ClamScan Denial of Service attack

Alistair Carmichael Alistair.Carmichael at ntltravel.com
Wed Jul 18 09:11:16 IST 2007


-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info
[mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Neil
Wilson
Sent: 18 July 2007 09:01
To: MailScanner discussion
Subject: ClamScan Denial of Service attack

Hi guys,

I've just had quite a serious problem with one of my clients which
seemed to have been 
caused by Clamscan which rejected nearly all emails as
"MailScanner[30767]: Virus Scanning: 
Denial Of Service attack detected!"

It looks like it did this because we're using "clamav" as our virus
scanner, and clamscan 
was killing the system rescources.

The server is running "ClamAV 0.90.3/3691/Wed Jul 18 08:04:43 2007"
which came with the 
Clam-SA-easy installation package.

I know the latest MailScanner has full support for clamd, and it appears
to work fine, but 
we have a lot of servers running with the same config, so to upgrade all
of them to the 
latest MS+Clam will take forever.

Does the latest stable release of clam correct the problem with using
clamav as our virus 
scanner with MS, can we just upgrade Clam on all our servers or do we
have to upgrade all of 
these servers to the latest MS+Clam etc?

Thanks,

Any help will be greatly appreciated.

Regards.

Neil

Hi,
I had experienced the same problem which is down to that version of clam
and the time it takes when starting up. Upgrading to the most recent
clam solves the problem, you may also want to look at clamd or
clamavmodule as a scanning engine if you handle large quantities of
mail, using clamavmodule now I've found this a lot more effective. The
most recent version of clam is included in the sa+clam package at
mailscanner.info.

Al

This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail.


More information about the MailScanner mailing list