OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Other good RBLs, apart from Zen?

From: /dev/rob0 (rob0gmx.co.uk)
Date: Mon May 05 2008 - 10:46:30 CDT


On Mon May 5 2008 09:07:11 Mauro Sanna wrote:
> > times a day; there are some very good user-contributed scripts
> > available on the Sanesecurity web site.
> > http://www.sanesecurity.com/clamav/usage.htm
>
> It's a not known thing to me.
> I try soon.
> The cron scripts must run under root privileges, isn't it?

When I set up a clamav site, I know the freshclam job was not run as
root. It simply has to have write privilege where the virus signatures
are stored. The same user should also be able to send a signal to the
running clamd process, so if the Sanesecurity scripts are requiring
root privilege, they're doing things wrong^Wdifferently than I would.

FWIW, helo checks and Zen catch the vast majority of viral spew. I
didn't see any benefit from clamav. The few it caught would probably
also have been caught by SpamAssassin.

Disclaimer: this was not recent, viruses and other spammers are
constantly morphing and evolving, so it might not be relevant now.
--
    Offlist mail to this address is discarded unless
    "/dev/rob0" or "not-spam" is in Subject: header