Jul 2021 15:30:05 + "Joel Esler (jesler)" wrote: > You can’t support everything, forever. When you are part of critical infrastructure -- as computers have become -- you must. (Well, not quite forever.) Compare the rollout of IPv6 with the rollout of x86_64 (not to mention the

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-27 Thread Paul Kosinski via clamav-users
On Mon, 26 Jul 2021 11:35:29 -0400 "Rick Cooper" wrote: > And what, exactly, is the reason for moving to cmake? I am sure you know > it's going to be problematic for thousands of people so I am curious what > tremendous gain of speed, size, memory usage or seciurity the other users > get from thi

Re: [clamav-users] Freshclam updates problem

2021-07-14 Thread Paul Kosinski via clamav-users
On Wed, 14 Jul 2021 23:55:06 + "Micah Snyder \(micasnyd\) via clamav-users" wrote: > Hi Paul, all: > > We're triaging this issue now, also reported by a user on Discord. > > We issue a zero-byte CDIFF database patch file whenever we want Freshclam to > download a whole CVD instead of doin

Re: [clamav-users] New Main & Daily CVD's are incoming

2021-07-13 Thread Paul Kosinski via clamav-users
On Tue, 13 Jul 2021 14:05:53 + "Joel Esler \(jesler\) via clamav-users" wrote: > Tomorrow, Wednesday July 14th, we are planning on publishing a brand new > main.cvd and daily.cvd, as we do periodically to move more of the long term > signatures into the main.cvd and make the daily.cvd small

[clamav-users] Fw: openSUSE-SU-2021:2242-1: important: Security update for clamav-database

2021-07-05 Thread Paul Kosinski via clamav-users
Just FYI: this is the first time I remember seeing openSUSE notifying something about ClamAV. Begin forwarded message: Date: Mon, 5 Jul 2021 15:17:01 +0200 (CEST) From: opensuse-secur...@opensuse.org To: opensuse-security-annou...@opensuse.org Subject: openSUSE-SU-2021:2242-1: important: Secur

Re: [clamav-users] Help about Clamava on QNAP

2021-05-06 Thread Paul Kosinski via clamav-users
All these stories about QNAP (etc.) make me glad that I build my own servers, rather than getting some easy-to-setup, but non-upgradable, box. (E.g., I'm running 0.103.2, at the minor cost of having to build it from source.) On Thu, 6 May 2021 13:18:20 +0100 (BST) "G.W. Haywood via clamav-users

Re: [clamav-users] Help, we are still seeing issues

2021-04-18 Thread Paul Kosinski via clamav-users
You're comparing daily.CLD with main.CVD: as I understand it, CVDs are compressed, CLDs aren't. On Sat, 17 Apr 2021 21:15:29 +0200 (CEST) "Robert M. Stockmann via clamav-users" wrote: > Here's the freshclam virus data files which were first downloaded when > i upgraded to 0.103.2 : > >[hu

Re: [clamav-users] Heuristics.Broken.Media.JPEG.JFIFdupAppMarker

2021-04-17 Thread Paul Kosinski via clamav-users
It's worse than that. Not only do almost all users ignore security (as do many organizations), it seems that every new piece or version of software or hardware *reduces* security. And this applies to some new protocols (remember WiFi's WEP debacle?) and some extensions to or uses of existing one

Re: [clamav-users] Last ClamAV compatible with x32

2021-04-12 Thread Paul Kosinski via clamav-users
I have sometimes been able to find older RPMs for various system components at rpm.pbone.net, but it can be tedious. On Mon, 12 Apr 2021 15:10:01 -0500 "J.R. via clamav-users" wrote: > > I've made some investigation and the people on google says that this > > is a BUG with zlib, and the last zl

Re: [clamav-users] Scanning a large file through HTTP

2021-04-07 Thread Paul Kosinski via clamav-users
Seems to me that this behavior, advertising a 4GB limit while silently imposing a 2GB limit and reporting "OK" for anything in between, is a *major* security flaw: ClamAV *must* report that the file was too big to deal with (however worded). Thus I've taken to using clamscan rather than clamdsc

Re: [clamav-users] Private Mirror Via Artifactory

2021-03-12 Thread Paul Kosinski via clamav-users
On Fri, 12 Mar 2021 15:47:02 + (GMT) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Fri, 12 Mar 2021, Arjen de Korte via clamav-users wrote: > > > Citeren "G.W. Haywood via clamav-users" : > > > >> I think the OP was saying that he's not allowed to do that. ... > > > > I see

