Re: sophie 3.04 libsavi 3.94
David Broome <[email protected]> Wed, 22 Jun 2005 16:19:12 -0700
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
Thanks very much Scott, What is your suggestion. Should we only use the Grp options? - I would assume that Sophos updates these as changes in viruses and compression standards occur. What Grp options are the suggested 'Best Practices' a while back Sophos said to set GrpArchiveUnpack, GrpSelfExtract, and GrpInternet to 1. This looks like it end up covering all the issues. Is that still the best advise? ie: With only the above Grp options set I see: +-----------------------------------+------+-----+ | Configuration parameter | Type |Value| +-----------------------------------+------+-----+ | GrpSuper | 9 | 2 | | GrpArchiveUnpack | 9 | 2 | | GrpSelfExtract | 9 | 2 | | GrpExecutable | 9 | 2 | | GrpInternet | 9 | 2 | | GrpMSOffice | 9 | 2 | | GrpMisc | 9 | 2 | | GrpDisinfect | 9 | 2 | | GrpClean | 9 | 2 | | PEHandling | 3 | 1 | | Emulation | 3 | 1 | | PeEmulator | 3 | 1 | | DynamicDecompression | 3 | 1 | | Upx | 3 | 1 | | ASPack | 3 | 1 | | Fsg | 3 | 1 | | PECompact | 3 | 1 | | ExecFileDisinfection | 3 | 1 | | Ole2FileDisinfection | 3 | 1 | | Elf | 3 | 1 | | MachO | 3 | 1 | | SfxArchives | 3 | 1 | | ConcatenatedArchives | 3 | 0 | | ZipDecompression | 3 | 1 | | ZipUseChd | 3 | 1 | | ArjDecompression | 3 | 1 | | RarDecompression | 3 | 1 | | UueDecompression | 3 | 1 | | GZipDecompression | 3 | 1 | | CmzDecompression | 3 | 1 | | MSCabinet | 3 | 1 | | ISCabinet | 3 | 1 | | ISCabinetFull | 3 | 1 | | ITSS | 3 | 0 | | TarDecompression | 3 | 1 | | TnefAttachmentHandling | 3 | 1 | | TnefEmbedHandling | 3 | 0 | | Lha | 3 | 1 | | MSCompress | 3 | 1 | | ActiveMimeHandling | 3 | 1 | | Pdf | 3 | 1 | | HqxDecompression | 3 | 1 | | MbinDecompression | 3 | 1 | | AppleSingle | 3 | 1 | | Bzip2 | 3 | 1 | | Stuffit | 3 | 1 | | LoopBackEnabled | 3 | 0 | | OpenMacRf | 3 | 1 | | PalmPilotHandling | 3 | 1 | | Rtf | 3 | 1 | | Html | 3 | 1 | | OLE2Handling | 3 | 1 | | WordB | 3 | 1 | | VBA3Handling | 3 | 1 | | VbaOnly | 3 | 0 | | VBA5Handling | 3 | 1 | | DecompressVBA5 | 3 | 1 | | Vba5p | 3 | 0 | | ExcelFormulaHandling | 3 | 1 | | ProjectHandling | 3 | 1 | | ScrapObjectHandling | 3 | 1 | | VisioFileHandling | 3 | 1 | | VisioEmbedHandling | 3 | 0 | | OleDataMsoHandling | 3 | 1 | | OleScriptHandling | 3 | 1 | | OleRawHandling | 3 | 1 | | SrpStreamHandling | 3 | 1 | | Office2001Handling | 3 | 1 | | Vba5Dir | 3 | 0 | | PowerPointMacroHandling | 3 | 1 | | PowerPointEmbeddedHandling | 3 | 1 | | IgnoreTemplateBit | 3 | 1 | | OF95DecryptHandling | 3 | 1 | | DelVBA5Project | 3 | 1 | | Msi | 3 | 0 | | HelpHandling | 3 | 1 | | Skip | 3 | 1 | | Mime | 3 | 1 | | MimeReScan | 9 | 2 | | MimeEmbedded | 3 | 1 | | Base64 | 3 | 1 | | Vbe | 3 | 1 | | OutlookExpress | 3 | 1 | | VbFiltering | 3 | 1 | | UTF16 | 3 | 1 | | Java | 3 | 1 | | Access | 3 | 1 | | CleanJpeg | 3 | 1 | | CleanBmp | 3 | 1 | | CleanGif | 3 | 1 | | CleanRiff | 3 | 1 | | CleanTiff | 3 | 1 | | CleanPng | 3 | 1 | | CleanMp3 | 3 | 1 | | CleanMpeg | 3 | 1 | | Xml | 3 | 0 | | FullMacroSweep | 3 | 0 | | FullPdf | 3 | 0 | | FullSweep | 3 | 0 | | StorageReport | 3 | 0 | | StorageReportAll | 3 | 0 | | StorageDetOnly | 3 | 0 | | DeleteAllMacros | 3 | 0 | | UnixArchive | 3 | 1 | | Rpm | 3 | 1 | | Saveset | 3 | 0 | | MaxRecursionDepth | 2 | 16 | | MaxIntRecDepth | 2 | 25 | | NamespaceSupport | 3 | 0 | | VirusDataDir | 10 | /usr/local/sweep/sav | VirusDataName | 10 | vdl | IdeDir | 10 | /usr/local/sweep/sav | AllowPartialVirusData | 3 | 0 | | EnableAutoStop | 3 | 0 | +-----------------------------------+------+-----+ Quoting Scott Walker <[email