Re: [Clamav-users] Running as User amavis

2003-12-01 Thread Sandy T. Santos
Wash said: >What is the $HOME of your clamav user? /root ??? >I got such an error once when the owner of that $HOME was different than >the "User amavis" directive (in your case). >I solved it by the amavis user has '/var/amavis' as its home directory. i also have a clamav user with '/home/clamav'

Re: [Clamav-users] Running as User amavis

2003-12-01 Thread Odhiambo Washington
* Sandy T. Santos <[EMAIL PROTECTED]> [20031201 10:22]: wrote: > Wash said: > >What is the $HOME of your clamav user? /root ??? > >I got such an error once when the owner of that $HOME was different than > >the "User amavis" directive (in your case). >

Re: [Clamav-users] Oversized Zip, again ...

2003-12-01 Thread Tomasz Papszun
On Fri, 28 Nov 2003 at 21:24:43 -0800, Chris Paul wrote: > On Fri, 28 Nov 2003 18:24:02 +0100 > Tomasz Papszun <[EMAIL PROTECTED]> wrote: > > > I have also seen stopped .doc files compressed with ratio 236. > > And .dbf files with ratio 1101. Also, .wav files with ratio 1182. > > > > Users send

[Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Michael V. Khaletsky
I had the same problems. All seems working but clamav-milter doesnt' produce output not to logs nor to e-mail headers. I rebuilt the whole Sendmail package with milter enabled. After that all works. For configuring the Sendmail with milter enabled You must read the instruction in file: [your sour

Re: [Clamav-users] Oversized Zip, again ...

2003-12-01 Thread Tomasz Klim
> On Fri, 28 Nov 2003 at 21:24:43 -0800, Chris Paul wrote: > > On Fri, 28 Nov 2003 18:24:02 +0100 > > Tomasz Papszun <[EMAIL PROTECTED]> wrote: > > > > > I have also seen stopped .doc files compressed with ratio 236. > > > And .dbf files with ratio 1101. Also, .wav files with ratio 1182. > > >

[Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Patrik
Richard, I have not generated a new /etc/mail/sendmail.cf Im not that familiar with sendmail, how do i generate a new one? Thanks, Patrik - Original Message - From: "Richard G. Roberto" <[EMAIL PROTECTED]> Newsgroups: gmane.comp.security.virus.clamav.user Sent: Monday, December 01, 2003

Re: [Clamav-users] Running as User amavis

2003-12-01 Thread Tomasz Kojm
On Tue, 2 Dec 2003 02:09:50 +0800 "Sandy T. Santos" <[EMAIL PROTECTED]> wrote: > hi, > > i've successfully compiled clamav-0.65 on my mandrake 8.2 but > everytime i start clamd i get this error. > > LibClamAV Error: cli_cvdload(): Can't create temporary > directory /root/tmp/45293e6f36fa5577 >

Re: [Clamav-users] Zip problems again

2003-12-01 Thread Tomasz Kojm
On Sat, 29 Nov 2003 17:16:07 + [EMAIL PROTECTED] (Sean Rima) wrote: > I am finding this after updating to today's cvs: > 003-11-29 17:13:56 1AQ8fM-00066n-1l malware acl condition: clamd: > ClamAV returned > /var/spool/exim/scan/1AQ8fM-00066n-1l/1AQ8fM-00066n-1l-1.com: > Zip module failur

RE: [Clamav-users] Autochecking script for clamd

2003-12-01 Thread Lynn Duerksen
> > > > > > Well, but why run freshclam all the time? > > > > > > > I suppose that I could have run a cron job. But in dealing > > Am I wrong in thinking this way? That: > > You are wasting your bandwidth running freshclam (well, at > some point the virus db files are up to date so no dat

Re: [Clamav-users] Autochecking script for clamd

2003-12-01 Thread Tomasz Kojm
On Mon, 1 Dec 2003 09:24:06 -0600 "Lynn Duerksen" <[EMAIL PROTECTED]> wrote: > I don't understand what you are getting at. My bandwidth is not an > issue at this time. If you are suggesting that I am wasting the > bandwidth and cpu time on the servers I download from, how would > checking for up

Re: [Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Odhiambo Washington
* Patrik <[EMAIL PROTECTED]> [20031201 17:25]: wrote: > Richard, > > I have not generated a new /etc/mail/sendmail.cf > Im not that familiar with sendmail, how do i generate a new one? hehee, time to drop Sendmail on the floor and get an easier to use MTA which does not requir

[Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Patrik
Richard, I have not generated a new /etc/mail/sendmail.cf. I not really familiar with sendmail.cf, how do I generate a new one? -Patrik "Richard G. Roberto" <[EMAIL PROTECTED]> skrev i meddelandet news:[EMAIL PROTECTED] Patrick, When you modified the sendmail.mc file, did you then use it to gen

Re: [Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Christopher X. Candreva
On Mon, 1 Dec 2003, Patrik wrote: > I have not generated a new /etc/mail/sendmail.cf. > I not really familiar with sendmail.cf, how do I generate a new one? Generally, m4 sendmail.cf == Chris Candreva -- [EMAIL PROTECTED] -- (914) 967-7

Re: [Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Jakub Jankowski
On 2003-12-01, Odhiambo Washington wrote: >* Patrik <[EMAIL PROTECTED]> [20031201 17:25]: wrote: >> Richard, >> >> I have not generated a new /etc/mail/sendmail.cf >> Im not that familiar with sendmail, how do i generate a new one? /usr/bin/m4 ../m4/cf.m4 config

