Koozali.org: home of the SME Server

ClamAV and rkhunter errors on SME Server 7.3 - Help Needed

Offline ScottieDog

  • *
  • 13
  • +0/-0
ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« on: February 21, 2008, 11:01:42 AM »
I am running SME Server 7.3. I always install the latest updates within 24 hours of being notified. For the past few weeeks, I have been receiving the following error messages.

This is the first error message;
_______________________________________________________________________________
2008-02-21 20:30:37.337590500 ClamAV update process started at Thu Feb 21 20:30:37 2008
2008-02-21 20:30:37.338174500 WARNING: Your ClamAV installation is OUTDATED!
2008-02-21 20:30:37.338198500 WARNING: Local version: 0.92 Recommended version: 0.92.1
2008-02-21 20:30:37.338202500 DON'T PANIC! Read http://www.clamav.net/support/faq
2008-02-21 20:30:37.338456500 main.inc is up to date (version: 45, sigs: 169676, f-level: 21, builder: sven)
2008-02-21 20:30:37.450703500 ERROR: cdiff_apply: lseek(desc, -350, SEEK_END) failed
2008-02-21 20:30:37.450727500 ERROR: getpatch: Can't apply patch
2008-02-21 20:30:37.450799500 WARNING: Incremental update failed, trying to download daily.cvd
2008-02-21 20:30:39.811291500 WARNING: Mirror 193.1.193.64 is not synchronized.
2008-02-21 20:30:39.816544500 Giving up on database.clamav.net...
2008-02-21 20:30:39.816580500 Update failed. Your network may be down or none of the mirrors listed in freshclam.conf is working. Check http://www.clamav.net/support/mirror-problem for possible reasons.
_____________________________________________________________________________________________

This is the second error message;
_____________________________________________________________________________________________
/etc/cron.daily/01-rkhunter:

Warning: The following processes are using deleted files:
         Process: /usr/bin/freshclam    PID: 3947    File: /var/clamav/clamav-3ba21ac2c79001b0e9062faa857950de
Warning: Process '/sbin/pppoe' (PID 3392) is listening on the network.
Warning: Process '/sbin/pppoe' (PID 3392) is listening on the network.

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
_____________________________________________________________________________________________


Any help would be greatly appreciated.

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #1 on: February 21, 2008, 10:34:41 PM »
1) I am also experiencing problems with Clamav over past day on all of our servers, they are in NSW.
 Are you with TPG? 

2) The errors you see with RKH are a result of the latest upgrade to 7.3.
Please fill a bug report at Bugzilla about this, there are already a few but it is best having one report per type of bugs.  The error you are seeing have not been reported to date AFAIK.  Doing so will ensure this issue is either fixed or documented.
Thanks,
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline igardiner

  • *
  • 24
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #2 on: February 21, 2008, 11:39:18 PM »
I have been receiving the same error messages as well as of Wed 20/2/08. Our servers are currently located in NSW as well, hosted with Exetel!
Totally New to SME

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #3 on: February 22, 2008, 02:37:58 AM »
I have been receiving the same error messages as well as of Wed 20/2/08. Our servers are currently located in NSW as well, hosted with Exetel!

Thanks, same here with TPG as of 20/2/08.
Is your connection working through a proxy at exetel?
To find out, go to a browser and type:

http://stuff.daniel15.com/php/testproxy.php

Thanks.
chris
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline igardiner

  • *
  • 24
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #4 on: February 22, 2008, 02:43:11 AM »
We don't have a proxy server. We currently have an IPCop box connecting to our modem which is using PPOE to connect to exetel. The results of your link say:

No proxy server detected!
Your IP address: 220.233.160.205
Totally New to SME

Offline StephenHodgman

  • *
  • 31
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #5 on: February 22, 2008, 03:05:04 AM »
I have also been getting ClamAV errors on the system we have on TPG.
Our other system using Netspeed is not getting the errors.
TPG proxy everything so this is what I get when testing for the proxy.

Proxy server detected!
Proxy server IP Address: 203.26.16.67
Proxy server details:

   1. Server HTTP version: 1.1
      Server address: cbr-pow-pr2.tpgi.com.au (port: 3128)
      Server version: squid
 .....

Do you have any ideas as to why this is failing?

