[sanesecurity] Re: Sanesecurity.Jurlbl.5624.UNOFFICIAL matches "com"

  • From: sanesecurity@xxxxxxxxxxxx
  • To: sanesecurity@xxxxxxxxxxxxx
  • Date: Tue, 14 Jul 2009 15:45:50 +0100

Tom Shaw wrote:

I think the "com" listing and the "acebook.com" listing from less than 2 months ago prove that there should be some sort of checking against ham in the main script. It shouldn't be a particular difficult thing to implement as all you have to do is run a "clamscan -d /path/to/new/signatures /path/to/some/ham" and parse the output. Unfortunately I'm not that great on shell scripting. If it was perl, I'd write a patch and submit it.

Please contribute a perl script to do that. Folks can either use or not and Bill and Gerard could incorporate or not.

FYI, I released a script for the old download method under the GPL back in 2007, which you can see here: https://secure.grepular.com/projects/clamav_sanesecurity.txt

With the move to rsync and gpg signatures, that script no longer works. I'd consider updating it and adding the latest GPG stuff and HAM scanning, but Bill has already said he'd look into it, so it seems like I would just be duplicating work.

--
Mike Cardwell - IT Consultant and LAMP developer
Cardwell IT Ltd. (UK Reg'd Company #06920226) http://cardwellit.com/

Other related posts: