Re: [clamav-users] - Can't connect to UNIX, socket /var/run/clamav/clamd.ctl

2013-11-01 Thread Shawn Webb
On Fri, Nov 1, 2013 at 5:51 AM, Paolo De Michele wrote: > > On 11/01/2013 10:11 AM, Paolo De Michele wrote: > >> >> On 11/01/2013 02:45 AM, Dennis Peterson wrote: >> >>> On 10/31/13, 5:08 PM, Paolo De Michele wrote: >>> hi everybody, I installed a web/mail server

Re: [clamav-users] Warning from Clamav on ISPconfig

2013-12-18 Thread Shawn Webb
On Wed, Dec 18, 2013 at 3:56 PM, EyeLand wrote: > Hello, on VPS I install ISPconfig, and on control panel I receive > warning from Clamav, can you consult? Thank you! > > Wed Dec 18 10:33:53 2013 -> main.cvd is up to date (version: 55, sigs: > 2424225, f-level: 60, builder: neo) > Wed Dec 18 10:3

Re: [clamav-users] request for feature

2014-01-31 Thread Shawn Webb
Hey Gene, Thank you for giving us ideas for new features. Our bugzilla system at https://bugzilla.clamav.net/ is the right place to file feature requests. Thanks, Shawn On Fri, Jan 31, 2014 at 2:23 PM, Gene Heskett wrote: > Greetings; > > I have trolled thru the man pages at length, and can

Re: [clamav-users] LibhClamAV Warning

2014-02-12 Thread Shawn Webb
On Wed, Feb 12, 2014 at 1:38 PM, Anthony Magrone < anthonymagr...@hamlinandburton.com> wrote: > How can I address the following warning? > > /etc/cron.daily/autoclam: > > LibClamAV Warning: SWF: Invalid tag length. > LibClamAV info: scancws: Error decompressing SWF file > > Regards, > Anthony > H

Re: [clamav-users] Error message "outdated version" although "yum list installed" reports correct version of clamav

2014-02-19 Thread Shawn Webb
On Feb 19, 2014 9:28 PM, "Jobst Schmalenbach" wrote: > > > Hi. > > Strange problem indeed: > > [root /tmp] #>yum list installed "clamav*" > Loaded plugins: fastestmirror > Installed Packages > clamav.x86_64 0.98-2.el5.rf installed > clamav-db.x86_64 0.9

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-26 Thread Shawn Webb
On Wed, Feb 26, 2014 at 1:01 PM, Dennis Peterson wrote: > On 2/26/14, 8:08 AM, Joel Esler (jesler) wrote: > >> On Friday last week I put a blog post up about introducing OpenSSL into >> the ClamAV ecosystem. I wanted to make sure everyone saw it, so please >> have a look at the blog post here: >>

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-27 Thread Shawn Webb
On Thu, Feb 27, 2014 at 5:56 PM, Lawrence K. Chen, P.Eng. wrote: > > > On 02/27/14 02:34, Steve Basford wrote: > > > > > >> OpenSSL will be required to both compile and run ClamAV. > > > > Out of interest what Cipher: > > > > http://zombe.es/post/4078724716/openssl-cipher-selection > > > > > http:

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Thu, Feb 27, 2014 at 5:56 PM, Lawrence K. Chen, P.Eng. wrote: > > > On 02/27/14 02:34, Steve Basford wrote: > > > > > >> OpenSSL will be required to both compile and run ClamAV. > > > > Out of interest what Cipher: > > > > http://zombe.es/post/4078724716/openssl-cipher-selection > > > > > http:

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Fri, Feb 28, 2014 at 8:59 AM, Richard Conto wrote: > Can the OpenSSL dependency be abstracted so that GNU TLS could be a > replacement as well? (Frankly, I'm speaking out of a bit of ignorance here > as I don't know how incompatible GNU TLS is with OpenSSL at the API layer. > With the except

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Fri, Feb 28, 2014 at 10:27 AM, Mark Allan wrote: > As this is first time ClamAV has had an external dependency, would it be > worth making it an opt-out configure option for people who can't get it to > compile or who have to rely on an older/incompatible version of OpenSSL? > > Mark Hey Mark

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-03-13 Thread Shawn Webb
On Wed, Mar 12, 2014 at 4:48 PM, Paul Kosinski wrote: > I'm not worried about dependency on external libraries per se. I just > want to know *why*? With libz and libz2, it's pretty obvious, with > SSL, it's not clear. > > Decrypting encrypted data while scanning would need the key. Is the > idea

Re: [clamav-users] Problem with Freshclam and local mirror

2014-04-01 Thread Shawn Webb
On Tue, Apr 1, 2014 at 5:30 AM, Simon Hobson wrote: > Because I've several machines using it, I've setup one to act as a local > server, with the others pulling their updates from it. It's been generally > reliable for years, but since updating to 0.98.1 I'm having repeated > problems where the s

Re: [clamav-users] Problem with Freshclam and local mirror

2014-04-01 Thread Shawn Webb
On Tue, Apr 1, 2014 at 12:47 PM, Shawn Webb wrote: > On Tue, Apr 1, 2014 at 5:30 AM, Simon Hobson wrote: > >> Because I've several machines using it, I've setup one to act as a local >> server, with the others pulling their updates from it. It's been generally

Re: [clamav-users] Silly question - clamav - linux viruses?

2014-04-17 Thread Shawn Webb
In addition to many other file formats, ClamAV recognizes and scans ELF files, the executable file format shared between Linux, BSD, and the other Unixes. The alert name can vary, as Alain pointed out. On Thu, Apr 17, 2014 at 11:26 AM, Dennis Peterson wrote: > On 4/17/14, 8:13 AM, Alain Zidouemb

Re: [clamav-users] clamdscan big files problem

2014-04-25 Thread Shawn Webb
On Fri, Apr 25, 2014 at 10:35 AM, SR wrote: > Hello everyone, > > I have happily been using Clamav on our file server for more than a year > now. > The scan of the different volumes is done by clamdscan which is ran > from cron jobs. > > The problem that I am facing since a few weeks, is that the

Re: [clamav-users] clamdscan big files problem

2014-04-25 Thread Shawn Webb
On Fri, Apr 25, 2014 at 11:35 AM, SR wrote: > 2014-04-25 10:58 GMT-04:00 Shawn Webb : > > Hey Stephen, > > > > How big is that file? How much RAM (physical and swap separate, please) > is > > installed on the scanning machine? Currently, ClamAV has a hard fil

Re: [clamav-users] Manual cdiff update

2014-04-28 Thread Shawn Webb
On Fri, Apr 25, 2014 at 8:20 PM, Arthur Snyder wrote: > I am trying to manually update a daily.cvd file with a daily-xx.cdiff > file. I know I can just download the latest daily.cvd. I know I can just > run freshclam and update. That is not the point. > > I run sigtool --verify-cdiff daily-xx

Re: [clamav-users] Manual cdiff update

2014-04-28 Thread Shawn Webb
On Mon, Apr 28, 2014 at 3:14 PM, Arthur Snyder wrote: > Thank you. That helps. Do I need to repack the daily.cvd after applying > the cdiff before placing it in /var/lib/clamav? If so, will it still work > since I cannot sign it with a clamav cert? > > Art > Yeah, you can repack it as you see

Re: [clamav-users] Freshclam and safebrowsing

2014-05-05 Thread Shawn Webb
On Sun, May 4, 2014 at 8:53 AM, Alex wrote: > Hi, > > I'm running clamav-0.98.1 on fedora20 and was just wondering about > safebrowsing.cvd. I notice when freshclam runs, it always downloads an > entirely new version when there are any changes, instead of just the > differences, as it does with d

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-07 Thread Shawn Webb
Hey James, Can you paste your clamd.conf file please? Thanks, Shawn On May 7, 2014 9:39 PM, "James Brown" wrote: > Have just upgraded to version 0.98.3 from 0.98.1. > > Clamd starts fine, but anytime I reload the database (e.g. running > freshclam) clamd will crash. > > OS X’s crash log says:

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-07 Thread Shawn Webb
What's the output of this command: file /usr/lib/libxml2.so Can you paste (preferably to a pastebin service) your config.log? What options did you pass to ./configure? On Thu, May 8, 2014 at 1:48 AM, Alexander Tampermeier < alexan...@tampermeier.at> wrote: > I have been using ClamAV on my Linux

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-07 Thread Shawn Webb
dynamically linked, not stripped > > This is my configure command (building 64bit): > CC="gcc ${BUILD64}" ./configure --prefix=/usr --sysconfdir=/etc/clamav > --with-zlib=/usr --with-dbdir=/usr/share/clamav > > Where 'echo ${BUILD64}' outputs: > -m64 > &

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-08 Thread Shawn Webb
gt; > I pasted the output of command #2 (CC="gcc ${BUILD64}" ./configure ...) at > http://de.pastebin.de/124756 > > Output of command #3 (make) is pasted at http://de.pastebin.de/124757 > > Regards > Alexander > > > Am 08.05.2014 08:40, schrieb Shawn Webb: > >

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-08 Thread Shawn Webb
Hey All, This bug only affects OSX machines and is due to an improper return. This commit fixes it: https://github.com/vrtadmin/clamav-devel/commit/9e47301bc96964b33fe578170296c780924b3b7b Additionally, this bug has been filed as bug 10986: https://bugzilla.clamav.net/show_bug.cgi?id=10986 Thank

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-08 Thread Shawn Webb
> And here is the corrected output of the make command: > http://de.pastebin.de/124761 > > Regards > Alexander > > > Am 08.05.2014 09:29, schrieb Shawn Webb: > >> Did you add the --disable-silent-rules to your ./configure run? It looks >> like step 3 is still pro

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-08 Thread Shawn Webb
Thanks! I'll have a fix for you first thing in the morning. It looks like there might be a buggy edge case. Thanks, Shawn On May 7, 2014 9:46 PM, "James Brown" wrote: On 8 May 2014, at 11:42 am, Shawn Webb wrote: > Hey James, > > Can you paste your clamd.conf file p

