HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.
It is currently 22 Jun 2014 09:53

All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: 14 Mar 2006 07:36 
Offline

Joined: 28 Feb 2006 14:01
Posts: 5
Location: Bora Bora
I am using Clamav with HAVP. I know this may sound bad. But one of our users downloaded and infected their workstation with this trojan virus. They were browsing a hentia site (I know, our url filter did not have this listed as a porn site...it is in the blacklist now) I have my HAVP logs, and nothing was found. However the workstation antivirus found it running in memory and quarantined it. I submitted the sample to virustotal.com and it said Clamav detected it as a virus (Exploit.Java.ByteVerify). So some how this bypassed HAVP? I have HAVP 0.78. I am using default config settings except for:
KEEPBACKDATA = 1000000
TRICKLING = 10
MAXSCANSIZE = 20000000

13/03/2006 16:54:05 127.0.0.1 http://game4all.biz/adv/030/count.jar 200 GET OK
13/03/2006 16:54:06 127.0.0.1 http://game4all.biz/adv/030/com/ms/secu ... ader.class 404 GET OK

These urls pass the virus to the user. Any help would be much appreciated.

Best regards,

Dayne


Top
 Profile  
 
 Post subject:
PostPosted: 14 Mar 2006 10:11 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
I'm sorry but ClamAV does not detect this.. this if from virustotal:

ClamAV devel-20060126 03.14.2006 no virus found

Also tested myself with newest clamav and clamav-devel.

This is sad, since I (and many others I suppose..) have sent count.jar sample to clamav long time ago..

Quick fix would be to make it yourself: sigtool --md5 count.jar > /usr/local/share/clamav/local.hdb

But no worries, it is not really a serious "virus". ClamAV does recognize all the bad ones. ;)

Cheers,
Henrik


Top
 Profile  
 
 Post subject:
PostPosted: 17 Apr 2006 13:29 
i just tested this with the avg scanner (which is free for home use)
and it had been detected!

also the mailscanner version of f-prot is able to detect it (but isn't free)

markus


Top
  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Yahoo [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group