Re: [clamav-users] Unable to download clamav cvd file using google cloud python function

2021-03-10 Thread Paul Kosinski via clamav-users
clamav-users > mailto:clamav-users@lists.clamav.net>> wrote: > > > > On Mar 10, 2021, at 12:31 PM, Paul Smith via clamav-users > mailto:clamav-users@lists.clamav.net>> wrote: > > On 10/03/2021 17:00, Paul Kosinski via clamav-users wrote: > I wonde

Re: [clamav-users] looks like I have a problem too

2021-03-10 Thread Paul Kosinski via clamav-users
I wrote a little script that run off cron every hour or so. But it *only* invokes freshclam after querying ClamAV's DNS TXT record to see if any advertised versions of 'daily', 'bytecode' or 'main' are newer than the local versions of the CVD files, as determined by 'head', not the files' timest

Re: [clamav-users] Unable to download clamav cvd file using google cloud python function

2021-03-10 Thread Paul Kosinski via clamav-users
I wonder how many "ordinary" users of ClamAV are giving up on using it after getting permanent 403s. I would imagine there are lots of people who don't pursue the issue. They may even tell others that ClamAV is unreliable (which would tarnish its reputation). On Wed, 10 Mar 2021 11:58:13 +

Re: [clamav-users] Freshclam network unreachable

2021-03-09 Thread Paul Kosinski via clamav-users
"Out of procedural curiosity, why would someone want to disable ipv6?" Although our FIOS connection supports IPv6, our firewall/gateway complex, which I custom built from scratch 16+ years ago using iptables etc., doesn't. Since this firewall/gateway also does lots of inter-LAN routing and block

Re: [clamav-users] ClamAV not even mentioned in article "The 6 Best Antiviruses for Linux 2021"

2021-02-19 Thread Paul Kosinski via clamav-users
21 21:02:08 + "Joel Esler (jesler)" wrote: > This is what happens when you don’t pay people for SEO. > > Sent from my  iPhone > > > On Feb 19, 2021, at 12:10, Paul Kosinski via clamav-users > > wrote:

[clamav-users] ClamAV not even mentioned in article "The 6 Best Antiviruses for Linux 2021"

2021-02-19 Thread Paul Kosinski via clamav-users
https://www.safetydetectives.com/best-antivirus/linux/ ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-fa

Re: [clamav-users] What are all the tmp.xyzuvwpqrs subdirs that keep accumulating

2021-02-11 Thread Paul Kosinski via clamav-users
7 + (GMT) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Thu, 11 Feb 2021, Paul Kosinski via clamav-users wrote: > > > in my clamav.0.103.0/share/clamav/ directory? > > > > They don't seem to

[clamav-users] What are all the tmp.xyzuvwpqrs subdirs that keep accumulating

2021-02-11 Thread Paul Kosinski via clamav-users
in my clamav.0.103.0/share/clamav/ directory? They don't seem to have been there with clamav.0.102.0 and earlier. ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a compr

Re: [clamav-users] [When was 0.103.1 announced on *this* list?

2021-02-09 Thread Paul Kosinski via clamav-users
my  iPad > > > On Feb 9, 2021, at 10:14, Paul Kosinski via clamav-users > > wrote: > > > > I save all the ClamAV mail, and couldn't find an announcement. ___ clamav-users mailing list clamav-users@lists.clamav.ne

[clamav-users] When was 0.103.1 announced on *this* list?

2021-02-09 Thread Paul Kosinski via clamav-users
I save all the ClamAV mail, and couldn't find an announcement. ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/

Re: [clamav-users] Terminate clamscan after specific time

2021-01-06 Thread Paul Kosinski via clamav-users
The problem with only scanning files that have changed since they were last scanned is that there usually have been virus signature updates in the meantime. So you could have an "old" file that contains what was a zero-day virus at the time it was scanned, and now there is a signature that would de

Re: [clamav-users] Is there anything to do about encrypted viruses?

2020-12-22 Thread Paul Kosinski via clamav-users
Since the password has to be included for the victim to be able to decrypt, it ought to be possible to automatically find the password in the email. Of course, eventually the criminals will start hiding the password in some way that a human can easily find it, but non-AI automation can't. On Tue,

Re: [clamav-users] local server takes time to update clamav db

2020-12-13 Thread Paul Kosinski via clamav-users
27; values sound like they might be particularly relevant. On Mon, 14 Dec 2020 02:57:48 + "Joel Esler \(jesler\) via clamav-users" wrote: > Both of those things are done as well. > > Sent from my  iPhone > > > On Dec 13, 2020, at 19:24, Dave Warren via clamav-user

Re: [clamav-users] PR: Removing PidFile

2020-12-12 Thread Paul Kosinski via clamav-users
I agree. I don't run ClamAV from systemd, and I wouldn't be pleased to have to spend time changing my scripts "just because". P.S. I do run other things from systemd -- if the OS set them up that way -- and I do appreciate the parallelism: it saves a few minutes of start-up time when I reboot ever

Re: [clamav-users] local server takes time to update clamav db

2020-12-11 Thread Paul Kosinski via clamav-users
"The whole CVD filename is not versioned (always "daily.cvd") which is why the CloudFlare caching issue may result in serving the previous version." HTML filenames for Web pages are not versioned either. Does this mean that CDNs like Cloudflare often serve up obsolete Web pages? If so, does nobody

Re: [clamav-users] local server takes time to update clamav db

2020-12-11 Thread Paul Kosinski via clamav-users
Does ClamAV (Talos?) check *all* the Cloudflare anycast servers? I thought it could only check those "near" to ClamAV POPs. On Thu, 10 Dec 2020 18:00:15 + "Joel Esler (jesler)" wrote: > > On Dec 10, 2020, at 11:58 AM, Paul Kosinski via clamav-users > >

Re: [clamav-users] local server takes time to update clamav db

2020-12-10 Thread Paul Kosinski via clamav-users
With regard to "sleep for awhile". I remember that Cloudflare's BOS server on occasion remained behind the latest CVD version (according to the DNS TXT record) for more than one hour! Might the following be possible instead? I would imagine that Cloudflare has a means of fetching a specific file

Re: [clamav-users] local server takes time to update clamav db

2020-12-09 Thread Paul Kosinski via clamav-users
"This is one of the IPs which I was expecting to see. I wouldn't expect any problems with it, our ClamAV server updated from it at 1818 GMT last night." Unfortunately, given the way Cloudflare works, the IP address (e.g., 104.16.218.84) isn't the whole story. A particular Anycast IP address such

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-04 Thread Paul Kosinski via clamav-users
ot;segments", "sequences", "pieces"? On Wed, 4 Nov 2020 17:49:09 + "Micah Snyder (micasnyd)" wrote: > Do you reckon folks will be less confused if it rounds up? > > -Micah > > On 11/3/20, 1:37 PM, "clamav-users on behalf of Paul K

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-03 Thread Paul Kosinski via clamav-users
ys 1 > disk sector. > > Can you not just round up by adding (BlockSize - 1) bytes when setting > the block variables ? > > Regards > Mark. > > On 03/11/2020 16:07, Paul Kosinski via clamav-users wrote: > > "This is a display problem, not a storag

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-03 Thread Paul Kosinski via clamav-users
0 17:44:18 +1100 "Gary R. Schmidt" wrote: > On 03/11/2020 16:00, Paul Kosinski via clamav-users wrote: > > "(don't you love C?)" > > > > I have never understood why the originators of C didn't give integers > > explicit widths in bits: their sc

[clamav-users] Clamd.exe -- excluding files when scanning

2020-11-02 Thread Paul Kosinski via clamav-users
I'm not a big Windows fan, but it sounds like ClamAV regexes are rather unfriendly to Windows since they don't seem to have an "ignore case" option (unlike most other regex-using programs). Assuming that is the case (sic), you might try: ExcludePath "[Cc]:\\[Ww][Ii][Nn][Dd][Oo][Ww][Ss]" as a s

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-02 Thread Paul Kosinski via clamav-users
where an unsigned long is 4 bytes, then that'd cap the scan limit > at 4GB. Changing the variable to be an uint64_t would be "best", but it > would be a non-backwards compatible change to the API which is very much not > worth it. > > Sigh :-/ > > >