Re: [clamav-users] Version 0.98.3 fails on Solaris

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:13 AM, Martin Preen < pr...@informatik.uni-freiburg.de> wrote: > Hello, > after building 0.98.3 on Solaris 10 (Sparc) I got some error > messages from freshclam. > > The first run: > > ERROR: Corrupted database file /var/clamav/main.cvd: Can't allocate memory > Corrupted

Re: [clamav-users] Version 0.98.3 compile failure on Solaris

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:04 AM, Lars Hecking < lheck...@users.sourceforge.net> wrote: > > The configure code checking for the newly required openssl library is > broken. > > [...] > configure:16590: checking for OpenSSL installation > configure:16632: checking for SSL_library_init in -lssl > con

Re: [clamav-users] Crash on db reload: 0.98.3 (OS: win32, ARCH: i386

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:41 AM, Steve Basford < steveb_cla...@sanesecurity.com> wrote: > Just a quick report... > > 0.98.3 crashes... 0.98.1 no issues... > > Thu May 08 15:29:06 2014 -> +++ Started at Thu May 08 15:29:06 2014 > Thu May 08 15:29:06 2014 -> clamd daemon 0.98.3 (OS: win32, ARCH: i38

Re: [clamav-users] Version 0.98.3 hard loops on "clamdscan -V"

2014-05-09 Thread Shawn Webb
On Thu, May 8, 2014 at 10:35 PM, Eric Shubert wrote: > Immediately after upgrading from 0.98 to 0.98.3, > when "clamdscan --stdout -V" is run (via simscanmk -g), > the clamdscan appears to go into a hard loop (eats a lot of cpu endlessly). > > Here are non-default config settings: > [root@qmt-cos

Re: [clamav-users] Version 0.98.3 hard loops on "clamdscan -V"

2014-05-09 Thread Shawn Webb
users-boun...@lists.clamav.net [mailto:clamav-users- > > boun...@lists.clamav.net] De la part de Eric Shubert > > Envoyé : Friday, May 09, 2014 2:49 PM > > À : clamav-users@lists.clamav.net > > Objet : Re: [clamav-users] Version 0.98.3 hard loops on "clamdscan -V" >

Re: [clamav-users] Version 0.98.3 compile failure on Solaris

2014-05-09 Thread Shawn Webb
On Thu, May 8, 2014 at 11:04 AM, Lars Hecking < lheck...@users.sourceforge.net> wrote: > > The configure code checking for the newly required openssl library is > broken. > > [...] > configure:16590: checking for OpenSSL installation > configure:16632: checking for SSL_library_init in -lssl > con

Re: [clamav-users] Version 0.98.3 fails on Solaris

2014-05-10 Thread Shawn Webb
Hey All, The attached two patches will make building (with gcc) and running on Solaris work. I've also pasted them to the below linked sites in case the attachments don't go through. The patches ought to be applied in order. Patch 1: http://ix.io/ceV (001-clamav-solaris.patch) Patch 2: http://ix.

Re: [clamav-users] Compiling a minimal version without some of the executables

2014-05-12 Thread Shawn Webb
On Mon, May 12, 2014 at 6:21 PM, Dennis Waters wrote: > I'm trying to find a way to compile clamav, but only compiling > clamscan and freshclam (and libclamav of course). > > I've tried searching, tried the documentation, tried ./configure > --help. Unfortunately, while I found the parameters to d

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-16 Thread Shawn Webb
On Fri, May 16, 2014 at 8:56 AM, Dariusz Wojciechowski wrote: > Hello. > > I try to compile Clamav 0.98.3 on my quite old server with Red Hat EL 4. I > guess I have the same issue as Gary on his Mac OSX 10.5.8: > > http://comments.gmane.org/gmane.comp.security.virus.clamav.user/39771 > > I mean to

Re: [clamav-users] [Clamav-devel] ClamAV(R): ClamAV 0.98.4rc1 is now available!

2014-05-20 Thread Shawn Webb
Hey Mark, Is there a way you could get me the sample? Thanks, Shawn On Tue, May 20, 2014 at 6:49 AM, Mark Allan wrote: > I may have been a bit hasty with this. It appears there's another issue > with clamd. > > I'm receiving reports of clamd crashing when attempting to parse email in > an in

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-20 Thread Shawn Webb
On Mon, May 19, 2014 at 2:52 PM, MarkusGMX wrote: > Am 16/05/14 17:57, schrieb Alexander Tampermeier: > > Sadly, the libxml2-error still persists in v0.98.4-rc1. >> Hope, it can be fixed soon. >> > [...] > > :-( > I am also waiting for a bugfix for the build process. > > >

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 1:45 PM, Todd Aiken wrote: > Hi everybody. I was having the same problem, and was able to compile and > install a new version of OpenSSL (0.9.8y) to /usr/local/ssl just like the > original poster of this thread, but I am still having trouble compiling > clamav-0.98.4-rc1.

