//  
BlueQuartz.US Forum Index HOME
BlueQuartz.US
Open Source Info for Open Source Users
RegisterRegister 
MemberlistMemberlist
UsergroupsUsergroups
FAQFAQ   
SearchSearch
SubscriptionsSubscriptions
ProfileProfile   
Private messagesPrivate messages   
Log inLog in 
Are You Paying More Than Wholesale For Your Names?   Join the Hottest Domain Name Reseller Program Around!

 
Post new topic   Reply to topic    BlueQuartz.US Forum Index -> ClamAV Users
 Cannot get a single hit on ClamAV + Google Safe Browsing Previous Topic
Next Topic
Message Author
PostPosted: Fri Jul 30, 2010 8:44 am    
Subject: Cannot get a single hit on ClamAV + Google Safe Browsing
Reply with quote  
Jonathan Bastien-Filia...

Hi,

I have recently enabled Google Safe Browsing on several of our servers
(we are a small spam filtering company). Many thousand mails go through
these servers each day. ClamAV shows that it now has many more
signatures (1464127+).

Not a single Google Safe Browsing hit was recorded in the ClamAV logs
over several days. My attempts to get a test URL to match have all
failed. The URL I am using for testing is
<http://malware.testing.google.test/testing/malware/>. This link, when
opened in Firefox warns that it is a malicious site. Mail scanning and
other relevant features are enabled.

I have attached the test email that does not match (but should).

ClamAV version:
ClamAV 0.96.1/11465/Fri Jul 30 07:43:50 2010

Enabled scanning features (as shown in clamd log):
Archive support enabled.
Algorithmic detection enabled.
Portable Executable support enabled.
ELF support enabled.
Mail files support enabled.
OLE2 support enabled.
PDF support enabled.
HTML support enabled.

Phishing config in clamd.conf:
PhishingSignatures true

PhishingScanURLs true

PhishingAlwaysBlockSSLMismatch false

PhishingAlwaysBlockCloak false

SafeBrowsing yes (in freshclam.conf)

Thanks,
Jonathan




_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml
Back to top
PostPosted: Fri Jul 30, 2010 8:47 am    
Subject: Cannot get a single hit on ClamAV + Google Safe Browsing
Reply with quote  
Jonathan Bastien-Filia...

Jonathan Bastien-Filiatrault wrote:
Quote:
Hi,

I have recently enabled Google Safe Browsing on several of our servers
(we are a small spam filtering company). Many thousand mails go through
these servers each day. ClamAV shows that it now has many more
signatures (1464127+).

Not a single Google Safe Browsing hit was recorded in the ClamAV logs
over several days. My attempts to get a test URL to match have all
failed. The URL I am using for testing is
<http://malware.testing.google.test/testing/malware/>. This link, when
opened in Firefox warns that it is a malicious site. Mail scanning and
other relevant features are enabled.

I have attached the test email that does not match (but should).

Mailman ate the attachment, you may find the file here:
http://x2a.org/pub/misc/gsb.eml

Quote:

ClamAV version:
ClamAV 0.96.1/11465/Fri Jul 30 07:43:50 2010

Enabled scanning features (as shown in clamd log):
Archive support enabled.
Algorithmic detection enabled.
Portable Executable support enabled.
ELF support enabled.
Mail files support enabled.
OLE2 support enabled.
PDF support enabled.
HTML support enabled.

Phishing config in clamd.conf:
PhishingSignatures true
PhishingScanURLs true
PhishingAlwaysBlockSSLMismatch false
PhishingAlwaysBlockCloak false

SafeBrowsing yes (in freshclam.conf)

Thanks,
Jonathan


------------------------------------------------------------------------

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml
Back to top
PostPosted: Fri Jul 30, 2010 10:53 am    
Subject: Cannot get a single hit on ClamAV + Google Safe Browsing
Reply with quote  
Török Edwin

On Fri, 30 Jul 2010 09:47:18 -0400
Jonathan Bastien-Filiatrault <joe@x2a.org> wrote:

Quote:
Jonathan Bastien-Filiatrault wrote:
Quote:
Hi,

I have recently enabled Google Safe Browsing on several of our
servers (we are a small spam filtering company). Many thousand
mails go through these servers each day. ClamAV shows that it now
has many more signatures (1464127+).

Not a single Google Safe Browsing hit was recorded in the ClamAV
logs over several days.

The safebrowsing code is definetely matching something, we had
bugreports from people asking why their urls are in safebrowsing.cvd,
and our stats page shows it in the top 10 for past 7 days:
Heuristics.Safebrowsing.Suspected-malware_safebrowsing.clamav.net
2010-07-30 02:14
Count: 211041

Quote:
My attempts to get a test URL to match have
Quote:
all failed. The URL I am using for testing is
<http://malware.testing.google.test/testing/malware/>. This link,
when opened in Firefox warns that it is a malicious site. Mail
scanning and other relevant features are enabled.

I have attached the test email that does not match (but should).

Mailman ate the attachment, you may find the file here:
http://x2a.org/pub/misc/gsb.eml

Is this a recent problem? Were you able to match this URL in the past?
Looks like the database doesn't contain that test URL.

Best regards,
--Edwin
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml
Back to top
Display posts from previous:   
Post new topic   Reply to topic    BlueQuartz.US Forum Index -> ClamAV Users All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group