Re: sophie 3.04 libsavi 3.94
Scott Walker <[email protected]> Fri, 24 Jun 2005 14:39:58 -0700
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <OF7E5356A2.32362E30-ON8825702A.0075DC80-8825702A.00770408@sophos.com> |
Dave, We don't really have a 'Best Practices' configuration as far as I know since how the engine is configured is largely dependant on the environment it which it is being used. That being said, I would also include GrpExecutable and GrpMSOffice with GrpArchiveUnpack, GrpSelfExtract, and GrpInternet, although most of the options in GrpExecutable and GrpMSOffice are already on by default. For most cases, sticking with the groups is your best bet. Another option to note is EnabledAutoStop, which is off by default. Turning it on instructs the engine to abort scans of files that it 'thinks' are zip bombs (files that take excessive system resources to scan). I said 'think' because the engine uses a heuristic approach to determine if the file is a zip bomb, which means that it could be wrong in some cases. This would result in a legitimate file being flagged as a zip bomb, which is why I believe it is off by default. However, I think the protection it provides outweighs this risk. Scott. [email protected] wrote on 06/22/2005 04:19:12 PM: > Thanks very much Scott, > > What is your suggestion. > > Should we only use the Grp options? > > - I would assume that Sophos updates these as changes in viruses and > compression standards occur. > > What Grp options are the suggested 'Best Practices' a while back > Sophos said to > set GrpArchiveUnpack, GrpSelfExtract, and GrpInternet to 1. This looks like it > end up covering all the issues. Is that still the best advise? > > ie: With only the above Grp options set I see: > > +-----------------------------------+------+-----+ > | Configuration parameter | Type |Value| > +-----------------------------------+------+-----+ > | GrpSuper | 9 | 2 | > | GrpArchiveUnpack | 9 | 2 | > | GrpSelfExtract | 9 | 2 | > | GrpExecutable | 9 | 2 | > | GrpInternet | 9 | 2 | > | GrpMSOffice | 9 | 2 | > | GrpMisc | 9 | 2 | > | GrpDisinfect | 9 | 2 | > | GrpClean | 9 | 2 | > | PEHandling | 3 | 1 | > | Emulation | 3 | 1 | > | PeEmulator | 3 | 1 | > | DynamicDecompression | 3 | 1 | > | Upx | 3 | 1 | > | ASPack | 3 | 1 | > | Fsg | 3 | 1 | > | PECompact | 3 | 1 | > | ExecFileDisinfection | 3 | 1 | > | Ole2FileDisinfection | 3 | 1 | > | Elf | 3 | 1 | > | MachO | 3 | 1 | > | SfxArchives | 3 | 1 | > | ConcatenatedArchives | 3 | 0 | > | ZipDecompression | 3 | 1 | > | ZipUseChd | 3 | 1 | > | ArjDecompression | 3 | 1 | > | RarDecompression | 3 | 1 | > | UueDecompression | 3 | 1 | > | GZipDecompression | 3 | 1 | > | CmzDecompression | 3 | 1 | > | MSCabinet | 3 | 1 | > | ISCabinet | 3 | 1 | > | ISCabinetFull | 3 | 1 | > | ITSS | 3 | 0 | > | TarDecompression | 3 | 1 | > | TnefAttachmentHandling | 3 | 1 | > | TnefEmbedHandling | 3 | 0 | > | Lha | 3 | 1 | > | MSCompress | 3 | 1 | > | ActiveMimeHandling | 3 | 1 | > | Pdf | 3 | 1 | > | HqxDecompression | 3 | 1 | > | MbinDecompression | 3 | 1 | > | AppleSingle | 3 | 1 | > | Bzip2 | 3 | 1 | > | Stuffit | 3 | 1 | > | LoopBackEnabled | 3 | 0 | > | OpenMacRf | 3 | 1 | > | PalmPilotHandling | 3 | 1 | > | Rtf | 3 | 1 | > | Html | 3 | 1 | > | OLE2Handling | 3 | 1 | > | WordB | 3 | 1 | > | VBA3Handling | 3 | 1 | > | VbaOnly | 3 | 0 | > | VBA5Handling | 3 | 1 | > | DecompressVBA5 | 3 | 1 | > | Vba5p | 3 | 0 | > | ExcelFormulaHandling | 3 | 1 | > | ProjectHandling | 3 | 1 | > | ScrapObjectHandling | 3 | 1 | > | VisioFileHandling | 3 | 1 | > | VisioEmbedHandling | 3 | 0 | > | OleDataMsoHandling | 3 | 1 | > | OleScriptHandling | 3 | 1 | > | OleRawHandling | 3 | 1 | > | SrpStreamHandling | 3 | 1 | > | Office2001Handling | 3 | 1 | > | Vba5Dir | 3 | 0 | > | PowerPointMacroHandling | 3 | 1 | > | PowerPointEmbeddedHandling | 3 | 1 | > | IgnoreTemplateBit | 3 | 1 | > | OF95DecryptHandling | 3 | 1 | > | DelVBA5Project | 3 | 1 | > | Msi | 3 | 0 | > | HelpHandling | 3 | 1 | > | Skip | 3 | 1 | > | Mime | 3 | 1 | > | MimeReScan | 9 | 2 | > | MimeEmbedded | 3 | 1 | > | Base64 | 3 | 1 | > | Vbe | 3 | 1 | > | OutlookExpress | 3 | 1 | > | VbFiltering | 3 | 1 | > | UTF16 | 3 | 1 | > | Java | 3 | 1 | > | Access | 3 | 1 | > | CleanJpeg | 3 | 1 | > | CleanBmp | 3 | 1 | > | CleanGif | 3 | 1 | > | CleanRiff | 3 | 1 | > | CleanTiff | 3 | 1 | > | CleanPng | 3 | 1 | > | CleanMp3 | 3 | 1 | > | CleanMpeg | 3 | 1 | > | Xml | 3 | 0 | > | FullMacroSweep | 3 | 0 | > | FullPdf | 3 | 0 | > | FullSweep | 3 | 0 | > | StorageReport | 3 | 0 | > | StorageReportAll | 3 | 0 | > | StorageDetOnly | 3 | 0 | > | DeleteAllMacros | 