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 3:26 PM, Todd Aiken wrote: > -Original Message- > > From: Shawn Webb > Reply-To: ClamAV users ML > Date: Friday, May 23, 2014 at 1:53 PM > To: ClamAV users ML > Subject: Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem > >

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 3:47 PM, Todd Aiken wrote: > -Original Message- > > From: Shawn Webb > Reply-To: ClamAV users ML > Date: Friday, May 23, 2014 at 3:32 PM > To: ClamAV users ML > Subject: Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem > >

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-26 Thread Shawn Webb
On Mon, May 26, 2014 at 8:58 AM, Todd Aiken wrote: > > -Original Message- > From: Shawn Webb > Reply-To: ClamAV users ML > Date: Friday, May 23, 2014 at 4:22 PM > To: ClamAV users ML > Subject: Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem > >

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-27 Thread Shawn Webb
On Tue, May 27, 2014 at 9:20 AM, Todd Aiken wrote: > > -Original Message- > From: Shawn Webb > Reply-To: ClamAV users ML > Date: Monday, May 26, 2014 at 4:06 PM > To: ClamAV users ML > Subject: Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem > >

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-27 Thread Shawn Webb
On Tue, May 27, 2014 at 11:04 AM, Todd Aiken wrote: > > -Original Message- > From: Shawn Webb > Reply-To: ClamAV users ML > Date: Tuesday, May 27, 2014 at 10:59 AM > To: ClamAV users ML > Subject: Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem >

Re: [clamav-users] Tips for low memory systems

2014-05-27 Thread Shawn Webb
You can also take a look at this thread from 2013: http://www.gossamer-threads.com/lists/clamav/users/59413 On Tue, May 27, 2014 at 10:26 PM, Michael Heuberger < michael.heuber...@binarykitchen.com> wrote: > Yeah I know but I am very busy these days. Either an easy solution or > I'll buy more RA

Re: [clamav-users] Communication error

2014-05-30 Thread Shawn Webb
On Fri, May 30, 2014 at 6:21 AM, Henri Salo wrote: > Hello list, > > I've been having lots of problems with scanning major dataset. Command I > execute > is: "clamdscan -i -m --fdpass /mnt/dataset/ --log=clamav.log" > > After some time of processing ClamAV starts to find malware and in this > poi

Re: [clamav-users] Communication error

2014-05-30 Thread Shawn Webb
On Fri, May 30, 2014 at 1:14 PM, Henri Salo wrote: > On Fri, May 30, 2014 at 08:16:46AM -0400, Shawn Webb wrote: > > Hey Henri, > > > > Which version of ClamAV are you using? On what OS and architecture? > > > > Thanks, > > Shawn > > Hello Shawn and

Re: [clamav-users] libclamunrar_iface.so

2014-05-30 Thread Shawn Webb
On May 30, 2014 5:11 PM, "Andreas Schulze" wrote: > > Hello, > > after packaging 0.98.4-rc1 I noticed a message after starting clamav: > LibClamAV Warning: Cannot dlopen: file not found – unrar support unavailable > > solution: > ln -s /usr/lib/libclamunrar_iface.so.6 /usr/lib/libclamunrar_if

Re: [clamav-users] OpenSSL Security Advisory [05 Jun 2014]

2014-06-07 Thread Shawn Webb
On Sat, Jun 7, 2014 at 3:05 AM, Al Varnell wrote: > Based on the subject document < > https://www.openssl.org/news/secadv_20140605.txt> what, if any > vulnerabilities are applicable to the ClamAV® scan engine? > Hey Al, Since we use OpenSSL purely for generating hashes, the recent vulnerabiliti

Re: [clamav-users] DatabaseCustomURL question

2014-06-19 Thread Shawn Webb
On Thu, Jun 19, 2014 at 9:49 AM, Steve Basford < steveb_cla...@sanesecurity.com> wrote: > Hi, > > Does anyone have DatabaseCustomURL in their freshclam.conf: > > I've just tried this format... > > DatabaseCustomURL http://blahblahblah.com:/test.cud > > And I get an "Unknown error" ? :) > > ie.

Re: [clamav-users] Does Clamsubmit work?

2014-06-24 Thread Shawn Webb
On Tue, Jun 24, 2014 at 4:36 PM, Daniel Quintiliani wrote: > Hi, > > There was a recent thread about ClamAV's low detection rates when compared > to other AVs on VirusTotal. > > When Clamsubmit came out I started using it to submit "false negatives", > following the "two per day" rules of the Web

Re: [clamav-users] Malformed database?

2014-06-25 Thread Shawn Webb
On Wed, Jun 25, 2014 at 8:44 AM, Paul Smith wrote: > > On 25/06/2014 13:25, Joel Esler (jesler) wrote: > >> On Jun 25, 2014, at 7:15 AM, Paul Smith mailto:paul@ >> pscs.co.uk>> wrote: >> >> Oh? The FAQ says that the latest two major versions (0.97 and 0.98 ?) are >> tested against the DB, so it s

Re: [clamav-users] Malformed database?

