Re: sophie 3.04 libsavi 3.94
[email protected] Mon, 27 Jun 2005 00:23:34 -0700
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
Scott, Just a note of thanks and a final confirmation. This should be a sufficen= t setting for Internet email scanning for the purposes of finding and rejec= ti ng viruses. Sophos will then add new items to these groups in the future: I have added some specific items enabled by these groups. Although note t= ha t many options that cover these categories are on by default. # Executable files. # Enables: Elf, 16-bit x86 Emulation, JAVA, Mach-O, PeEmulator # (32bit Executable emulator), PEHandling (Win32/PE format). GrpExecutable: 1 # All archive and compressed archive file formats (e.g. ZIP, UUE, etc). GrpArchiveUnpack: 1 # File formats that contain an executable stub that automatically # decompresses the body of the file. GrpSelfExtract: 1 # File formats commonly in use on the internet. # Enables: MIME, Base64, OutlookExpress (mailboxes), TnefAttachmentHandli= ng , # VbFiltering. GrpInternet: 1 # Microsoft Office file formats. # Enables: formats with VBA ie PPA, VBA5p. GrpMSOffice: 1 # Causes scanning ro be aborted for files (e.g. "zip bombs") whose # characteristics cause the Virus Engine to consume excessive # System resource (disc, memory, CPU). # Note -- On rare occasions it may be possible for an innocent file # to trigger the AutoStop detection (a =93false positive=94). However, fi= le s # causing SAVI to return ...SCAN_ABORTED should initially be treated # in the same way as one containing a virus. EnableAutoStop: 1 Note the setting is: EnableAutoStop not EnableD..., darn spelling ;-) dave, Quoting Scott Walker <[email protected]>: > Dave, > > We don't really have a 'Best Practices' configuration as far as I know > since how the engine is configured is largely dependant on the environm= en t > it which it is being used. That being said, I would also include > GrpExecutable and GrpMSOffice with GrpArchiveUnpack, GrpSelfExtract, an= d > GrpInternet, although most of the options in GrpExecutable and GrpMSOff= ic e > are already on by default. For most cases, sticking with the groups is > your best bet. > > Another option to note is EnabledAutoStop, which is off by default. > Turning it on instructs the engine to abort scans of files that it 'thi= nk s' > are zip bombs (files that take excessive system resources to scan). I = sa id > 'think' because the engine uses a heuristic approach to determine if th= e > file is a zip bomb, which means that it could be wrong in some cases. = Th is > would result in a legitimate file being flagged as a zip bomb, which is= w hy > I believe it is off by default. However, I think the protection it > provides outweighs this risk. > > Scott. > > > [email protected] wrote on 06/22/2005 04:19:12 PM: > >> Thanks very much Scott, >> >> What is your suggestion. >> >> Should we only use the Grp options? >> >> - I would assume that Sophos updates these as changes in viruses and >> compression standards occur. >> >> What Grp options are the suggested 'Best Practices' a while back >> Sophos said to >> set GrpArchiveUnpack, GrpSelfExtract, and GrpInternet to 1. This looks > like it >> end up covering all the issues. Is that still the best advise? >> >> ie: With only the above Grp options set I see: >> >> +-----------------------------------+------+-----+ >> | Configuration parameter | Type |Value| >> +-----------------------------------+------+-----+ >> | GrpSuper | 9 | 2 | >> | GrpArchiveUnpack | 9 | 2 | >> | GrpSelfExtract | 9 | 2 | >> | GrpExecutable | 9 | 2 | >> | GrpInternet | 9 | 2 | >> | GrpMSOffice | 9 | 2 | >> | GrpMisc | 9 | 2 | >> | GrpDisinfect | 9 | 2 | >> | GrpClean | 9 | 2 | >> | PEHandling | 3 | 1 | >> | Emulation | 3 | 1 | >> | PeEmulator | 3 | 1 | >> | DynamicDecompression | 3 | 1 | >> | Upx | 3 | 1 | >> | ASPack | 3 | 1 | >> | Fsg | 3 | 1 | >> | PECompact | 3 | 1 | >> | ExecFileDisinfection | 3 | 1 | >> | Ole2FileDisinfection | 3 | 1 | >> | Elf | 3 | 1 | >> | MachO | 3 | 1 | >> | SfxArchives | 3 | 1 | >> | ConcatenatedArchives | 3 | 0 | >> | ZipDecompression | 3 | 1 | >> | ZipUseChd | 3 | 1 | >> | ArjDecompression | 3 | 1 | >> | RarDecompression | 3 | 1 | >> | UueDecompression | 3 | 1 | >> | GZipDecompression | 3 | 1 | >> | CmzDecompression | 3 | 1 | >> | MSCabinet | 3 | 1 | >> | ISCabinet | 3 | 1 | >> | ISCabinetFull | 3 | 1 | >> | ITSS | 3 | 0 | >> | TarDecompression | 3 | 1 | >> | TnefAttachmentHandling | 3 | 1 | >> | TnefEmbedHandling | 3 | 0 | >> | Lha | 3 | 1 | >> | MSCompress | 3 | 1 | >> | ActiveMimeHandling | 3 | 1 | >> | Pdf | 3 | 1 | >> | HqxDecompression | 3 | 1 | >> | MbinDecompression | 3 | 1 | >> | AppleSingle | 3 | 1 | >> | Bzip2 | 3 | 1 | >> | Stuffit | 3 | 1 | >> | LoopBackEnabled | 3 | 0 | >> | OpenMacRf | 3 | 1 | >> | PalmPilotHandling | 3 | 1 | >> | Rtf | 3 | 1 | >> | Html | 3 | 1 | >> | OLE2Handling | 3 | 1 | >> | WordB | 3 | 1 | >> | VBA3Handling | 3 | 1 | >> | VbaOnly | 3 | 0 | >> | VBA5Handling | 3 | 1 | >> | DecompressVBA5 | 3 | 1 | >> | Vba5p | 3 | 0 | >> | ExcelFormulaHandling | 3 | 1 | >> | ProjectHandling | 3 | 1 | >> | ScrapObjectHandling | 3 | 1 | >> | VisioFileHandling | 3 | 1 | >> | VisioEmbedHandling | 3 | 0 | >> | OleDataMsoHandling | 3 | 1 | >> | OleScriptHandling | 3 | 1 | >> | OleRawHandling | 3 | 1 | >> | SrpStreamHandling | 3 | 1 | >> | Office2001Handling | 3 | 1 | >> | Vba5Dir | 3 | 0 | >> | PowerPointMacroHandling | 3 | 1 | >> | PowerPointEmbeddedHandling | 3 | 1 | >> | IgnoreTemplateBit | 3 | 1 | >> | OF95DecryptHandling | 3 | 1 | >> | DelVBA5Project | 3 | 1 | >> | Msi | 3 | 0 | >> | HelpHandling | 3 | 1 | >> | Skip | 3 | 1 | >> | Mime | 3 | 1 | >> | MimeReScan | 9 | 2 | >> | MimeEmbedded | 3 | 1 | >> | Base64 | 3 | 1 | >> | Vbe | 3 | 1 | >> | OutlookExpress | 3 | 1 | >> | VbFiltering | 3 | 1 | >> | UTF16 | 3 | 1 | >> | Java | 3 | 1 | >> | Access | 3 | 1 | >> | CleanJpeg | 3 | 1 | >> | CleanBmp | 3 | 1 | >> | CleanGif | 3 | 1 | >> | CleanRiff | 3 | 1 | >> | CleanTiff | 3 | 1 | >> | CleanPng | 3 | 1 | >> | CleanMp3 | 3 | 1 | >> | CleanMpeg | 3 | 1 | >> | Xml | 3 | 0 | >> | FullMacroSweep | 3 | 0 | >> | FullPdf | 3 | 0 | >> | FullSweep | 3 | 0 | >> | StorageReport | 3 | 0 | >> | StorageReportAll | 3 | 0 | >> | StorageDetOnly | 3 | 0 | >> | DeleteAllMacros | 3 | 0 | >> | UnixArchive | 3 | 1 | >> | Rpm | 3 | 1 | >> | Saveset | 3 | 0 | >> | MaxRecursionDepth | 2 | 16 | >> | MaxIntRecDepth | 2 | 25 | >> | NamespaceSupport | 3 | 0 | >> | VirusDataDir | 10 | /usr/local/sweep/sav >> | VirusDataName | 10 | vdl >> | IdeDir | 10 | /usr/local/sweep/sav >> | AllowPartialVirusData | 3 | 0 | >> | EnableAutoStop | 3 | 0 | >> +-----------------------------------+------+-----+ >> >> >> >> >> Quoting Scott Walker <[email protected]>: >> >> > There are two things going on here. >> > >> > 1) Grp options are always reported as 2 by the engine. The only wa= y > to >> > confirm that a group option is set is to look at one of the options = it >> > sets. >> > For example, toggle GrpArchiveUnpack and watch the ZipDecompression > option. >> > >> > 2) However, there is still an error. The configuration file lists t= he > Grp >> > options first and the individual options next. It also (for some > reason) >> > lists _all_ the individual options. Sophie reads the config file fr= om > top >> > to bottom, so it first sets the groups, then overwrites any options = th e >> > groups may have set by setting the individual options (thus making t= he >> > group options useless). There really is no need for all options to b= e >> > listed in the default config file. You should only list the options > you >> > want to change from their default. >> > >> > Try commenting out ZipDecompression in the config file and toggling = th e >> > GrpArchiveUnpack option, you should see ZipDecompression change. >> > >> > Scott. >> > >> > >> > >> > [email protected] wrote on 06/22/2005 01:44:32 PM: >> > >> > > Hello - I think we have uncovered a signifigant Sophie problem tha= t > may >> > be the >> > > cause of this error. >> > > >> > > I see that 3.04rc2 and 3.04 operate the same in this and so it is = a > long >> > > standing issue. >> > > >> > > Issue: sophie.savi GrpXXX settings are not respected. >> > > >> > > With testing via 'sophie -c' to show Sophie's configuration I have >> > > seen that the >> > > Grp settings are not picked up. They do not change for the default > '2'. >> > > >> > > Can anyone confirm this? >> > > >> > > Dave, >> > > >> > > Quoting Ronan <[email protected]>: >> > > >> > > > hi all, >> > > > As with most of you i was getting the ERROR stream corrupted > blabla >> > > > with libsavi 3.93 and even 3.93.2(which was released at the time= t o > try >> > > > and fix the sophie incompatibilty) After reading and AIUI sophos > are >> > not >> > > > going to unmake the changes to libsavi for whatever reason and > thats >> > why >> > > > 3.04 final was released... >> > > > >> > > > Unfortunately, now I am no longer getting any stream corrupted > errors >> > > > but in actual fact am getting apparently no scanning now at all.= .. =2E >> > > > >> > > > I run the latest exim on my smtp server and have running both > clamav >> > and >> > > > sophie on every message. Sophie is first preference because we h= av e > a >> > > > site licence for it and clamav runs second... im healthily > paranoid! >> > > > >> > > > however when testing with GTUBE sophie doesnt appear to catch or > indeed >> > > > log anything whereas clamav as expected detects and sends a >> > 550message... >> > > > >> > > > any clues as to why its not even scanning now?? >> > > > >> > > > libsavi 3.94 >> > > > sophie 3.04 (compiled 32bit becuase of libsavi ) >> > > > Slamd64 (slackware 10.1 64bit linux on dual opterons) >> > > > /lib/libc.so.6 >> > > > GNU C Library stable release version 2.3.2, by Roland McGrath et > al. >> > > > >> > > > any other info needed?? >> > > > >> > > > ronan >> > > > >> > > > >> > > > >> > > > _______________________________________________ >> > > > vtools mailing list >> > > > [email protected] >> > > > http://www.vanja.com/list/listinfo.cgi/vtools >> > > > >> > > >> > > >> > > -- >> > > David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP >> > > 250.721-6307 [email protected] FIA 221 >> > > _______________________________________________ >> > > vtools mailing list >> > > [email protected] >> > > http://www.vanja.com/list/listinfo.cgi/vtools >> > >> > >> > -- >> > Scott Walker >> > Software Integration & Support Engineer, Sophos >> > >> > Tel: 604 484 6883 >> > Web: www.sophos.com >> > Sophos - protecting businesses against viruses and spam >> > >> > _______________________________________________ >> > vtools mailing list >> > [email protected] >> > http://www.vanja.com/list/listinfo.cgi/vtools >> > >> >> >> -- >> David Broome Programmer_Analyst.FineArts.UVic.CA /BSc /CNA /MCP >> 250.721-6307 [email protected] FIA 221 >> _______________________________________________ >> vtools mailing list >> [email protected] >> http://www.vanja.com/list/listinfo.cgi/vtools > > > -- > Scott Walker > Software Integration & Support Engineer, Sophos > > Tel: 604 484 6883 > Web: www.sophos.com > Sophos - protecting businesses against viruses and spam > > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools >