SpamFilter + antivirus plugin beta avail. |
Post Reply ![]() |
Page 12> |
Author | ||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() Posted: 17 March 2005 at 4:36pm |
|
Jim,
Soon (we're hoping days rather than weeks) we should have another beta that will also include automatic download of virus updates. |
||
![]() |
||
JimMeredith ![]() Newbie ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 28 |
![]() ![]() ![]() ![]() ![]() |
|
Roberto, Would it be possible to post the updated Norman virus patterns on your web site, so that we can download them and (manually) update them for now? Since it's a beta, we're not using this as our only line of virus defense... but it would still be a good idea to make updated virus patterns available at least every week or two during the beta, for continued effectiveness. Thanks Edited by JimMeredith |
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
The limitation is *not* present in the beta.
|
||
![]() |
||
mikek ![]() Senior Member ![]() ![]() Joined: 22 February 2005 Location: Switzerland Status: Offline Points: 133 |
![]() ![]() ![]() ![]() ![]() |
|
does this version have the same limitation as the trial version? (not delivering e-mails marked as good directly in the database)
|
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
The code is not complied to specifically make use of any cpu-specific
features. Insimple terms, what Windows gives SpamFilter is what
SpamFilter will use...
|
||
![]() |
||
Desperado ![]() Senior Member ![]() ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 1143 |
![]() ![]() ![]() ![]() ![]() |
|
I am running with Quad xeon which looks like 8 CPUs as far as the OS sees it. San |
||
The Desperado
Dan Seligmann. Work: http://www.mags.net Personal: http://www.desperado.com |
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
A bit off topic, but does this version or others support dual or quad cpus?
|
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
Dwight,
Absolutely yes on the automatic updates. We're still working the details with Norman (the AV engine owners) on how this will work, but the next beta will probably have this feature enabled. |
||
![]() |
||
dcook ![]() Senior Member ![]() ![]() Joined: 31 January 2005 Location: United States Status: Offline Points: 174 |
![]() ![]() ![]() ![]() ![]() |
|
I have had the Beta running successfully under moderate load. I am increasing the load on the beta today. I had about 40 discovered and blocked viruses. I agree filtering on file extensions is preventing a higher count. The install was smooth on both windows 2000 and 2003 server. Everything registered correctly. So far vary stable. Will the final release include the ability for signature to be updated on a schedule? Dwight
|
||
Dwight
www.vividmix.com |
||
![]() |
||
mikek ![]() Senior Member ![]() ![]() Joined: 22 February 2005 Location: Switzerland Status: Offline Points: 133 |
![]() ![]() ![]() ![]() ![]() |
|
I have my own quarantine front-end as well, but for my part I just modified the SQL SELECT to include a WHERE RejectID<>17 and the user never sees mails that were blocked because of viruses... |
||
![]() |
||
JimMeredith ![]() Newbie ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 28 |
![]() ![]() ![]() ![]() ![]() |
|
Kevin, I'd be glad to, but I don't think it will help, since it's not in ASP. We have a proprietary quarantine management page and "reportlet" that is written in ColdFusion. We don't use the SpamFilter ASP code at all. |
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
Jim, can you let me know what you come up with in regards to preventing users from forwarding on virus' |
||
![]() |
||
Desperado ![]() Senior Member ![]() ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 1143 |
![]() ![]() ![]() ![]() ![]() |
|
Jim, Better? 45973 infected with the virus Sober.K@mm Dan |
||
The Desperado
Dan Seligmann. Work: http://www.mags.net Personal: http://www.desperado.com |
||
![]() |
||
JimMeredith ![]() Newbie ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 28 |
![]() ![]() ![]() ![]() ![]() |
|
Yes, I've noticed the same thing on all attachment types that we are allowing to be quarantined. (The attachment types that we have listed with ":null" to NOT quarantine are not even received, therefore not scanned by the antivirus... and that's fine.) The great thing about this is that the virus block becomes the reason logged in the database. I'm modifying our web interface to prevent a user from delivering a virus-infected message from quarantine. |
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
that worked for me too. I did notice that, even though I block *.com files, when I sent through the eicar test virus, it blocked the file via the black list but it also found that it had a virus and ultimatly blocked the message because of the virus. |
||
![]() |
||
mikek ![]() Senior Member ![]() ![]() Joined: 22 February 2005 Location: Switzerland Status: Offline Points: 133 |
![]() ![]() ![]() ![]() ![]() |
|
already have it working! installed the beta version of spamfilter, installed the av plugin on a different machine, copied the 3 dlls into the spamfilter directory, that's it!