2014-06-25 Thread Shawn Webb
On Wed, Jun 25, 2014 at 8:48 AM, Shawn Webb wrote: > On Wed, Jun 25, 2014 at 8:44 AM, Paul Smith wrote: > >> >> On 25/06/2014 13:25, Joel Esler (jesler) wrote: >> >>> On Jun 25, 2014, at 7:15 AM, Paul Smith mailto:paul@ >>> pscs.co.uk>> wrote: &g

Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-06-26 Thread Shawn Webb
On Thu, Jun 26, 2014 at 12:37 AM, Paul Kosinski wrote: > I'm using HAVP (0.92) on Linux (openSuSE 13.1) as a virus scanning > filter for HTTP traffic. It worked perfectly with ClamAV 0.98.3 (and > many previous versions), but now it won't start at all with 0.98.4. > > HAVP uses libclamav.so to do

Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-06-26 Thread Shawn Webb
On Thu, Jun 26, 2014 at 11:31 AM, Stuart Henderson < stu-clamav-l...@spacehopper.org> wrote: > On 2014/06/26 11:10, Shawn Webb wrote: > > On Thu, Jun 26, 2014 at 12:37 AM, Paul Kosinski > wrote: > > > > > I'm using HAVP (0.92) on Linux (openSuSE 13.1) as

Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-06-26 Thread Shawn Webb
Hey Paul, The reason for that is likely due to my usage of ctors and dtors with 0.98.3. In that version, I had added a ctors entry in libclamav to call cl_initialize_crypto and a dtors entry to call cl_cleanup_crypto. It turns out that operating systems like AIX, HPUX, and Solaris 10 don't support

Re: [clamav-users] Are vbs virus dected by clamav?

2014-07-01 Thread Shawn Webb
On Tue, Jul 1, 2014 at 7:26 PM, Patrick DOURET wrote: > Dear > > I would like to know if clamav is able to detect vbs (i mean viruses based > on vb script)? > > What about if those kind of viruse are included in Microsoft office > documents as objets? > > We have the latest version 0.98 > > Thank

Re: [clamav-users] ClamAV(R): ClamAV 0.98.5 beta has been posted!

2014-07-09 Thread Shawn Webb
On Wed, Jul 9, 2014 at 9:01 AM, Frank Elsner wrote: > On Wed, 9 Jul 2014 14:48:31 +0200 Matus UHLAR - fantomas wrote: > > >On Tue, 8 Jul 2014 23:15:12 + Joel Esler (jesler) wrote: > > >> ClamAV 0.98.5 beta has been posted! > > >> The ClamAV team is proud to announce the availability of ClamAV

Re: [clamav-users] ClamAV(R): ClamAV 0.98.5 beta has been posted!

2014-07-09 Thread Shawn Webb
On Wed, Jul 9, 2014 at 11:32 AM, Frank Elsner wrote: > On Wed, 09 Jul 2014 09:38:11 -0400 Greg Folkert wrote: > > On Wed, 2014-07-09 at 15:01 +0200, Frank Elsner wrote: > > > On Wed, 9 Jul 2014 14:48:31 +0200 Matus UHLAR - fantomas wrote: > > > > >On Tue, 8 Jul 2014 23:15:12 + Joel Esler (jes

Re: [clamav-users] Datebase Warning

2014-07-11 Thread Shawn Webb
On Fri, Jul 11, 2014 at 11:37 AM, Chris wrote: > Restarting clamd since I made a change to the .conf file I see this: > > Starting Clam AntiVirus Daemon: LibClamAV Warning: > ** > LibClamAV Warning: *** The virus database is older than 7 days! ***

Re: [clamav-users] ClamAV(R): Compiling OpenSSL For Windows

2014-07-14 Thread Shawn Webb
I haven't tried with LibreSSL. Their first (and second) official release was over the weekend. Your mileage may vary. On Sun, Jul 13, 2014 at 1:48 PM, Steve Basford < steveb_cla...@sanesecurity.com> wrote: > Just a thought.. Will ClamAV use LibreSSL too, as it's supposed to be drop > in > > On 9

Re: [clamav-users] old signature files

2014-07-16 Thread Shawn Webb
On Wed, Jul 16, 2014 at 12:08 PM, c chupela wrote: > I've inherited an old CentOS(v5.5) installation running CLamAV 0.95.3. > /usr/local/share/clamav is using 283GB of space, and it looks like old > signature updates. I saw a previous question on this with a newer release > of clam, and the adv

Re: [clamav-users] [Clamav-devel] ClamAV(R): ClamAV 0.98.5 beta has been posted!

