Re: problems scanning .sit (Stuffit) files
Markus Stumpf <[email protected]> Thu, 23 Mar 2006 16:55:46 +0100
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Organization | SpaceNet AG, Muenchen, Germany |
| Message-ID | <[email protected]> |
Hoi Martin, thanks for answering. On Thu, Mar 23, 2006 at 09:19:43AM +0100, Martin Zuziak wrote: > Otherwise, like I wrote in a mail yesterday, you can recompile sophie > with the --enable-only-fatal-err option to configure or patch > sophie_core.c, look for SOPHOS_SAVI_ERROR_NOT_SUPPORTED. There don't > seem to be a configuration file option for ignoring non-fatal errors. I know about that, but I don't want to disable this globally :) I the meantime I also got feedback from Sophos support. There is a new version of Stuffit out there and Sophos hasn't yet got the new specification so the new compression/encoding is not supported yet. > There is a stuffit option in sophie.savi but it defaults to 0. If you > are running an older savi version you could try upgrading it. Found it *only* in the comment of the (altervative) sophie.savi file in the description for "GrpArchiveUnpack". This is "1" so Stuffit scanning also gets set. However I didn't find in sophie-3.05 a special "Stuffit" Option (neither in sav_if/savitype.h nor savitype_extended.h) and I can't find it in the SAV Interface configuration docs (they seem to have vanished from the documentation section at sophos.com so I am stuck with a somewhat dated version). But you are right, "sophie -c" reports Stuffit and it is accepted as a config option. I'll give it a try and see what happens ;-) Thanks, \Maex -- SpaceNet AG | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0 Research & Development | D-80807 Muenchen | Fax: +49 (89) 32356-299 "The security, stability and reliability of a computer system is reciprocally proportional to the amount of vacuity between the ears of the admin"