Re: problems scanning .sit (Stuffit) files

Markus Stumpf <[email protected]> Thu, 23 Mar 2006 16:55:46 +0100
Newsgroups gmane.comp.security.virus.vtools
Organization SpaceNet AG, Muenchen, Germany
Message-ID <[email protected]>
Hoi Martin,

thanks for answering.

On Thu, Mar 23, 2006 at 09:19:43AM +0100, Martin Zuziak wrote:
> Otherwise, like I wrote in a mail yesterday, you can recompile sophie
> with the --enable-only-fatal-err option to configure or patch
> sophie_core.c, look for SOPHOS_SAVI_ERROR_NOT_SUPPORTED. There don't
> seem to be a configuration file option for ignoring non-fatal errors.

I know about that, but I don't want to disable this globally :)

I the meantime I also got feedback from Sophos support. There is a new
version of Stuffit out there and Sophos hasn't yet got the new specification
so the new compression/encoding is not supported yet.

> There is a stuffit option in sophie.savi but it defaults to 0. If you
> are running an older savi version you could try upgrading it.

Found it *only* in the comment of the (altervative) sophie.savi file in the
description for "GrpArchiveUnpack". This is "1" so Stuffit scanning also
gets set.
However I didn't find in sophie-3.05 a special "Stuffit" Option (neither
in sav_if/savitype.h nor savitype_extended.h) and I can't find it in the
SAV Interface configuration docs (they seem to have vanished from the
documentation section at sophos.com so I am stuck with a somewhat dated
version).
But you are right, "sophie -c" reports Stuffit and it is accepted as a
config option. I'll give it a try and see what happens ;-)

Thanks,

	\Maex

-- 
SpaceNet AG            | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
Research & Development |       D-80807 Muenchen    | Fax: +49 (89) 32356-299
"The security, stability and reliability of a computer system is reciprocally
 proportional to the amount of vacuity between the ears of the admin"