Koozali.org: home of the SME Server

THANK YOU CLAMAV!

Offline Neririn

  • ****
  • 100
  • +0/-0
THANK YOU CLAMAV!
« on: February 25, 2004, 12:35:05 AM »
Ok, so clamav is finding hundreds of emails coming in with mydoom. Which is MUCH better than my users finding them and opening them anyway.  My concern is that it is now quarantining (SP) them and writing a log file for each.  

Do I need to worry about this?  At this rate my hard disk is going to fill with logs and quarantined emails eventually.  

Is there some maintainence that I should perform to nuke them?  I really wouldnt mind if it just deleted/dropped the email completely once a virus was found.  Is there a config flag to do this?

Any suggestions on a good maintainence schedule for ClamAV will be greatly appreciated.
......

Offline psc

  • *
  • 151
  • +0/-0
Re.: THANK YOU CLAMAV!
« Reply #1 on: February 25, 2004, 11:31:43 AM »
Buy the Antivirus addon at http://dungog.net/sme/ works very good and you can view/delete the virus-mails via Server-Manager.

Peter
First, solve the problem. Then, write the code.

Offline MasterSleepy

  • *
  • 386
  • +0/-0
    • http://www.vanhees.cc
THANK YOU CLAMAV!
« Reply #2 on: February 25, 2004, 03:24:08 PM »
Hello,

All mail finding with viruses by clamav are stored in
/var/spool/amavis-ng/quarantine
And all mail that have some problems by passing through clamav are stored in
/var/spool/amavis-ng/problems

It could be usefull for you to clean up that directories sometime, when you need to gain some space on your HD.

Regards,

Anonymous

THANK YOU CLAMAV!
« Reply #3 on: February 26, 2004, 12:17:28 AM »
Might be nice if someone would add to the contrib a way to auto delete quarantine files. Could be on a daily, weekly, or monthly basis depending on how much hard drive you wanted to use. Really shouldn't be to hard just a simple script added to the cron jobs.

pistonpilot

The mail is probably not going to your users.
« Reply #4 on: February 27, 2004, 06:47:15 AM »
When I installed Clamav on my server the emails that it was flagging with Mydoom were all sent to users who don't exist.  

I had my mail settings set to reject mail if it wasn't for a user - no catchall - but clam gets to it first and cleans the mails even though I reject at the server.

The directory that holds the quarantine is easy to find and I just delete the files in it once in a while.