Koozali.org: home of the SME Server
Obsolete Releases => SME 9.x Contribs => Topic started by: Michail Pappas on March 23, 2016, 09:47:49 AM
-
As per the wiki at https://wiki.contribs.org/Clamav_unofficial_sigs I decided to install it. After executing a clamav-unofficial-sigs.sh I received an error though:
======================================================================
Sanesecurity Database & GPG Signature File Updates
======================================================================
Sanesecurity mirror site used: host-178-255-171-31.cloudsigma.com 31.171.255.178
Connection to host-178-255-171-31.cloudsigma.com 31.171.255.178 failed - Trying next mirror site...
Sanesecurity mirror site used: 46.21.115.195
Connection to 46.21.115.195 failed - Trying next mirror site...
Sanesecurity mirror site used: ws3-170.freeformit.com 69.16.193.170
Connection to ws3-170.freeformit.com 69.16.193.170 failed - Trying next mirror site...
Sanesecurity mirror site used: secure.kozstyle.com 84.201.25.108
Connection to secure.kozstyle.com 84.201.25.108 failed - Trying next mirror site...
Sanesecurity mirror site used: srv3.tuxinator.org 94.23.165.57
Connection to srv3.tuxinator.org 94.23.165.57 failed - Trying next mirror site...
Sanesecurity mirror site used: mail.espmail.co.uk 95.154.208.105
Connection to mail.espmail.co.uk 95.154.208.105 failed - Trying next mirror site...
Sanesecurity mirror site used: postfix.charite.de 141.42.206.35
Connection to postfix.charite.de 141.42.206.35 failed - Trying next mirror site...
Sanesecurity mirror site used: clamav.us.es 150.214.142.197
Connection to clamav.us.es 150.214.142.197 failed - Trying next mirror site...
Sanesecurity mirror site used: saturn.retrosnub.co.uk 178.18.118.26
Connection to saturn.retrosnub.co.uk 178.18.118.26 failed - Trying next mirror site...
Sanesecurity mirror site used: spamexperts-mirror.sanesecurity.com 185.66.251.102
Connection to spamexperts-mirror.sanesecurity.com 185.66.251.102 failed - Trying next mirror site...
Sanesecurity mirror site used: resolv3.vianetworks.de 194.77.111.24
Connection to resolv3.vianetworks.de 194.77.111.24 failed - Trying next mirror site...
Sanesecurity mirror site used: rsync-mirror.rollernet.us 208.79.241.67
Connection to rsync-mirror.rollernet.us 208.79.241.67 failed - Trying next mirror site...
Sanesecurity mirror site used: web.virusfree.cz 212.24.139.164
Connection to web.virusfree.cz 212.24.139.164 failed - Trying next mirror site...
Access to all Sanesecurity mirror sites failed - Check for connectivity issues
or signature database name(s) misspelled in the script's configuration file.
======================================================================
SecuriteInfo Database File Updates
======================================================================
4 hours have not yet elapsed since the last SecuriteInfo update check
--- No update check was performed at this time ---
Next check will be performed in approximately 3 hour(s), 55 minute(s)
======================================================================
MalwarePatrol Database File Update
======================================================================
6 hours have not yet elapsed since the last MalwarePatrol download
--- No database download was performed at this time ---
Next download will be performed in approximately 5 hour(s), 55 minute(s)
======================================================================
=============================================================
= No update(s) detected, ClamAV databases were not reloaded =
=============================================================
There's a chance I might have been blacklisted, because I was fooling around with the newer script version at http://sanesecurity.com/usage/linux-scripts/
Can someone using this confirm if rsync access/download of these signatures works or not?
-
[root@fileserver ~]$ clamav-unofficial-sigs.sh
======================================================================
Sanesecurity Database & GPG Signature File Updates
======================================================================
Sanesecurity mirror site used: mail.espmail.co.uk 95.154.208.105
Number of files: 18 (reg: 18)
Number of created files: 0
Number of regular files transferred: 6
Total file size: 15,616,574 bytes
Total transferred file size: 9,259,906 bytes
Literal data: 3,460 bytes
Matched data: 9,256,446 bytes
File list size: 585
File list generation time: 0.154 seconds
File list transfer time: 0.000 seconds
Total bytes sent: 29,554
Total bytes received: 2,050
sent 29,554 bytes received 2,050 bytes 12,641.60 bytes/sec
total size is 15,616,574 speedup is 494.13
Testing updated Sanesecurity database file: jurlbl.ndb
Sanesecurity GPG Signature tested good on jurlbl.ndb database
Clamscan reports Sanesecurity jurlbl.ndb database integrity tested good
Successfully updated Sanesecurity production database file: jurlbl.ndb
Testing updated Sanesecurity database file: junk.ndb
Sanesecurity GPG Signature tested good on junk.ndb database
Clamscan reports Sanesecurity junk.ndb database integrity tested good
Successfully updated Sanesecurity production database file: junk.ndb
Testing updated Sanesecurity database file: rogue.hdb
Sanesecurity GPG Signature tested good on rogue.hdb database
Clamscan reports Sanesecurity rogue.hdb database integrity tested good
Successfully updated Sanesecurity production database file: rogue.hdb
======================================================================
works for me
-
Thanks, must be some blacklisting and/or firewalling issue then.
-
Okay, some days later and I can still not download anything at all. Since a SME 8 server on another lan is able to at least rsync the selected directories, I can only presume the issue is with the WAN my own SME 9 server resides. I presume that there are other sanesecurity-connecting clients in this WAN, all connecting with the same IP, leading to a possible ban... :(
The current clamav-unofficial-sigs.sh has become a bit outdated. It can not work out of the box with SecuriteInfo and MalwarePatrol, since they now require some sort of free registration. But, I do need to make SS work, since I have to use the foxhole signatures at all costs. Is there some public rsync proxy of some sort I could configure clamav-unofficial-sigs.sh with?
-
according to http://sanesecurity.com/usage/linux-scripts/
we should really update our contrib that is based on EPEL rpm based on the sourceforge version that is out of date !!!