2014-07-18 Thread Shawn Webb
On Fri, Jul 18, 2014 at 4:51 PM, Mark Allan wrote: > > On 9 Jul 2014, at 12:15 am, Joel Esler (jesler) wrote: > > > ClamAV 0.98.5 beta has been posted! > > The ClamAV team is proud to announce the availability of ClamAV 0.98.5 > beta ready for testing! > > > > http://blog.clamav.net/2014/07/clam

Re: [clamav-users] Libclamav :: Issue with version 0.98.4 on FC20 - Can't load /usr/local/share/clamav/daily.cvd: Can't allocate memory

2014-08-08 Thread Shawn Webb
On Fri, Aug 8, 2014 at 8:44 AM, Chinmay Mahata < chinmay_mah...@rediffmail.com> wrote: > Hi, >     I need to use clamav library in one of my modules. I > downloaded latest version of clamav (clamav-0.98.tar.gz) and installed on > my system FC-20. Then I built the code in example directory and tire

Re: [clamav-users] clamav 98.4 for SuSE 10

2014-08-27 Thread Shawn Webb
On Wed, Aug 27, 2014 at 11:57 AM, Mario O. Sgattoni < mario.sgatt...@ensi.com.ar> wrote: > My Clamav update process had notified me that the versión 98.4 is the last > stable versión, but I couldn’t finde it yet at the SuSE repositories. The > last versión there is 98.1. > > > > How long would it

Re: [clamav-users] Why are the ClamAV team so slow at creating signatures ?

2014-10-06 Thread Shawn Webb
On Mon, Oct 6, 2014 at 9:37 AM, Tim Smith wrote: > > are you really trying to compare response times from PAID sollutions to > the free/community maintened ones > > Of course not, the paid solutions will always be better. > > But three days to get some definitions pushed out for a zero-day i

Re: [clamav-users] Who can I contact because of inconsitent mirrors?

2014-10-28 Thread Shawn Webb
On Tue, Oct 28, 2014 at 11:35 AM, Denny Bortfeldt wrote: > $:/# wget http://database.clamav.net/daily-19533.cdiff > --2014-10-28 16:34:26-- http://database.clamav.net/daily-19533.cdiff > Resolving database.clamav.net (database.clamav.net)... 46.4.205.40, > 62.27.56.14, 62.201.161.84, ... > Conne

Re: [clamav-users] FreshClam problem | MailScanner setup

2014-10-29 Thread Shawn Webb
On Wed, Oct 29, 2014 at 12:14 PM, Mark Meelhuysen wrote: > Hello, > > I recently installed a CentOS system running MailScanner, ClamAV, > SpamAssassin and greylisting. > Since I solved another problem, for which I opened many configfiles, my > freshclam does nto update automatically anymore. My M

Re: [clamav-users] Error using libclamav (cli_scanraw error)

2014-11-04 Thread Shawn Webb
On Tue, Nov 4, 2014 at 12:27 PM, Alessandro Vesely wrote: > Hi, > I use libclamav to have a mail filter scan mail. It works fine at mine. > However, I shared the code with someone and it doesn't work at his --he > reads in BCC. We both use 0.98.4. We managed to run the same test with > debug e

Re: [clamav-users] clamav-milter & logrotation

2014-11-17 Thread Shawn Webb
On Mon, Nov 17, 2014 at 4:56 AM, Andreas Schulze wrote: > Hello, > > I run clamd. Logs are written without syslog and rotated using logrotate: > - move old logfile away > - touch new logfile > - send clamd a SIGHUP > > that work without service interuption. > > Now I installed clamav-milter an

Re: [clamav-users] 0.98.5 installation error

2014-11-19 Thread Shawn Webb
On Wed, Nov 19, 2014 at 6:13 AM, Schleusener, Jens wrote: > On Wed, 19 Nov 2014, nikos wrote: > >> >> Hello list >> I try to install 0.98.5 from source as I always do, and I got the error: >> ERROR: This tool requires libclamav with functionality level 79 or >> higher (current f-level: 77) >> The

Re: [clamav-users] Clamsubmit option -p

2014-12-01 Thread Shawn Webb
On Sat, Nov 29, 2014 at 10:26 PM, Benny Pedersen wrote: > Is the help text correct ? > > Fase possitive ? > > If running clamsubmit do i need to extract content first with eg ripmine if > content is in email or does clamsubmit self do all this ? > > What is a fp and fn ? No need to extract files

Re: [clamav-users] (no subject)

2014-12-22 Thread Shawn Webb
On Sun, Dec 21, 2014 at 9:04 AM, jpff wrote: > Since building 0.98.5 I am seeing > > ERROR: This tool requires libclamav with functionality level 79 or higher > (current f-level: 77) > > when updating rules. I assume I have some mis-configuration but what? > ==John ff Hey John, You can take a

Re: [clamav-users] Downloading trouble

2014-12-24 Thread Shawn Webb
On Wed, Dec 24, 2014 at 12:40 PM, Nele Ysebaert wrote: > Hi there (second posting), > > Trying to download the latest version of Clamwin, I just ended up in a > loop. It didn't work: on hitting the download button, I saw a countdown > screen, but after that I was just redirected to the former sc

Re: [clamav-users] Trying to track down bug using lsof & clamscan/clamdscan.. odd behavior

