[clamav-users] Fw: important message

2016-01-28 Thread lists
Hello! New message, please read li...@kratzt.net ___ Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml

Re: [clamav-users] Fw: important message

2016-01-28 Thread Al Varnell
Yet another malware site. Can we get this guy off the list please. -Al- On Jan 28, 2016, at 10:40 AM, li...@kratzt.net wrote: > Hello! > > > > New message, please read > > > > li...@kratzt.net smime.p7s Description: S/MIME cryptographic signature ___

Re: [clamav-users] Fw: important message

2016-01-28 Thread Benny Pedersen
On 2016-01-28 19:50, Al Varnell wrote: Yet another malware site. Can we get this guy off the list please. + add sanesecurity sigs to maillist server could help even more ___ Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/cla

[clamav-users] Freshclam Non-repudiation

2016-01-28 Thread Brad Scalio
Is there any integrity or authenticity checks within freshclam when it connects to the clamAV servers to download the virus signature databases? Also is there any non-repudiation of the servers hosting the virus signature databases, that is who gets to be a host and is there any procedures to ens

Re: [clamav-users] Freshclam Non-repudiation

2016-01-28 Thread Dennis Peterson
See the config file for freshclam. It will pull sigs from where ever you specify. The default is to use the ClamAV signature server farm and are known to the ClamAv team. Checksums are examined. Others will have to speak to the credentials expected of those volunteers who make up the server fa

Re: [clamav-users] Is it a real attack?

2016-01-28 Thread Al Varnell
All but the eicar test signature are PUA (Potentially Unwanted Application) detections. So several comments about PUA need to be made. First be sure to read the ClamAV FAQ on PUA: . PUA cannot be a False Positive, by definit