[Clamav-users] Re: Zip problems again

2003-12-01 Thread Sean Rima
Tomasz Kojm writes: On Sat, 29 Nov 2003 17:16:07 + [EMAIL PROTECTED] (Sean Rima) wrote: I am finding this after updating to today's cvs: 003-11-29 17:13:56 1AQ8fM-00066n-1l malware acl condition: clamd: ClamAV returned /var/spool/exim/scan/1AQ8fM-00066n-1l/1AQ8fM-00066n-1l-1.com: Zip mod

[Clamav-users] Re: Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Patrik
Problems with clamav-milter + sendmail > On 2003-12-01, Odhiambo Washington wrote: > > >* Patrik <[EMAIL PROTECTED]> [20031201 17:25]: wrote: > >> Richard, > >> > >> I have not generated a new /etc/mail/sendmail.cf > >> Im not that familiar with s

Re: [Clamav-users] Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Richard G. Roberto
That's a good question. Usually, there is a README file in the "cf" subdirectory of the sendmail configuration (m4) sources that explains this for your platform. I don't know where this is on a debian system. Its in /usr/share/sendmail on FreeBSD. FreeBSD also has makefiles for everything a

[Clamav-users] Re: Re: Problems with clamav-milter + sendmail

2003-12-01 Thread Patrik
See my earlier just posted post :p I have successfully created a new sendmail.cf, but it seems to be the case clamav-milter doesnt grap mails with virus, though it says i the maillog that clamav adds a header in the mail saying it have been checked. -Patrik - Original Message - From: "Ri

[Clamav-users] CLAM 0.65 Not Identifying Anything

2003-12-01 Thread Adam Williams
Both CLAM 0.60 and Solo Antivirus identify the following file as bieng infected with W97/Marker. But since upgrading to CLAM 0.65, CLAM does not detect the infection; either as a regular file or as a mail attachment via clamav-milter. But the message - X-Virus-Scanned: ClamAV version 'clamd / Cl

Re: [Clamav-users] Oversized Zip, again ...

2003-12-01 Thread Tomasz Kojm
On Mon, 1 Dec 2003 11:20:39 GMT Tomasz Klim <[EMAIL PROTECTED]> wrote: > The right solution is to decompress files block-by-block, and scanning > only that block, like it is done for reading and scanning file from > a descriptor. But this requires direct integration of unzip and scan > code. I kno

Re: [Clamav-users] Process based clamd

2003-12-01 Thread Tomasz Kojm
On Sun, 30 Nov 2003 02:35:48 +0100 (CET) Jakub Jankowski <[EMAIL PROTECTED]> wrote: > On 2003-11-29, Tomasz Kojm wrote: > > >The current CVS code contains a new directive: UseProcesses that will > >cause clamd to use processes instead of threads. Initial version but > >seems to work ;) It should

[Clamav-users] ClamAV vs Commercial Products

2003-12-01 Thread Joshua French
Hello, I am trying to find out the difference(s) between ClamAV's virus db and any given commercial product. In the latter, I've noted that they have covered 70-80k viruses, whereas ClamAV has somewhere around 10k in its definitions. Is this an apples and oranges comparison? Does ClamAV's 10k n

Re: [Clamav-users] ClamAV vs Commercial Products

2003-12-01 Thread McKeever Chris
On 01 Dec 2003 14:00 , Joshua French <[EMAIL PROTECTED]> sent: >Hello, > >I am trying to find out the difference(s) between ClamAV's virus db and >any given commercial product. In the latter, I've noted that they have >covered 70-80k viruses, whereas ClamAV has somewhere around 10k in its >defi

Re: [Clamav-users] ClamAV vs Commercial Products

2003-12-01 Thread Daniel J McDonald
On Mon, 2003-12-01 at 14:00, Joshua French wrote: > Hello, > > I am trying to find out the difference(s) between ClamAV's virus db and > any given commercial product. In the latter, I've noted that they have > covered 70-80k viruses, whereas ClamAV has somewhere around 10k in its > definitions. >

[Clamav-users] using ClamAV on Windows

2003-12-01 Thread G. Jullien
Hi, I tried to use ClamAV on a standalone Win machine. I don't know if I can filter incoming and outgoing mail What should I install more ? Is it a good idea to try to use clamAV this way ? Or is this usage not the purpose for ClamAV ? I had no answer about this before, maybe this time thanks f

Re: [Clamav-users] using ClamAV on Windows

2003-12-01 Thread Brian Bruns
Right now, there is no programs to integrate clamav with windows based apps. I've got something in development, but its still a long ways away. -- Brian Bruns The Summit Open Source Development Group Open Solutions For A Closed World / Anti-Spam Resources http://www.sosdg.or

Re: [Clamav-users] Oversized Zip, again ...

2003-12-01 Thread Tomasz Kojm
On Fri, 28 Nov 2003 18:24:02 +0100 Tomasz Papszun <[EMAIL PROTECTED]> wrote: > I think that this parameter should be made runtime configurable (in > clamav.conf). Not every site compiles Clamav on its own. You can now setup the limit with ArchiveMaxCompressionRatio in clamav.conf. Best regards,

Re: [Clamav-users] CLAM 0.65 Not Identifying Anything

2003-12-01 Thread Thomas Lamy
Adam Williams wrote: Both CLAM 0.60 and Solo Antivirus identify the following file as bieng infected with W97/Marker. But since upgrading to CLAM 0.65, CLAM does not detect the infection; either as a regular file or as a mail attachment via clamav-milter. But the message - X-Virus-Scanned: ClamA