|
||
![]() |
||
mikek ![]() Senior Member ![]() ![]() Joined: 22 February 2005 Location: Switzerland Status: Offline Points: 133 |
![]() ![]() ![]() ![]() ![]() |
|
ok, so after installing the av plugin, I delete the mentioned registry entry and the SpamFilter\nvc\nse directories, except for the 3 DLLs mentioned? will there be a reduced license fee for users like me that only need the plugin but not the norman engine? |
||
![]() |
||
JimMeredith ![]() Newbie ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 28 |
![]() ![]() ![]() ![]() ![]() |
|
Dan, you show-off! But based on the resultset you posted, the query I posted earlier needs to be modified to give accurate totals by virus type. Looks like the RejectDetails field sometimes includes a leading space, sometimes it does not... no biggie, it's easy to just trim it. SELECT COUNT(*) 'Virus_Messages', LTRIM(RejectDetails) 'Details' FROM tblquarantine WHERE RejectID=17 GROUP BY LTRIM(RejectDetails) ORDER BY COUNT(*) DESC Jim |
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
Roberto, can you please email me...
|
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
The av plugin must be installed in the same directory where SpamFilter
is installed, from the path you posted it would not seem that is the
case. If the directory is not the same, that would definetly not work
correctly.
|
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
I checked that and its blank. Any suggestions?
I installed it to c:\program files\spamfilterav if that helps at all? |
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
This is an early beta, so things will not be perfect, but... if you
check under the Settings - Anti Virus tab, you'll see, although
incomplete, a few lines in a status box describing the status of the
antivirus engine.
|
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
Antivirus is not working on my system. I did the install as suggested and just sent through the eicar test file, and it went right through. Wouldn't it make sense to have something similar to the database to show the antivirus is active? perhaps later to show the datfile version?
|
||
![]() |
||
gsforsyth ![]() Guest Group ![]() |
![]() ![]() ![]() ![]() ![]() |
|
The install on differant system worked.
Thx |
||
![]() |
||
Desperado ![]() Senior Member ![]() ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 1143 |
![]() ![]() ![]() ![]() ![]() |
|
Jim, 33917 infected with the virus Sober.K@mm I think it is working. Dan |
||
The Desperado
Dan Seligmann. Work: http://www.mags.net Personal: http://www.desperado.com |
||
![]() |
||
JimMeredith ![]() Newbie ![]() Joined: 27 January 2005 Location: United States Status: Offline Points: 28 |
![]() ![]() ![]() ![]() ![]() |
|
Kevin, The first thing I did was send a message from an outside mail account with the EICAR test file attached. The EICAR file is not a real virus, but every antivirus program is programmed to treat it as a virus for testing purposes. You can download the EICAR file from Norman's web site. Another way is to look at your logs to see if you have had any traps. Here is a log entry with a virus trap. 03/05/05 05:30:41:070 -- (191) Connection from: 213.171.61.35 - Originating country : Russian Federation A SQL query should also reveal antivirus activity. SELECT COUNT(*) 'Virus_Messages', RejectDetails FROM tblquarantine WHERE RejectID=17 GROUP BY RejectDetails ORDER BY COUNT(*) DESC I just ran this query on my SpamFilter test server (handling traffic for one low-volume domain only) and it returned the following resultset. Virus_Messages RejectDetails Jim
|
||
![]() |
||
kspare ![]() Senior Member ![]() Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
![]() ![]() ![]() ![]() ![]() |
|
So how do you know if it is working ok or not?
|
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
SpamFilter's error is probably caused by the incomplete av install. You
can try to install the av on a different computer, and then copy the
directory tree /SpamFilter/nvc/nse from the alternate computer to the
one where the install fails. After the copy, from the
SpamFilter/nvc/nse directory on the SpamFilter server try issuing the
following command at a DOS prompt:
NSE /INSTALL That should inistialize the av engine, and then restart SpamFilter. |
||
![]() |
||
gsforsyth ![]() Guest Group ![]() |
![]() ![]() ![]() ![]() ![]() |
|
Hi, After installing the new beta I am getting this error.
Could not initialize Norman A/V engine - error $00010000 During install of the Beta I get a 16bit application error from the application and the av install is missing some install required file. Is there any instructions on how to use or what to expect? g |
||
![]() |
||
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
|
Jim,
For now in this first beta, the antivirus filter is the last on the list. However within the next builds we'll be changing that and moving it before the keywords filter. It cannot be moved even sooner order-wise, as the email content has not been received yet when the other filters are processing the email. |
||
![]() |
Post Reply ![]() |
Page 12> |
Tweet
|
Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.344 seconds.