Re: Documenting ClamAV on Fedora?

From: James Kosin (jkosin_at_beta.intcomgrp.com)
Date: 04/12/04

  • Next message: Juan Carlos Inostroza: "Re: How to customize locale for each desktop icon for KDE?"
    Date: Mon, 12 Apr 2004 14:41:38 -0400
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Ron Goulard wrote:

    | On Mon, 2004-04-12 at 00:51, Chris Kloiber wrote:
    |
    |>On Mon, 2004-04-12 at 09:05, Alexander Dalloz wrote:
    |
    |
    |>>define(`confINPUT_MAIL_FILTERS', `clamav')dnl
    |>>
    |>>That is no needed sendmail.mc entry. InputMailFilters is set up
    |>>automatically in sendmail.cf, even if you use multiple milter
    |>>applications. If used though "define" entries have to be placed at top
    |>>of sendmail.mc, in front of FEATURE and INPUT_MAIL_FILTER entries. Last
    |>>in front of the MAILER settings.
    |
    |
    |>Is this somehow better than using procmail to call clamav-milter?
    |
    |
    | What follows can be seen as purely a WildAssedGuess. I haven't been
    | able to test or verify this. If I am wrong, then please simply ignore
    | this post and I'll go sit in the corner with my dunce cap. There are
    | others who can answer much more authoritatively than I.
    |
    | I've observed that by calling clamav-milter (or anything for that
    | matter) via procmail, the entire message is accepted, with or without a
    | virus, spooled to disk, etc., all the normal things, before the scan
    | takes place.
    |
    | Here's the guessing part...
    | Calling clamav-milter from sendmail.cf _appears_ to pick the virus
    | signature out of the incoming data stream and close the connection when
    | one is found, thereby eliminating the extra disk work.
    |
    | That may or may not be what's happening. It's simply my observation.
    | Some could argue that it's a small distinction but on a heavily loaded,
    | high volume server, it may make a difference.
    |
    |
    Ron,

    I can't verify procmail, but sendmail does as you say it cuts the email
    off before getting fully sent. The user sending the email gets a
    message something to the effect "Connection Denied: ClamAV detected a
    virus." Sorry, don't remember the exact phasing and it has been a
    little while since I checked. The maillog does get an entry about the
    virus though. And the connection is terminated real-time (so to
    speak)... Down side, the intended user never sees the email. Important
    or not.

    Up side, viruses don't get in....

    James

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (MingW32)
    Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

    iD8DBQFAeuLic7lFLjBWKW0RAu+qAJ43VGui2Xut5enzS4KdRUDvbgKaegCfS1FQ
    F1D4NgADuvBISFCP14Rh20w=
    =o858
    -----END PGP SIGNATURE-----

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Juan Carlos Inostroza: "Re: How to customize locale for each desktop icon for KDE?"

    Relevant Pages

    • Re: Clicking Links Freezes Programs
      ... RUNDLL32.EXE - Entry Point Not Found" Error Message When You Start Your Computer ... Have you scanned for a virus? ... Mary Sauer MS MVP ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Unwanted files downloading on their own
      ... Check to see if you can remove the program from the Add/Remove Programs ... entry and double click to begin uninstall. ... You can run virus scan using the following URL: ... restore to several different dates but it won't restore to any of them. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: RUNDLL/Updater.dll
      ... Rundll.exe is part of Windows. ... Try looking at the relevant Symantec site for your virus. ... If it is only the entry at startup and you don't have the file, ... Click Startup Programs ...
      (microsoft.public.windowsupdate)
    • Re: strange startup files and win32cfg
      ... >> entry from the RunOnce listing, ... However, after disabling the virus, I ran the searches again and this ... did not run this trojan myself. ...
      (microsoft.public.security.virus)
    • Re: Documenting ClamAV on Fedora?
      ... > Is this somehow better than using procmail to call clamav-milter? ... Calling clamav-milter from sendmail.cf _appears_ to pick the virus ... thereby eliminating the extra disk work. ...
      (Fedora)