2015-08-28 Thread Shawn Webb
On Thursday, 27 August 2015 01:48:00 PM Charles Swiger wrote: > On Aug 27, 2015, at 1:13 PM, Alexander Urcioli wrote: > > We were running into an issue where larger files were not able to be moved > > after scanning with ClamAV. Our hypothesis was that perhaps the process > > has > > not released

Re: [clamav-users] Trying to track down bug using lsof & clamscan/clamdscan.. odd behavior

2015-08-28 Thread Shawn Webb
ned! Thanks everyone. > > On Fri, Aug 28, 2015, 12:31 Shawn Webb wrote: > > On Thursday, 27 August 2015 01:48:00 PM Charles Swiger wrote: > > > On Aug 27, 2015, at 1:13 PM, Alexander Urcioli > > > > wrote: > > > > We were running into an iss

Re: [clamav-users] Communigate Pro parser fails

2012-09-06 Thread Shawn Webb
Were you able to scan with versions of ClamAV prior to 0.97.5? Can you send me some samples? Thanks, Shawn On Thu, Sep 6, 2012 at 6:15 AM, Victor Sudakov wrote: > Colleagues, > > AFAIK clamd can parse Communigate Pro message spool format, where the > message itself is preceded by several extra

Re: [clamav-users] Windows versions of ClamAV 0.97.6 posted!

2012-09-19 Thread Shawn Webb
Paul, As of 0.97.5, we do not generate CAB or ZIP files for binary builds. The last published ZIP file was for 0.97.4 and is located on Sourcefore. Since MSI files can be extracted, we haven't provided CAB/ZIP files. Thanks, Shawn Webb On Wed, Sep 19, 2012 at 10:03 AM, Joel Esler wrote:

Re: [clamav-users] Help to download ClamAV 0.97.6 tar.gz source code

2012-10-01 Thread Shawn Webb
On Mon, Oct 1, 2012 at 10:33 AM, Noel Jones wrote: > This makes getting source code unnecessarily complicated; lots of > folks do not use a browser on their production server. Please > remove the offending web code immediately. I'm a little confused. From what page would you like the browser det

Re: [clamav-users] Virus names - a rose by any name?

2013-01-12 Thread Shawn Webb
In addition to having the same sentiments Joel has, I'd like to explain why not displaying the name of the virus does not add any extra security for a number of reasons: 1. Attackers can already "deduce" ClamAV's engine because it's opensource. They have the blueprints. They already know how it wo

Re: [clamav-users] Solaris 10 UFS Support?

2013-01-23 Thread Shawn Webb
ClamAV does not currently support scanning file-backed UFS containers. The closest thing that it does support is ISO files. If you can mount the UFS container, ClamAV can scan the mountpoint. Thanks, Shawn On Jan 23, 2013 7:59 AM, "Peter Bonivart" wrote: > On Wed, Jan 23, 2013 at 11:59 AM, Jos

Re: [clamav-users] Question about a virus

2013-01-30 Thread Shawn Webb
Additionally, if you (April) can provide an MD5 or SHA1 of the sample in question, I can look up if we have coverage for it. On Wed, Jan 30, 2013 at 10:25 AM, Al Varnell wrote: > On Jan 30, 2013, at 6:50 AM, April Wilson wrote: > > > My question is can ClamAV block a certain virus? The name wh

Re: [clamav-users] Is there a way to download old clamAV cvd file from 2007, 2009, 2011 etc.?

2013-02-04 Thread Shawn Webb
knew what you really wanted to do with them, we could figure out a solution that could benefit multiple people. Thanks, Shawn Webb ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] I would like to discuss sample submission with a ClamAV team member

2013-02-12 Thread Shawn Webb
On Tue, Feb 12, 2013 at 7:51 PM, Al Varnell wrote: > On 2/12/13 4:13 PM, "Dave Michmerhuizen" wrote: > > > I have a regular feed of very new malicious email attachments that are > not > > detected by ClavAV (which we use.) I would like to share them with the > > ClamAV team, preferably in an

Re: [clamav-users] daily-16682.cdiff not found on remote server

2013-02-14 Thread Shawn Webb
On Thu, Feb 14, 2013 at 10:59 AM, Matthias Egger wrote: > Hello > > Since about two hours we get the following Errors while updating with > freshclam: > > ClamAV update process started at Thu Feb 14 16:51:42 2013 > main.cvd is up to date (version: 54, sigs: 1044387, f-level: 60, builder: > sven)

Re: [clamav-users] Database Mirror Issues

2013-02-14 Thread Shawn Webb
On Thu, Feb 14, 2013 at 11:00 AM, Clayton Keller wrote: > Within the past hour we have started seeing the following errors reported > when running freshclam: > > ERROR: getpatch: Can't download daily-16682.cdiff from db.us.clamav.net > ERROR: Can't download daily.cvd from db.us.clamav.net > ERROR:

Re: [clamav-users] TTL on the current.cvd.clamav.net TXT resource record.