3 | 0 | > | UnixArchive | 3 | 1 | > | Rpm | 3 | 1 | > | Saveset | 3 | 0 | > | MaxRecursionDepth | 2 | 16 | > | MaxIntRecDepth | 2 | 25 | > | NamespaceSupport | 3 | 0 | > | VirusDataDir | 10 | /usr/local/sweep/sav > | VirusDataName | 10 | vdl > | IdeDir | 10 | /usr/local/sweep/sav > | AllowPartialVirusData | 3 | 0 | > | EnableAutoStop | 3 | 0 | > +-----------------------------------+------+-----+ > > > > > Quoting Scott Walker <[email protected]>: > > > There are two things going on here. > > > > 1) Grp options are always reported as 2 by the engine. The only way to > > confirm that a group option is set is to look at one of the options it > > sets. > > For example, toggle GrpArchiveUnpack and watch the ZipDecompression option. > > > > 2) However, there is still an error. The configuration file lists the Grp > > options first and the individual options next. It also (for some reason) > > lists _all_ the individual options. Sophie reads the config file from top > > to bottom, so it first sets the groups, then overwrites any options the > > groups may have set by setting the individual options (thus making the > > group options useless). There really is no need for all options to be > > listed in the default config file. You should only list the options you > > want to change from their default. > > > > Try commenting out ZipDecompression in the config file and toggling the > > GrpArchiveUnpack option, you should see ZipDecompression change. > > > > Scott. > > > > > > > > [email protected] wrote on 06/22/2005 01:44:32 PM: > > > > > Hello - I think we have uncovered a signifigant Sophie problem that may > > be the > > > cause of this error. > > > > > > I see that 3.04rc2 and 3.04 operate the same in this and so it is a long > > > standing issue. > > > > > > Issue: sophie.savi GrpXXX settings are not respected. > > > > > > With testing via 'sophie -c' to show Sophie's configuration I have > > > seen that the > > > Grp settings are not picked up. They do not change for the default '2'. > > > > > > Can anyone confirm this? > > > > > > Dave, > > > > > > Quoting Ronan <[email protected]>: > > > > > > > hi all, > > > > As with most of you i was getting the ERROR stream corrupted blabla > > > > with libsavi 3.93 and even 3.93.2(which was released at the time to try > > > > and fix the sophie incompatibilty) After reading and AIUI sophos are > > not > > > > going to unmake the changes to libsavi for whatever reason and thats > > why > > > > 3.04 final was released... > > > > > > > > Unfortunately, now I am no longer getting any stream corrupted errors > > > > but in actual fact am getting apparently no scanning now at all.... > > > > > > > > I run the latest exim on my smtp server and have running both clamav > > and > > > > sophie on every message. Sophie is first preference because we have a > > > > site licence for it and clamav runs second... im healthily paranoid! > > > > > > > > however when testing with GTUBE sophie doesnt appear to catch or indeed > > > > log anything whereas clamav as expected detects and sends a > > 550message... > > > > > > > > any clues as to why its not even scanning now?? > > > > > > > > libsavi 3.94 > > > > sophie 3.04 (compiled 32bit becuase of libsavi ) > > > > Slamd64 (slackware 10.1 64bit linux on dual opterons) > > > > /lib/libc.so.6 > > > > GNU C Library stable release version 2.3.2, by Roland McGrath et al. > > > > > > > > any other info needed?? > > > > > > > > ronan > > > > > > > > > > > > > > > > _______________________________________________ > > > > vtools mailing list > > > > [email protected] > > > > http://www.vanja.com/list/listinfo.cgi/vtools > > > > > > > > > > > > > -- > > > David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP > > > 250.721-6307 [email protected] FIA 221 > > > _______________________________________________ > > > vtools mailing list > > > [email protected] > > > http://www.vanja.com/list/listinfo.cgi/vtools > > > > > > -- > > Scott Walker > > Software Integration & Support Engineer, Sophos > > > > Tel: 604 484 6883 > > Web: www.sophos.com > > Sophos - protecting businesses against viruses and spam > > > > _______________________________________________ > > vtools mailing list > > [email protected] > > http://www.vanja.com/list/listinfo.cgi/vtools > > > > > -- > David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP > 250.721-6307 [email protected] FIA 221 > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools -- Scott Walker Software Integration & Support Engineer, Sophos Tel: 604 484 6883 Web: www.sophos.com Sophos - protecting businesses against viruses and spam