ClamAV unofficial rules?

Forum for getting help with Project Gamera, Spamassassin, Clamav, qmail-scanner and other anti-spam tools.
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

ClamAV unofficial rules?

Unread post by faris »

I've noticed that the number of bad messages (spam/phishing rather than actualy badware) that clamav detects and drops has ...errr...dropped significantly recently.

Going through my clamav logs, I'm not seeing anything with "UNOFFICIAL" listed.

Previously I'd see loads of these, which were from the http://sanesecurity.com/clamav/ rulset.

I notice from the above page that there were some issues with a DoS, and that the rules have instead now been mirrored (but with some false positives - out ouf date rules).

Scott, what's your take on this? Those rules were obviously doing a lot of good in the past, though mostly they were picking up spam.

Faris.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Unread post by mikeshinn »

Looks like the SaneSecurity project is on a temporary break. We have an archive of the last good set of signatures and will make them available, but you can see the author isn't supporting them right now.

If he decides to drop the project we may fork the sigs (copyright and licensing issues still be explored by the laywers) and start maintaining them ourselves as they are really good sigs - and stop a lot of spam and phishing. We've seen them do a better job than the commercial services out there in fact.
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Unread post by faris »

I'd definitely like to make use of the last known good set. They were working very well for us.

If you do make them available please can you be sure to let us know where they are supposed to go (i.e which folder)?

Faris.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
Griffith
Forum User
Forum User
Posts: 95
Joined: Tue Dec 07, 2004 1:32 pm

Unread post by Griffith »

Any news on this? Maybe a link where we can download a copy of the signatures? :)
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

We've been maintaining our own mirror with the Atomic version of clamav since last year actually. The updater is /usr/bin/clamav_updater.sh, take a look in there if you want to see how it works.
Griffith
Forum User
Forum User
Posts: 95
Joined: Tue Dec 07, 2004 1:32 pm

Unread post by Griffith »

I actually did :)

I noticed that when I tried to download the scam.ndb, the filesize is 0kb. That means will have to pay to get access to it?
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Unread post by faris »

I was going to ask about that -- if the updater is meant to download the known good rules mirror then something is up - because it doesn't seem to be doing so.

If the filesize is 0kb then that would explain it :-)

Faris.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

Its an upstream problem, SANE is taking a break/was being DoS'd.
Griffith
Forum User
Forum User
Posts: 95
Joined: Tue Dec 07, 2004 1:32 pm

Unread post by Griffith »

We've noticed that:)

Mike said:
Looks like the SaneSecurity project is on a temporary break. We have an archive of the last good set of signatures and will make them available, but you can see the author isn't supporting them right now.
Could we get a copy of that?? :)
Griffith
Forum User
Forum User
Posts: 95
Joined: Tue Dec 07, 2004 1:32 pm

Unread post by Griffith »

Scott: have you considered updating clamav_updater.sh with some of this:
http://www200.pair.com/mecham/spam/Upda ... ity.sh.txt

and include it in gamera?
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

Sure, it would go into the clamav-db package. Fortunately almost all of that is already in there.
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Unread post by faris »

Well, it looks like the sanesecurity site came up, then went back down (as far as the rules are concerned).

Maybe you should sponsor him as well if you have anything left after grsec?

All he needs is a server capable of handling the huge number of requests really.

And his rules rock.

Faris.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
Griffith
Forum User
Forum User
Posts: 95
Joined: Tue Dec 07, 2004 1:32 pm

Unread post by Griffith »

Sanesec rules are back now :)
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Unread post by faris »

yay!
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Unread post by faris »

ok, so the download method/location has changed.

I presume ASL clamav users don't need to worry about this?
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
Post Reply