Qmail
[Top] [All Lists]

Re: Antivirus recommendation?

To: qmail list <qmail@list.cr.yp.to>
Subject: Re: Antivirus recommendation?
From: Kyle Wheeler <kyle-qmail@memoryhole.net>
Date: Mon, 18 Dec 2006 17:49:43 -0500
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=memoryhole.net; b=EttOn7bZst4dJBeAFck5V4VHxz/kLUlhG/INOYvc23Dm9TJS+60Mv8dSfug4JE1OWPZ7qTnkD2Fz6/0rFOAQJy/TatGjn6Ss7GDIFhYiw0LK4pn1g9NyrYphKD0mfd7p4yaogAupMxmo7W/x6a4fLJSRIR/P5V/3zdLqtGeMEEU= ;
Domainkey-status: good
In-reply-to: <4586F666.8040903@infostreet.com>
Mail-followup-to: qmail list <qmail@list.cr.yp.to>
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <4586F666.8040903@infostreet.com>
User-agent: Mutt/1.5.13 (2006-11-28)
On Monday, December 18 at 12:13 PM, quoth Peter Serwe:
For whatever reasons, BitDefender decided to no longer offer/support their
BitDefender for qmail product, and now wants to attempt to charge a per user
fee for scanning email.  I've used ClamAV before, but I'm not certain how up
to date it's definitions are. Are there any other products, commercial or otherwise
anyone recommends for Linux?  Should I go with ClamAV?

There are plenty. A popular one on this list is Russ Nelson's attachment blocker (which is NOT an antivirus solution, but is instead an anti-FILE solution that allows you to do things like reject all Windows executables regardless of their extension or mime-type); you can find it on qmail.org. It's extremely lightweight and hard to fool, but, like I said, it's not a full antivirus solution (viruses can be in other formats, like MS Office documents), and has the drawback that it makes it more difficult for your users to send each other Windows executables (and whatever other file type you decide to block).

My personal favorite is ClamAV; it's virus definitions are updated constantly (my server updates them four times a day), and in my experience, it tends to catch new viruses at least as quickly as other virus scanners.

In the commercial category, there's f-prot (www.f-prot.com), Kaspersky's (www.kaspersky.com), and Sophos (www.sophos.com), and probably a few others. I haven't had much experience with them, but the options are there.

~Kyle
--
Moral indignation is jealousy with a halo.
                                                       -- H. G. Wells

Attachment: pgp91p8jjanpj.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>