[sanesecurity] Re: SaneSecurity Signatures

  • From: Sujit Acharyya-choudhury <s.choudhury@xxxxxxxxx>
  • To: "sanesecurity@xxxxxxxxxxxxx" <sanesecurity@xxxxxxxxxxxxx>
  • Date: Tue, 31 May 2016 17:22:55 +0000

Following on from my earlier message, not many people will regret having seen 
their mail, which would have destined for junk mail box to be blocked at SMTP 
time due to extra signatures of SaneSecurity being added to ClamAV.
However, it would be helpful to know, that the configuration with LOW in the 
config file, signatures are fairly safe to use with ClamAV in our situation.

Regards

Sujit


-----Original Message-----
From: sanesecurity-bounce@xxxxxxxxxxxxx 
[mailto:sanesecurity-bounce@xxxxxxxxxxxxx] On Behalf Of Sujit ;
Acharyya-choudhury
Sent: 31 May 2016 16:42
To: sanesecurity@xxxxxxxxxxxxx
Subject: [sanesecurity] Re: SaneSecurity Signatures

Hi Steve,
Thanks for your e-mail.  However, I am using clamd to check for virus and
adding the "LOW" SaneSecurity signatures to improve ClamAV, which is not very
useful without SaneSecurity.  What you are suggesting I think is ideal for
amavisd-new.  However, in our Exim config, we have the following line:
av_scanner = clamd:193.61.xx.yy 3310

and the machine 193.61.xx.yy is used solely for ClamAV and now for ClamAV plus
SaneSecurity signatures.   How can I change the configuration to ensure that
the VIRUS will be marked as VIRUS and others as SPAM in this set up?

Regards

Sujit




-----Original Message-----
From: sanesecurity-bounce@xxxxxxxxxxxxx
[mailto:sanesecurity-bounce@xxxxxxxxxxxxx] On Behalf Of Steve Basford
Sent: 31 May 2016 16:25
To: sanesecurity@xxxxxxxxxxxxx
Subject: [sanesecurity] Re: SaneSecurity Signatures


On Tue, May 31, 2016 4:16 pm, Sujit Acharyya-choudhury wrote:

I am trying out SaneSecurity signatures and finding out that many of the
so called "VIRUS" are not exactly virus, but marketing e-mail, albeit can
be considered junk.  How can I distinguish between real Virus and Junk
mail, marked as Virus?

Hi Sujit,

You probably need to look at spam_score_maps, to "split" malware/spam etc.

There an example config here:

http://sanesecurity.com/support/problems/

Cheers,

Steve
Sanesecurity.com


Attachment: smime.p7s
Description: S/MIME cryptographic signature

Other related posts: