Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 10th April 2006, 06:11 AM
wprauchholz Offline
Registered User
 
Join Date: Nov 2004
Location: Barcelona - Spain
Age: 49
Posts: 308
Missed ant-virus test

I setup an email server (postfix,dovecot, spanassassinm, amavisd-nre and clamav).
There is a website (https://www.webmail.us/testvirus) which send kind of viruses to you to check security of the installation. From all 26 emails sent, I received 1 with the following text:

Test #23: (Non-Virus): Attachment with a CLSID extension which may hide the real
file extension. <B>This does not include the EICAR virus</B>, however your mail
server should still block this since the CLSID technique can be used to hide the
true extension of a malicious file. ***

If your mail server's virus scanner did not detect this email, it allows some
viruses through! Please note: This test message uses the EICAR test virus, which is
completely benign and contains no viral code. For more information see:
http://www.eicar.org

Is this a lack of clamav viruses database or did I do something wrong in the installation?
Any help is welcomed. Thanks
__________________
Salu2,

Wolfgang
Reply With Quote
  #2  
Old 11th April 2006, 02:48 AM
blammo's Avatar
blammo Offline
Registered User
 
Join Date: May 2004
Location: That toddlin' town...
Posts: 296
This is interesting. Two of these tests also got through ClamAV on my system. It stated that these two did NOT contain the EICAR test virus but it should of been blocked because the technique used could infect a system. I searched on the ClamAV mail list and it discusses the problems with the CLSID extension and the Partial (Fragmented) Vulnerability. Apparently it is a limitation of ClamAV. On the other hand ClamAV did block 23 of the 25 infected emails.
Reply With Quote
Reply

Tags
antvirus, missed, test

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
missed reply test before accepting post marko Suggestions & Feedback 7 6th June 2008 01:18 PM
Im Back!! Was I missed?? kona0197 Wibble 10 9th October 2007 07:11 AM
mail() - what have I missed? LuAn Servers & Networking 15 24th May 2007 08:33 AM
Missed mod_webapp.so !!! Moosa Using Fedora 0 12th February 2006 03:26 PM


Current GMT-time: 05:05 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat