Re: [Clamav-users] No supported Database

2008-04-16 Thread Tomasz Kojm
On Wed, 16 Apr 2008 08:30:11 +0200 (CEST) [EMAIL PROTECTED] (Lanfranco Fabriani) wrote: > Is this necessary? In the years I never run freshclam before > restarting clamd and the software always ran very well. The server > of mine is a little mail server, so usually I try to switch off mimedefang >

Re: [Clamav-users] No supported Database

2008-04-16 Thread Brian Morrison
On Wed, 16 Apr 2008 08:30:11 +0200 (CEST) [EMAIL PROTECTED] (Lanfranco Fabriani) wrote: > Mogens Kjaer wrote: > > > > Lanfranco Fabriani wrote: > > ... > > > clamd stop > > > make uninstall 0.92.1 > > > make install 0.93 > > > ldconfig > > > clamd restart > > > > I would run freshclam before sta

[Clamav-users] freshclam / sigtool problems

2008-04-16 Thread Frank Elsner
Hello *, my "freshclam.conf" contains OnUpdateExecute /usr/ClamAV/bin/freshclam.mail and the refenced "/usr/ClamAV/bin/freshclam.mail" reads | #!/bin/sh | | cd /usr/ClamAV/data | DIFF="/tmp/clamav-signatures.$$" ; /bin/rm -f $DIFF | | MAIL="[EMAIL PROTECTED]" | | /bin/mv signatures sign

Re: [Clamav-users] freshclam / sigtool problems

2008-04-16 Thread Török Edwin
Frank Elsner wrote: > Why this? Is sigtool broken? Is my procedure broken in respect to version > 0.93? > From the log freshclam obviously does the job, but ... > Please try the patch from here: https://wwws.clamav.net/bugzilla/show_bug.cgi?id=938 Best regards, --Edwin ___

[Clamav-users] [EMAIL PROTECTED]: Cron <[EMAIL PROTECTED]> /usr/contrib/bin/freshclam]

2008-04-16 Thread Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem
- Forwarded message from Cron Daemon <[EMAIL PROTECTED]> - X-NetKnow-InComing-4694-2-MailScanner-Watermark: [EMAIL PROTECTED] X-Spam-Filter: [EMAIL PROTECTED] by digitalanswers.org Date: Tue, 15 Apr 2008 16:48:03 -0600 (MDT) From: Cron Daemon <[EMAIL PROTECTED]> To: [EMAIL PROTECTE

Re: [Clamav-users] No supported Database

2008-04-16 Thread Dennis Peterson
Tomasz Kojm wrote: > On Wed, 16 Apr 2008 08:30:11 +0200 (CEST) > [EMAIL PROTECTED] (Lanfranco Fabriani) wrote: > >> Is this necessary? In the years I never run freshclam before >> restarting clamd and the software always ran very well. The server >> of mine is a little mail server, so usually I tr

Re: [Clamav-users] clamav-0.93 error

2008-04-16 Thread Roberto Ullfig
George R. Kasica wrote: >> George R. Kasica wrote: >> We have the same issue. I'd take a guess that it's because we're running zlib-1.2.1.2-1.2 which is the latest offered by RHEL 4. >>> Ditto error here with zlib 1.2.3 and I've made sure there are no >>> dup

Re: [Clamav-users] freshclam / sigtool problems

2008-04-16 Thread Frank Elsner
On Wed, 16 Apr 2008 15:08:41 +0300 Török Edwin wrote: > Frank Elsner wrote: > > Why this? Is sigtool broken? Is my procedure broken in respect to version > > 0.93? > > From the log freshclam obviously does the job, but ... > > > > Please try the patch from here: > https://wwws.clamav.net/bugzi

Re: [Clamav-users] No supported Database

2008-04-16 Thread James Kosin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dennis Peterson wrote: | So I currently have a main.cvd and a daily.cld, both files. Is this what | 0.93 uses or will main.cvd be swapped out with a cld container at some | point? | | dp Yes, when there is finally an update to main.cvd... I believe th

