Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Gene Heskett
On Thursday 15 October 2015 12:19:19 Peter Bonivart wrote: > On Thu, Oct 15, 2015 at 5:55 PM, Gene Heskett wrote: > >> http://sanesecurity.co.uk/foxhole-databases/ > > > > Unfortunatly, nothing seems to be linked, the only thing I can save > > is the web page itself with either iceweasel or chro

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Peter Bonivart
On Thu, Oct 15, 2015 at 5:55 PM, Gene Heskett wrote: >> http://sanesecurity.co.uk/foxhole-databases/ > > Unfortunatly, nothing seems to be linked, the only thing I can save is > the web page itself with either iceweasel or chromium. And I did enable > cookies, in chromium, to no avail. That's ju

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Benny Pedersen
Gene Heskett skrev den 2015-10-15 17:32: Amanda will have them yet for about 29 more days. But they are very very old, with lots newer versions readily downloadable. so amanda is not usefull here Can freshclam be used to keep it up to date? If so, how? yes, but in case dns is spoffed yo

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Gene Heskett
On Thursday 15 October 2015 11:22:21 Steve Basford wrote: > http://sanesecurity.co.uk/foxhole-databases/ Unfortunatly, nothing seems to be linked, the only thing I can save is the web page itself with either iceweasel or chromium. And I did enable cookies, in chromium, to no avail. I am also

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Benny Pedersen
Gene Heskett skrev den 2015-10-15 17:27: Ok, but how do I keep clamscan from using it, when its clamdscan, scanning the incoming mail via this recipe in my .procmailrc add --official-db-only=yes to clamscan or for clamdscan search for this option in clamd.conf more info in man clamscan VI

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Gene Heskett
On Thursday 15 October 2015 11:15:54 Benny Pedersen wrote: > On October 15, 2015 5:04:36 PM Gene Heskett wrote: > > So they will be gone from tomoorows scan report. > > no backup ? Amanda will have them yet for about 29 more days. But they are very very old, with lots newer versions readily do

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Gene Heskett
On Thursday 15 October 2015 11:15:54 Benny Pedersen wrote: > On October 15, 2015 5:04:36 PM Gene Heskett wrote: > > So they will be gone from tomoorows scan report. > > no backup ? > > > Clamav user list, comments please? > > foxhole is 0day signatures, so you find files that match it in > localh

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Al Varnell
Yes, please try not to bring up any more UNOFFICIAL database issues here. -Al- On Thu, Oct 15, 2015 at 08:03 AM, Gene Heskett wrote: > > Clamav user list, comments please? > Cheers, Gene Heskett smime.p7s Description: S/MIME cryptographic signature _

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Steve Basford
On Thu, October 15, 2015 4:03 pm, Gene Heskett wrote: > Greetings everybody; > > > I added a new, not quite official database to my clamav checker, and this > morning its fussing about several files I have on my web page: > /var/www/html/gene/Genes-os9-stf/dw4_beta_1.4.tar.gz: > Sanesecurity.Foxh

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread J. Tozo
Hi, When you have "UNOFFICIAL" in the Clamav findings, means that a signature was created with a sigtool either for md5 or hex-dump and added manually in the .hdb or .ndb files. I strongly encourage you not to use any database you dont know, because the signatures may be written for a purpouse

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Steve Basford
On Thu, October 15, 2015 4:03 pm, Gene Heskett wrote: > Greetings everybody; > > > I added a new, not quite official database to my clamav checker, and this > morning its fussing about several files I have on my web page: > /var/www/html/gene/Genes-os9-stf/dw4_beta_1.4.tar.gz: > Sanesecurity.Foxh

Re: [clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Benny Pedersen
On October 15, 2015 5:04:36 PM Gene Heskett wrote: So they will be gone from tomoorows scan report. no backup ? Clamav user list, comments please? foxhole is 0day signatures, so you find files that match it in localhost does not mean its virus ___

[clamav-users] Interesting report from clamscan after adding new database

2015-10-15 Thread Gene Heskett
Greetings everybody; I added a new, not quite official database to my clamav checker, and this morning its fussing about several files I have on my web page: /var/www/html/gene/Genes-os9-stf/dw4_beta_1.4.tar.gz: Sanesecurity.Foxhole.Zip.UNOFFICIAL FOUND /var/www/html/gene/Genes-os9-stf/print4dw.