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-02 Thread Paul Kosinski via clamav-users
data scanned/read output. > > -Micah > > On 11/2/20, 9:47 AM, "clamav-users on behalf of G.W. Haywood via > clamav-users" clamav-users@lists.clamav.net> wrote: > > Hi there, > > On Mon, 2 Nov 2020, Paul Kosinski via clamav-users wrote: > >

Re: [clamav-users] ClamAV Scan - Data Read vs Data Scanned

2020-11-02 Thread Paul Kosinski via clamav-users
When I first saw this message, I quickly concluded it was a roundoff behavior. But I still think it is a bad message that should be fixed. First, most file managers that only display file sizes in "human readable" form, still display a non-zero size for small files. Second, it is not logically imp

Re: [clamav-users] ClamAV - Emotet - Malware not detected

2020-09-16 Thread Paul Kosinski via clamav-users
"Vaccine for Emotet Malware" at "Schneier on Security": https://www.schneier.com/crypto-gram/archives/2020/0915.html#cg2 On Wed, 16 Sep 2020 16:27:45 +0200 Brent Clark via clamav-users wrote: > Hiya > > Thanks so much. > > I know the community and the internet as a whole, stands to gain fro

Re: [clamav-users] ClamAV® blog: Freshclam, cdiffs and bandwidth are your friends

2020-07-28 Thread Paul Kosinski via clamav-users
"...we also only release updates once a day." Are there *never* any urgent virus updates released in between? In other words, is it always useless to check the TXT record more often? On Mon, 27 Jul 2020 22:09:31 + "Joel Esler \(jesler\) via clamav-users" wrote: > https://blog.clamav.net/2

Re: [clamav-users] clamscan vs clamdscan

2020-05-10 Thread Paul Kosinski via clamav-users
clamav-users" wrote: > Hi there, > > On Sat, 9 May 2020, Paul Kosinski via clamav-users wrote: > > > On our mailserver, we run clamdscan, since mail arrives frequently (!). > > On a mail server most people would use a milter, e.g. clamav-milter, > which is pa

Re: [clamav-users] clamscan vs clamdscan

2020-05-09 Thread Paul Kosinski via clamav-users
On our mailserver, we run clamdscan, since mail arrives frequently (!). On my workstation, I have switched to just using clamscan. Clamdscan now uses so much resident memory (~ 1 GB), that even on my 32 GB workstation I found it unreasonable to permanently tie up that much RAM when I only scan thi

Re: [clamav-users] Clamav with VPN

2020-05-05 Thread Paul Kosinski via clamav-users
g no clout with Cloudflare). On Tue, 5 May 2020 19:02:20 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Tue, 5 May 2020, Paul Kosinski via clamav-users wrote: > > >>> To try to solve this issue, i have added this line in my /e

Re: [clamav-users] Clamav with VPN

2020-05-05 Thread Paul Kosinski via clamav-users
> > To try to solve this issue, i have added this line in my /etc/hosts file : > > > > * 104.16.218.84 database.clamav.net > > Don't do things like that. Sooner or later it will break, and you'll > find yourself back here again asking why. Our firewall blocks our mail server from issuing req

Re: [clamav-users] ClamAV Server Agent

2020-04-23 Thread Paul Kosinski via clamav-users
W. Haywood via clamav-users" wrote: > Hi there, > > On Wed, 22 Apr 2020, Paul Kosinski via clamav-users wrote: > > > Your list includes a number of databases I haven't seen before. Could > > you provide a list of source sites that provide the DBs that you find &g

Re: [clamav-users] ClamAV Server Agent

2020-04-22 Thread Paul Kosinski via clamav-users
Your list includes a number of databases I haven't seen before. Could you provide a list of source sites that provide the DBs that you find most useful? Thanks! On Wed, 22 Apr 2020 18:43:47 +0100 (BST) "G.W. Haywood via clamav-users" wrote: > Hi there, > > On Wed, 22 Apr 2020, Karmendra Suth

Re: [clamav-users] ClamAV 0.102.2 needs a "--without-systemd" option

2020-04-20 Thread Paul Kosinski via clamav-users
You should be able to use `--with-systemdsystemunitdir=no` to make it > so that `make install` won't try to register clamd as a systemd > service > > -Andrew > > On Sun, Apr 19, 2020 at 1:26 PM Paul Kosinski via clamav-users < > clamav-users@lists.clamav.net> wro

  1   2   >