Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-15 Thread Henrik K
On Tue, Dec 15, 2009 at 12:16:52PM +0200, Jari Fredriksson wrote: > > > On 9.12.2009 20:13, Török Edwin wrote: > > On 2009-12-07 19:21, Sundara Kaku wrote: > >> Hi, > >> > >> I have a special requirement where I want to scan downloaded pages from > >> website for phishing detection, ex: i use ht

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-15 Thread Jari Fredriksson
On 9.12.2009 20:13, Török Edwin wrote: > On 2009-12-07 19:21, Sundara Kaku wrote: >> Hi, >> >> I have a special requirement where I want to scan downloaded pages from >> website for phishing detection, ex: i use httracker to download a website or >> wget to download a particular website and i wa

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Török Edwin
On 2009-12-11 22:08, Tom Shaw wrote: > At 9:31 PM +0200 12/11/09, Török Edwin wrote: >> On 2009-12-11 21:14, Tom Shaw wrote: >>> At 3:53 PM +0200 12/10/09, Török Edwin wrote: >> >> On 2009-12-10 15:41, Sundara Kaku wrote: >> The heuristic phishing detector only works on emails correctly, not >> w

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Tom Shaw
At 9:31 PM +0200 12/11/09, Török Edwin wrote: On 2009-12-11 21:14, Tom Shaw wrote: At 3:53 PM +0200 12/10/09, Török Edwin wrote: >> On 2009-12-10 15:41, Sundara Kaku wrote: The heuristic phishing detector only works on emails correctly, not websites by design, hence there is no point in runni

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Török Edwin
On 2009-12-11 21:14, Tom Shaw wrote: > At 3:53 PM +0200 12/10/09, Török Edwin wrote: >> On 2009-12-10 15:41, Sundara Kaku wrote: >>> Hi, >>> >>> As you mentioned "clamav would scan the mail".. means..can i add >>> downloaded webpage as attachment to email with (javamail api) and save >>> tha

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Tom Shaw
At 3:53 PM +0200 12/10/09, Török Edwin wrote: On 2009-12-10 15:41, Sundara Kaku wrote: Hi, As you mentioned "clamav would scan the mail".. means..can i add downloaded webpage as attachment to email with (javamail api) and save that mail as eml file and send this file for scanning.. is

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Jerry
On Fri, 11 Dec 2009 14:21:11 +0530 Sundara Kaku replied: > Can you pls provide the link to DB which holds unofficial sings, and > is there any automated way to retrieve and update the unofficial > signs..pls guide me > http://sanesecurity.com/download_scripts_linux.htm -- Jerry ges...@yahoo.c

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Sundara Kaku
On 2009-12-10 12:25, TR Shaw wrote: > > > > On Dec 10, 2009, at 6:24 AM, Török Edwin wrote: > > > On 2009-12-10 13:06, Sundara Kaku wrote: > >> Thanks for the reply, > >> > > > > However if all you want is detect phishing, the heuristic phishing > > detection won't work with webpages, it is design

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-10 Thread Török Edwin
On 2009-12-10 15:41, Sundara Kaku wrote: > Hi, > >As you mentioned "clamav would scan the mail".. means..can i add > downloaded webpage as attachment to email with (javamail api) and save > that mail as eml file and send this file for scanning.. > > is this practically possible, does clamav sc

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-10 Thread Sundara Kaku
Hi, As you mentioned "clamav would scan the mail".. means..can i add downloaded webpage as attachment to email with (javamail api) and save that mail as eml file and send this file for scanning.. is this practically possible, does clamav scans html attachments for phishing links and malicious

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-10 Thread TR Shaw
On Dec 10, 2009, at 6:24 AM, Török Edwin wrote: On 2009-12-10 13:06, Sundara Kaku wrote: Thanks for the reply, However if all you want is detect phishing, the heuristic phishing detection won't work with webpages, it is designed for phishing mails (which are different than the phishing w

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-10 Thread Török Edwin
On 2009-12-10 13:06, Sundara Kaku wrote: > Thanks for the reply, > > i am also looking for a way to scan the URLs present in webpages for > phishing detection. To scan URLs for phishing and malware links you can query google's safebrowsing DB yourself. I know there is perl module, there must sur

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-10 Thread Sundara Kaku
Thanks for the reply, i am also looking for a way to scan the URLs present in webpages for phishing detection. I can not use firefox as i want to automate the process of scanning by first download the website using httracker and then run my custom program to scan the download webpages for URLs tha

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-09 Thread Török Edwin
On 2009-12-07 19:21, Sundara Kaku wrote: > Hi, > > I have a special requirement where I want to scan downloaded pages from > website for phishing detection, ex: i use httracker to download a website or > wget to download a particular website and i want scan that webpage for > phishing detection. I

Re: [Clamav-users] Phishing detection

2006-02-17 Thread Oliver Stöneberg
> > ClamAV still doesn't ctach all variants of a Parite.B > > Please show me an active variant of Parite.B that is not detected by > ClamAV and at the same time is not a false positive detection of some > 3rd party scanners. > > Then I will owe you a beer ;-) Depends how you define "active". I

Re: [Clamav-users] Phishing detection

2006-02-17 Thread Tomasz Kojm
On Fri, 17 Feb 2006 19:55:20 +0100 "Oliver Stöneberg" <[EMAIL PROTECTED]> wrote: > ClamAV still doesn't ctach all variants of a Parite.B Please show me an active variant of Parite.B that is not detected by ClamAV and at the same time is not a false positive detection of some 3rd party scanners.

Re: [Clamav-users] Phishing detection

2006-02-17 Thread Oliver Stöneberg
> > Sites were hot at the time the messages were received, so either my concept > > of how ClamAV blocks phishing is wrong or the detection method is not as > > generic as I would have thought. > > > Generic fishing signature can be done... but... they are very difficult > to get right, without

Re: [Clamav-users] Phishing detection

2006-02-16 Thread Dennis Peterson
> > > > Can someone please tell me how ClamAV goes about phishing detection? I > > presume it has something to do with libcurl going out to a web site and > > some checks being performed on whatever is returned. > > > Not normally... most fishing detection is done by matching text/html > th

Re: [Clamav-users] Phishing detection

2006-02-16 Thread Harold Hartley
Steve Basford wrote: We have had several phishes get through -- most appear to be Google, About, or Ebay redirects, such as: href="http://www.google.com/url?sa=U&q=http://81.196.204.130:82/webscr/index.php"; (A PayPal phish.) Well, the above is just using Google to re-direct to the phis

Re: [Clamav-users] Phishing detection

2006-02-16 Thread Steve Basford
Can someone please tell me how ClamAV goes about phishing detection? I presume it has something to do with libcurl going out to a web site and some checks being performed on whatever is returned. Not normally... most fishing detection is done by matching text/html that is common, looks odd

RE: [Clamav-users] Phishing detection

2006-02-16 Thread Matthew.van.Eerde
Jon R. Kibler wrote: > Greetings, > > Can someone please tell me how ClamAV goes about phishing detection? > I presume it has something to do with libcurl going out to a web site > and some checks being performed on whatever is returned. No visiting of websites is done. A signature is written