Re: [Clamav-users] No supported Database

2008-04-16 Thread Brian Morrison
Dennis Peterson wrote: > So I currently have a main.cvd and a daily.cld, both files. Is this what > 0.93 uses or will main.cvd be swapped out with a cld container at some > point? And might someone explain what this change is about, how it improves performance or whatever? I had assumed that t

Re: [Clamav-users] No supported Database

2008-04-16 Thread Tomasz Kojm
On Wed, 16 Apr 2008 14:49:59 +0100 Brian Morrison <[EMAIL PROTECTED]> wrote: > And might someone explain what this change is about, how it improves > performance or whatever? I had assumed that the change to using .inc > directories allowed various different signatures to be held in separate >

Re: [Clamav-users] No supported Database

2008-04-16 Thread Dennis Peterson
Brian Morrison wrote: > Dennis Peterson wrote: > >> So I currently have a main.cvd and a daily.cld, both files. Is this what >> 0.93 uses or will main.cvd be swapped out with a cld container at some >> point? > > And might someone explain what this change is about, how it improves > performanc

Re: [Clamav-users] No supported Database

2008-04-16 Thread Brian Morrison
Tomasz Kojm wrote: > On Wed, 16 Apr 2008 14:49:59 +0100 > Brian Morrison <[EMAIL PROTECTED]> wrote: > >> And might someone explain what this change is about, how it improves >> performance or whatever? I had assumed that the change to using .inc >> directories allowed various different signature

Re: [Clamav-users] No supported Database

2008-04-16 Thread Tomasz Kojm
On Wed, 16 Apr 2008 16:38:05 +0100 Brian Morrison <[EMAIL PROTECTED]> wrote: > Does the unsigned .cld file mean that an attack vector could be to edit > the .cld file and thus corrupt it? I can see that the cdiff signing > protects the path between the database servers and freshclam, but that >

[Clamav-users] Can clamav-milter quarantine ALL messages?

2008-04-16 Thread Gomes, Rich
I need to temporarily quarantine all messages from a particular IP address. I have written a custom virus signature before but it will not trap what I need. I am getting messages looping that have no From address (they show up in maillog as: <"">... User address required I am working with the de

Re: [Clamav-users] No supported Database

2008-04-16 Thread Brian Morrison
Tomasz Kojm wrote: > On Wed, 16 Apr 2008 16:38:05 +0100 > Brian Morrison <[EMAIL PROTECTED]> wrote: > >> Does the unsigned .cld file mean that an attack vector could be to edit >> the .cld file and thus corrupt it? I can see that the cdiff signing >> protects the path between the database server

Re: [Clamav-users] No supported Database

2008-04-16 Thread Dennis Peterson
Brian Morrison wrote: > Tomasz Kojm wrote: >> On Wed, 16 Apr 2008 16:38:05 +0100 >> Brian Morrison <[EMAIL PROTECTED]> wrote: >> >>> Does the unsigned .cld file mean that an attack vector could be to edit >>> the .cld file and thus corrupt it? I can see that the cdiff signing >>> protects the pat

[Clamav-users] Can clamav-milter quarantine ALL messages?

2008-04-16 Thread Gomes, Rich
I need to temporarily quarantine all messages from a particular IP address. I have written a custom virus signature before but it will not trap what I need. I am getting messages looping that have no From address (they show up in maillog as: <"">... User address required I am working with the de

Re: [Clamav-users] No supported Database

2008-04-16 Thread Brian Morrison
Dennis Peterson wrote: >> Yes, I realise that. I run clamd under user clamav, hence it's probably >> easier to access /var/lib/clamav/* than it would be if owned by root. > > Why would that be? It is no more work to crack the root account than any > other account. Nor any less. Hopefully too yo