Offline Tib

  • *
  • 571
  • +0/-0
    • http://www.tibors.net
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #6 on: February 22, 2008, 03:10:12 AM »

I'm getting these errors as well .... I'm not with TPG

Quote
Server HTTP version: 1.0
Server address: proxy1.bne.dft.com.au (port: 80)
Server version: squid/2.6.STABLE18

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #7 on: February 22, 2008, 03:17:01 AM »
Thanks, this make me feel better, at least it does not appear to be related to our ISP or proxy issue.  (I may live to regret saying this...)
Have posted a bug report, check:
http://bugs.contribs.org/show_bug.cgi?id=3962
Best would be to provide iadditional comments at Bugzilla about this issue from now on, so that all information is found at one place, and one place only.
Thanks
chris

« Last Edit: February 22, 2008, 03:20:17 AM by chris burnat »
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline ScottieDog

  • *
  • 13
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #8 on: February 22, 2008, 03:23:30 AM »
My server is connected through aaNet (eftel) in Victoria, Australia.

I know for a fact they use transparent proxy, as I have had issues with my Windows servers as well due to proxy issues.

My proxy testing came back as follows;

Proxy server detected!
Proxy server IP Address: 203.171.70.222
Proxy server details:
Server HTTP version: 1.1
Server address: glasgow.shields.net.au (port: 3128)
Server version: squid/2.5.STABLE14
Server reports IP address as: 10.50.4.100

Server HTTP version: 1.0
Server address: proxy4.mel.dft.com.au (port: 80)
Server version: squid/2.6.STABLE18
Server reports IP address as: 203.171.70.222

Raw HTTP X_Forwarded_For header: 10.50.4.100, 203.171.70.222
Raw HTTP Via header: 1.1 glasgow.shields.net.au:3128 (squid/2.5.STABLE14), 1.0 proxy4.mel.dft.com.au:80 (squid/2.6.STABLE18)


I know, due to the windows problem, that I can request from aaNet to bypass the proxy. I might try that & see what happens.

Chris - maybe it is your ISP.......

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #9 on: February 22, 2008, 04:39:42 AM »
Scottie,

I know, due to the windows problem, that I can request from aaNet to bypass the proxy. I might try that & see what happens.
Chris - maybe it is your ISP.......

Hmmmm.  I have requested proxy to be disabled on one of the affected service from TPG, needs to be in written form,  lets see. Please let us know what you find after your proxy is disabled. 
Thanks.
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline idp_qbn

  • *****
  • 347
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #10 on: February 22, 2008, 08:44:50 AM »
Hi,
I had the same problem and it reminded me that it had also occurred about 18 months ago (more or less). It was solved then by issuing the following commands (which I found in the forums somewhere).

sv d freshclam
rm -f /var/clamav/mirrors.dat
sv u freshclam

I think the upshot of these is to :
1 stop freshclam service
2. delete the mirrors list (which preseumably has become corrupted somehow)
3. restart freshclam

Anyhoooo... I did this again this afternoon and have had no "freshclam failures" since.

Cheers
Ian
___________________
Sydney, NSW, Australia

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #11 on: February 22, 2008, 09:10:56 AM »
Hi,
I had the same problem and it reminded me that it had also occurred about 18 months ago (more or less). It was solved then by issuing the following commands (which I found in the forums somewhere).

sv d freshclam
rm -f /var/clamav/mirrors.dat
sv u freshclam

I think the upshot of these is to :
1 stop freshclam service
2. delete the mirrors list (which preseumably has become corrupted somehow)
3. restart freshclam

Anyhoooo... I did this again this afternoon and have had no "freshclam failures" since.

Cheers
Ian

idp, I have arrived at path.  Check: http://bugs.contribs.org/show_bug.cgi?id=3962
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline jokiin

  • **
  • 28
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #12 on: February 22, 2008, 02:07:51 PM »
My server is connected through aaNet (eftel) in Victoria, Australia.

Likewise, aaNet but NSW


I know, due to the windows problem, that I can request from aaNet to bypass the proxy. I might try that & see what happens.

Keep in mind if you have them take you off the proxy you will get a new IP address as part of the procedure, just mentioning it in case you need to keep your IP


I recall last time this happened the proxy took a few days to get the update before the newer version came through, was a while ago though

Offline william_syd

  • *****
  • 1,608
  • +0/-0
  • Nothing to see here.
    • http://www.magicwilly.info
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #13 on: February 22, 2008, 02:17:14 PM »
How often does freshclam update?

I'm with Optus cable in NSW and I get one or two failures a day every couple of days.

SME 7.3 fully updated. Actually, just did the smeupdates-testing update of clamav to get rid of the version warning.
Regards,
William

IF I give advise.. It's only if it was me....

Offline jokiin

  • **
  • 28
  • +0/-0
Re: ClamAV and rkhunter errors on SME Server 7.3 - Help Needed
« Reply #14 on: February 22, 2008, 02:24:45 PM »
How often does freshclam update?

Not sure how often it updates but I think it checks for updates daily, occasionally the new version seems to need to be fixed to suit SME and it takes a bit longer to get sorted, this happened a while ago also but has been for ages