Koozali.org: home of the SME Server

Anti Virus - Additional Signatures - HOW-TO still working?

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Anti Virus - Additional Signatures - HOW-TO still working?
« Reply #15 on: March 26, 2016, 10:19:06 AM »
Quote
So, I looked for ways to block .doc and .docx attachments, however blocking documents with macros seems the best solution. This doesn't block documents in .zip files, but that's ok because when a user opens a .zip file, the zip program places temporary copies on the drive where the user's antivirus can see them.

I created this directory and file:

nano /etc/e-smith/templates-custom/etc/clamd.conf/25OLE2BlockMacros

Then paste this into the file:

OLE2BlockMacros yes

Save and exit. Then activate:

signal-event post-upgrade
signal-event reboot

Big thanks to compdoc for this!
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Anti Virus - Additional Signatures - HOW-TO still working?
« Reply #16 on: March 26, 2016, 10:40:29 AM »
Many of the additional signatures have changed the download URL a/o require you to sign in in order to get some key before downloading.
There is a new version of the script here
https://github.com/extremeshok/clamav-unofficial-sigs
which addresses these issues.
It could be taken as an example or, if the licensing permits, ported to SME.

How did you manage the systemd issue on CentOS6?
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)