Re: [Clamav-users] No supported Database

2008-04-16 Thread Tomasz Kojm
On Wed, 16 Apr 2008 17:28:58 +0100 Brian Morrison <[EMAIL PROTECTED]> wrote: > Yes, I realise that. I run clamd under user clamav, hence it's probably > easier to access /var/lib/clamav/* than it would be if owned by root. Only freshclam needs a write access to the database directory so you can

Re: [Clamav-users] No supported Database

2008-04-16 Thread Dennis Peterson
Brian Morrison wrote: > Dennis Peterson wrote: > >>> Yes, I realise that. I run clamd under user clamav, hence it's probably >>> easier to access /var/lib/clamav/* than it would be if owned by root. >> Why would that be? It is no more work to crack the root account than any >> other account. Nor

[Clamav-users] Upgrade ClamAV

2008-04-16 Thread Carlos Williams
So it appears my installed version is too old to update the database and I need to upgrade from 0.90.3 to the latest version. I don't know who or how this version of clamav was installed on this rhel4.6 es server but I downloaded the tarball since clamav is not a supported rpm available from Re

[Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread kwijibo
People who may have problems compiling ClamAV 0.93 with the FreeBSD ports on 4.11 may need to patch the port Makefile as I had to. I am not sure if it affects other FreeBSD versions or not, I didn't try it. --- Makefile.orig Wed Apr 16 10:59:51 2008 +++ MakefileWed Apr 16 11:37:41 2008

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Dennis Peterson
Carlos Williams wrote: > So it appears my installed version is too old to update the database and > I need to upgrade from 0.90.3 to the latest version. I don't know who or > how this version of clamav was installed on this rhel4.6 es server but I > downloaded the tarball since clamav is not a s

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Carlos Williams
Dennis Peterson wrote: > It looks like earlier versions were installed as RPM packages from > rpmforge using yum, not the RH repository. Have you tried using yum to > see if the current version is availble? > I had no idea YUM was even installed on this server. I thought YUM was only availabl

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Dennis Peterson
Carlos Williams wrote: > Dennis Peterson wrote: > > It looks like earlier versions were installed as RPM packages from >> rpmforge using yum, not the RH repository. Have you tried using yum to >> see if the current version is availble? >> > I had no idea YUM was even installed on this server. I

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Carlos Williams
Dennis Peterson wrote: > It looks like earlier versions were installed as RPM packages from > rpmforge using yum, not the RH repository. Have you tried using yum to > see if the current version is availble? I am getting the following error when running "yum update" --> Processing Dependency: lib

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Dennis Peterson
Carlos Williams wrote: > Dennis Peterson wrote: >> It looks like earlier versions were installed as RPM packages from >> rpmforge using yum, not the RH repository. Have you tried using yum to >> see if the current version is availble? > I am getting the following error when running "yum update" >

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Carlos Williams
Dennis Peterson wrote: > This was discussed on the list the last couple of day - check the > archives to see what is suggested. Google this: > > libclamunrar_iface.so.3 site:clamav.net > I searched Google and could not find anything that was obvious to resolving this dep. issue. When I go t

Re: [Clamav-users] clamd seg faulting (ver 0.93)

2008-04-16 Thread Török Edwin
Lyle Giese wrote: > Looks like we are having an intermitant problem with 0.93 > > I built it from source on a SuSE 10.2(64bit), 2.6.18.2-34-default #1 SMP > kernel on an AMD Athlon 64 processor. I compiled with no configure options. > > About 3 or 4 times since I updated on the 14th, I am getting

Re: [Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread James Kosin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: | People who may have problems compiling ClamAV 0.93 with the FreeBSD | ports on 4.11 may need to patch the port Makefile as I had to. I am | not sure if it affects other FreeBSD versions or not, I didn't try it. | | --- Make

Re: [Clamav-users] WARNING: Suspicious recipient address blocked

2008-04-16 Thread Eric Rostetter
Quoting John Rudd <[EMAIL PROTECTED]>: > Tilman Schmidt wrote: > >> So why am I dissecting that list like this? Just to show that blocking >> or not blocking certain unusal characters in mail addresses is indeed a >> policy decision which should not be forced by a piece of software, but at >> most

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread James Kosin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Carlos Williams wrote: | I searched Google and could not find anything that was obvious to | resolving this dep. issue. | | When I go to search the archives manually, I went to | http://lurker.clamav.net/list/clamav-users.html and I get a blank page |

[Clamav-users] clamd seg faulting (ver 0.93)

2008-04-16 Thread Lyle Giese
Looks like we are having an intermitant problem with 0.93 I built it from source on a SuSE 10.2(64bit), 2.6.18.2-34-default #1 SMP kernel on an AMD Athlon 64 processor. I compiled with no configure options. About 3 or 4 times since I updated on the 14th, I am getting where clamdmon.sh is findi

Re: [Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread kwijibo
James Kosin wrote: > ~ SPARC Options > ~- > ~ -pthreads > ~ Add support for multithreading using the POSIX threads library. > ~ This option sets flags for both the preprocessor and > linker. This > ~ option does not affect the thre

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Nigel Frankcom
On Wed, 16 Apr 2008 14:21:17 -0400, Carlos Williams <[EMAIL PROTECTED]> wrote: > >Dennis Peterson wrote: > >> This was discussed on the list the last couple of day - check the >> archives to see what is suggested. Google this: >> >> libclamunrar_iface.so.3 site:clamav.net >> > >I searched Googl

Re: [Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread kwijibo
James Kosin wrote: > > The -pthread should only be needed on IBM RS/6000 and PowerPC platforms. > SPARC has their own option and everyone else should follow into the -l > category. > I suppose I should clarify the architecture. This was done on an x86. Steven ___

Re: [Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread Török Edwin
[EMAIL PROTECTED] wrote: > James Kosin wrote: > > >> The -pthread should only be needed on IBM RS/6000 and PowerPC platforms. >> SPARC has their own option and everyone else should follow into the -l >> category. >> >> > > I suppose I should clarify the architecture. This was done on an x

Re: [Clamav-users] FreeBSD 4.11 and ports

2008-04-16 Thread Chuck Swiger
On Apr 16, 2008, at 12:31 PM, Török Edwin wrote: > Manpages indicate to use -pthread to link. > Linux: man pthreads > Compiling on Linux > On Linux, programs that use the Pthreads API should be compiled > using cc -pthread > > FreeBSD: > http://www.freebsd.org/cgi/man.cgi?query=pthread&apropo

Re: [Clamav-users] Upgrade ClamAV

2008-04-16 Thread Dennis Peterson
> > > Dennis Peterson wrote: > > > This was discussed on the list the last couple of day - check the > > archives to see what is suggested. Google this: > > > > libclamunrar_iface.so.3 site:clamav.net > > > > I searched Google and could not find anything that was obvious to > resolving this

Re: [Clamav-users] No supported Database

2008-04-16 Thread Sarocet
Brian Morrison wrote: > Dennis Peterson wrote: > >>> Yes, I realise that. I run clamd under user clamav, hence it's probably >>> easier to access /var/lib/clamav/* than it would be if owned by root. >>> >> Why would that be? It is no more work to crack the root account than any >> other

[Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Naomi Hospodarsky
I've been trying to compile clamav (0.93) on AIX 5.2, and I keep getting the checking for libgmp... no configure: WARNING: ** GNU MP 2 or newer NOT FOUND - digital signature support will be disabled ! conflig.log shows the following: configure:15256: checking for libgmp configure:15286: cc -

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread kwijibo
Naomi Hospodarsky wrote: > So I'm not sure where the disconnect is happening between the two > programs; if anyone has any ideas, I'd be very glad to hear them! I am not up to speed on AIX so I may have some wrong presumptions but shouldn't your header files by in /usr/local/include and your libra

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Naomi Hospodarsky
In the output of the config.log I posted, you'll see that clamav is looking for the libs in /usr/local/include (where GMP installed its files), but for some reason doesn't see them. So it's not that clamav is looking in the wrong location, exactly, but that it is, for some reason, not seeing what's

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Dennis Peterson
Naomi Hospodarsky wrote: > In the output of the config.log I posted, you'll see that clamav is > looking for the libs in /usr/local/include (where GMP installed its > files), but for some reason doesn't see them. So it's not that clamav > is looking in the wrong location, exactly, but that it is, f

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Naomi Hospodarsky
Okay, that makes sense. I tried copying the lib files over to /usr/local/lib as you suggested, and am now getting this error in config.log configure:15256: checking for libgmp configure:15286: cc -qlanglvl=extc89 -o conftest -g -I/usr/local/include conftest.c /usr/local/lib/libgmp.a >&5 ld: 0711

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Kwijibo
Naomi Hospodarsky wrote: > Okay, that makes sense. I tried copying the lib files over to > /usr/local/lib as you suggested, and am now getting this error in > config.log > > configure:15256: checking for libgmp > configure:15286: cc -qlanglvl=extc89 -o conftest -g > -I/usr/local/include conftest.c

Re: [Clamav-users] compiling on AIX 5.2 and location of libgmp.

2008-04-16 Thread Dennis Peterson
Naomi Hospodarsky wrote: > Okay, that makes sense. I tried copying the lib files over to > /usr/local/lib as you suggested, and am now getting this error in > config.log > > configure:15256: checking for libgmp > configure:15286: cc -qlanglvl=extc89 -o conftest -g > -I/usr/local/include conftest.

Re: [Clamav-users] US-CERT alert regarding ClamAV

2008-04-16 Thread James Brown
On 16/04/2008, at 4:33 AM, fchan wrote: This part of clamav-0.92 and new fix of a bug. https://wwws.clamav.net/bugzilla/show_bug.cgi?id=613 And in short we need to get gcc4.1.1 or newer to get this work on Macintosh 10.4.11 and xcode 2.5 which only has an gcc 4.0.1. However Apple hasn't r

Re: [Clamav-users] Can clamav-milter quarantine ALL messages?

2008-04-16 Thread Michael Isaev
> Can I either(thru sendmail, clamav, or clamav-milter): > Quarantine all messages from a particular IP ? You can (thru sendmail). Append 'access' file from sendmail as follow: Connect:aaa.bbb.ccc.dddQUARANTINE Michael ___ Help us build a comprehensive

Re: [Clamav-users] US-CERT alert regarding ClamAV

2008-04-16 Thread Dennis Peterson
James Brown wrote: > >> >>> John Rudd wrote: Oh, and, while we're on the subject, what about 0.88.6? is that version vulnerable? (don't tell me to upgrade -- I haven't been able to get newer versions to compile on Mac OS X 10.4.x) > > Frank & John, I've used ./configure --e

Re: [Clamav-users] US-CERT alert regarding ClamAV

2008-04-16 Thread Dennis Peterson
Dennis Peterson wrote: > James Brown wrote: > John Rudd wrote: > Oh, and, while we're on the subject, what about 0.88.6? is that > version > vulnerable? (don't tell me to upgrade -- I haven't been able to get > newer versions to compile on Mac OS X 10.4.x) >> Frank & John, I

Re: [Clamav-users] US-CERT alert regarding ClamAV

2008-04-16 Thread Dennis Peterson
Dennis Peterson wrote: > Dennis Peterson wrote: >> James Brown wrote: >> > John Rudd wrote: >> Oh, and, while we're on the subject, what about 0.88.6? is that >> version >> vulnerable? (don't tell me to upgrade -- I haven't been able to get >> newer versions to compile on Mac