protected]>: > There are two things going on here. > > 1) Grp options are always reported as 2 by the engine. The only way to > confirm that a group option is set is to look at one of the options it > sets. > For example, toggle GrpArchiveUnpack and watch the ZipDecompression option. > > 2) However, there is still an error. The configuration file lists the Grp > options first and the individual options next. It also (for some reason) > lists _all_ the individual options. Sophie reads the config file from top > to bottom, so it first sets the groups, then overwrites any options the > groups may have set by setting the individual options (thus making the > group options useless). There really is no need for all options to be > listed in the default config file. You should only list the options you > want to change from their default. > > Try commenting out ZipDecompression in the config file and toggling the > GrpArchiveUnpack option, you should see ZipDecompression change. > > Scott. > > > > [email protected] wrote on 06/22/2005 01:44:32 PM: > > > Hello - I think we have uncovered a signifigant Sophie problem that may > be the > > cause of this error. > > > > I see that 3.04rc2 and 3.04 operate the same in this and so it is a long > > standing issue. > > > > Issue: sophie.savi GrpXXX settings are not respected. > > > > With testing via 'sophie -c' to show Sophie's configuration I have > > seen that the > > Grp settings are not picked up. They do not change for the default '2'. > > > > Can anyone confirm this? > > > > Dave, > > > > Quoting Ronan <[email protected]>: > > > > > hi all, > > > As with most of you i was getting the ERROR stream corrupted blabla > > > with libsavi 3.93 and even 3.93.2(which was released at the time to try > > > and fix the sophie incompatibilty) After reading and AIUI sophos are > not > > > going to unmake the changes to libsavi for whatever reason and thats > why > > > 3.04 final was released... > > > > > > Unfortunately, now I am no longer getting any stream corrupted errors > > > but in actual fact am getting apparently no scanning now at all.... > > > > > > I run the latest exim on my smtp server and have running both clamav > and > > > sophie on every message. Sophie is first preference because we have a > > > site licence for it and clamav runs second... im healthily paranoid! > > > > > > however when testing with GTUBE sophie doesnt appear to catch or indeed > > > log anything whereas clamav as expected detects and sends a > 550message... > > > > > > any clues as to why its not even scanning now?? > > > > > > libsavi 3.94 > > > sophie 3.04 (compiled 32bit becuase of libsavi ) > > > Slamd64 (slackware 10.1 64bit linux on dual opterons) > > > /lib/libc.so.6 > > > GNU C Library stable release version 2.3.2, by Roland McGrath et al. > > > > > > any other info needed?? > > > > > > ronan > > > > > > > > > > > > _______________________________________________ > > > vtools mailing list > > > [email protected] > > > http://www.vanja.com/list/listinfo.cgi/vtools > > > > > > > > > -- > > David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP > > 250.721-6307 [email protected] FIA 221 > > _______________________________________________ > > vtools mailing list > > [email protected] > > http://www.vanja.com/list/listinfo.cgi/vtools > > > -- > Scott Walker > Software Integration & Support Engineer, Sophos > > Tel: 604 484 6883 > Web: www.sophos.com > Sophos - protecting businesses against viruses and spam > > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools > -- David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP 250.721-6307 [email protected] FIA 221