Re: [clamav-users] /home/gene/firefox/browser/omni.ja: Html.Exploit.CVE_2017_8750-6336209-0 FOUND

2017-10-24 Thread Tsutomu Oyamada
Yes, I have submit the file many times. File name: omni.ja SHA256: 5e852b33f716fb6b81bc75d762372a105f04dcdab07a621eddb8507970dbd0b6 On Mon, 23 Oct 2017 23:48:26 -0700 Al Varnell wrote: > Did you submit a sample of it as a false positive report? If so please reply > with a hash value for the f

Re: [clamav-users] Signatur help - php injection

2017-10-24 Thread Eric Tykwinski
Hajo, > Hello list, > > Pattern is always the same, including the 5-char comments. In my case the > include string decodes to a path and includes an .ico file. > I dont understand this code to obfuscate the path. I saw some samples and all > of the lines look a different way in encoded case. Wh

[clamav-users] Quick Question on clamd and OSX

2017-10-24 Thread Eric Tykwinski
On the VirusEvent section of clamd.conf, it says that it creates two environment variables. I've got clamdscan running under my user account on OS X 10.13, but not showing anything on printenv. Is there something I'm missing? Sincerely, Eric Tykwinski TrueNet, Inc. P: 610-429-8300

Re: [clamav-users] Quick Question on clamd and OSX

2017-10-24 Thread Eric Tykwinski
Sorry for the noise... The variables are only available for the duration of the script... Sincerely, Eric Tykwinski TrueNet, Inc. P: 610-429-8300 ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listi

[clamav-users] If anyone can give me a hand...

2017-10-24 Thread Eric Tykwinski
So I’ve got clamd running as root on a MacPro, and individual plist files running clamdscan with fswatch scanning user directories for threats. These are running in individuals ~/Library/LaunchAgents/ directories. The clam part is running fine, and catching things. My notify script however isn’t