2013-02-15 Thread Shawn Webb
We temporarily bumped the TTL up to three hours yesterday to ease the burden on the mirrors while we pushed out a change that would cause a lot of bandwidth. The TTL will be set back to its previous value soon. On Fri, Feb 15, 2013 at 7:26 AM, Kees Theunissen wrote: > The "ClamAV Virus Databases

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
Due to some hiccups with pushing out a custom daily.cvd I tried to do, you will need to delete the daily.cvd you have. You will download a fresh daily.cvd. Sorry for any inconvenience. On Fri, Feb 15, 2013 at 6:13 PM, Lee Graves wrote: > Here it is in verbose mode. > > WARNING: Can't download d

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
It applies to those who are stuck on updates prior to daily.cvd version 16685. On Fri, Feb 15, 2013 at 6:31 PM, Al Varnell wrote: > On Feb 15, 2013, at 3:24 PM, Shawn Webb wrote: > > > Due to some hiccups with pushing out a custom daily.cvd I tried to do, > you > > wi

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
On Fri, Feb 15, 2013 at 8:24 PM, Lee Graves wrote: > Is there any other way around this? It wouldn't be a big deal if it > was just a few boxes, but we've got quite a lot affected by this. > I wish there was, but there is not. I'm sorry for the inconvenience.

Re: [clamav-users] Freshclam: Error creating socket

2013-02-25 Thread Shawn Webb
Can you paste the whole log, please? On Mon, Feb 25, 2013 at 9:02 AM, Massimo Rossi wrote: > Hi to all, > > > I'm having an issue updating clamav virus definitions on a CentOS 5 > server. When I launch freshclam I obtain "ERROR: Can't create new socket". > Using clamav or root user doesn't reso

Re: [clamav-users] Freshclam: Error creating socket

2013-02-25 Thread Shawn Webb
On Mon, Feb 25, 2013 at 9:22 AM, Massimo Rossi wrote: > ERROR: Can't create new socket > WARNING: getpatch: Can't download daily-16682.cdiff from > clamav.mirror.garr.it > ERROR: Can't create new socket > WARNING: getpatch: Can't download daily-16682.cdiff from > clamav.mirror.garr.it > ERROR: Can

Re: [clamav-users] llvm library

2013-03-15 Thread Shawn Webb
to the nature of our modifications, we can't simply submit patches upstream. We've essentially forked LLVM's source and included the fork within ClamAV's source code. I hope that helps answer your questions. Let me know if you have any further questions or comments. Than

Re: [clamav-users] http://blog.clamav.net/2013/02/resolving-issues-with-freshclam.html

2013-03-26 Thread Shawn Webb
was generated by mistake with the wrong version of ClamAV. Your database, which shows an f-level of 63, is correct. You're good to go. Thanks, Shawn Webb ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] SubmitDetectionStats error message after update

2013-03-26 Thread Shawn Webb
On Tue, Mar 26, 2013 at 11:09 AM, Jerry wrote: > On Tue, 26 Mar 2013 08:59:19 -0400 > Matt Olney articulated: > > > Jerry, is this still an issue for you? Our systems team says there > > was an issue with the box but that has been resolved. > > > > Please let us know, > > This is the output from

Re: [clamav-users] SubmitDetectionStats error message after update

2013-03-27 Thread Shawn Webb
On Tue, Mar 26, 2013 at 1:10 PM, Jerry wrote: > On Tue, 26 Mar 2013 12:14:52 -0400 > Shawn Webb articulated: > > > What version of ClamAV were you running before you updated and what > > version are you running now? > > I am running FreeBSD-8.3 amd64. From the p

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
Hey Scott, This is a known bug in ClamAV 0.97. We've addressed and fixed it in 0.98. Development is ongoing on 0.98 and there isn't a firm release date, yet. Thanks, Shawn On Thu, Apr 11, 2013 at 9:13 AM, Scott Ehrlich wrote: > Making more progress - > > using --scan-mail=yes and --max-scansi

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
es_ work now, what are the needed switches/options to make it > work? > > Thanks. > > Scott > > On Thu, Apr 11, 2013 at 9:32 AM, Shawn Webb wrote: > > > Hey Scott, > > > > This is a known bug in ClamAV 0.97. We've addressed and fixed it in 0

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
ults with a 1.5 GB file (thus, less than 2 GB). > > What is the best way to scan it? > > Thanks. > > Scott > > On Thu, Apr 11, 2013 at 9:42 AM, Shawn Webb wrote: > > > Hey Scott, > > > > The bug is that ClamAV 0.97 doesn't support scanning large file

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
i_updatelimits: filesize exceeded (allowed: abc, needed: xyz) > > How to fix this? > > Thanks. > > Scott > > On Thu, Apr 11, 2013 at 9:59 AM, Shawn Webb wrote: > > > Interesting. Can you send me the log file from clamscan or clamd > (whichever > > you're

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
ning: fmap: map allocation failed > libclamav Error: CRITICAL: fmap() failed > /path/to/mbox-file: Cannot allocate memory ERROR > > The file is about 1.6 GB. > > Thanks. > > Scott > > On Thu, Apr 11, 2013 at 12:20 PM, Shawn Webb wrote: > > > Hey Scott, > &

  1   2   >