RE: mail antivirus





-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx
[mailto:listbounce@xxxxxxxxxxxxxxxxx] On Behalf Of Tom Walsh
Sent: 23 August 2007 19:09
To: focus-linux@xxxxxxxxxxxxxxxxx
Subject: RE: mail antivirus

ClamAV. http://www.clamav.net/

Open Source. Virus definitions automatically updated with new
definitions via freshclam. New strains added very quickly.
Client / Server model.

We use a shell script to make clamscan work with maildrop
xfilter and it works very well.

No complaints other than some issues with the code base
evolving a little to quickly which can make it difficult to
keep up to date (some newer virus definitions will not work
with an older version of clamscan so you need to check the
logs of freshclam occasionally for "WARNING: Your ClamAV
installation is OUTDATED!" and update when needed).

It is evolving rapidly for a very good reason:

<http://search.securityfocus.com/swsearch?query=clamav&sbm=archive%2F1%2F&submit=Search%21&metaname=alldoc&sort=swishlastmodified>

Yes, that's 7 pages of vulnerabilities over the last 3 years.

They ClamAV developers have a very commendable attitude to
fixing security issues, but you do have to keep an eye out
on the bugtrack list for the weekly issues. Shame I cannot
say the same about some very popular mailservers. YMMV.


Paul



Relevant Pages

  • [Full-disclosure] DMA[2006-0514a] - ClamAV freshclam incorrect privilege drop
    ... Tomasz Kojm of the ClamAV team describes the following code snippet from freshclam as being "for system administrators who know ... components of ClamAV because some of them contain code that is intended to be "for system administrators who know what they're doing". ...
    (Full-Disclosure)
  • DMA[2006-0514a] - ClamAV freshclam incorrect privilege drop
    ... Tomasz Kojm of the ClamAV team describes the following code snippet from freshclam as being "for system administrators who know ... components of ClamAV because some of them contain code that is intended to be "for system administrators who know what they're doing". ...
    (Bugtraq)
  • Re: ClamAv: is anyone paying attention?
    ... 0.88.5 was released Oct 15 according to the ClamAv ... downloads clamav virus databases from the Internet ... This package contains the program freshclam and scripts to automate ... problems in freshclam and other minor bugfixes. ...
    (Ubuntu)
  • Re: clamav: uptodate or not?
    ... When i run the gui antivirus scanner that uses clamav, ... as freshclam needs to be setuid clamav. ... The freshclam program updates the databses, ... The OP needs to check on why the mirrors are not connecting. ...
    (Debian-User)
  • Re: ClamAv: is anyone paying attention?
    ... WARNING: Your ClamAV installation is OUTDATED! ... The main signatures are up to date ... system monitor and freshclam is currently running. ...
    (Ubuntu)