[clamav-users] Generating a positive?
Douglas Goddard
dgoddard at sourcefire.com
Mon Apr 21 19:27:17 UTC 2014
You can also write your own signatures.
[PDF]
https://github.com/vrtadmin/clamav-devel/raw/master/docs/signatures.pdf
On Mon, Apr 21, 2014 at 3:21 PM, Charles Swiger <cswiger at mac.com> wrote:
> Hi--
>
> On Apr 21, 2014, at 12:12 PM, Dave Shevett <shevett at pobox.com> wrote:
> > Hi everyone - we have clamav now running happily via cron job and
> > integrated with puppet. Problem is I want to have it successfully find
> > something so I can test our notification mechanism.
> >
> > "Infect one of my servers" seems a big gruesome. Is there an easy way
> > to test clamav notifications (like a simple test rule that says "if
> > there's a file called BOB here, you're infected with the BOBSMASH virus?"
>
> You want to use the EICAR test file:
>
> http://en.wikipedia.org/wiki/EICAR_test_file
>
> It's a harmless test file which is also a working 16-bit COM file:
>
> % clamscan eicar.com
> eicar.com: Eicar-Test-Signature FOUND
>
> Regards,
> --
> -Chuck
>
> _______________________________________________
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
> http://www.clamav.net/support/ml
>
More information about the clamav-users
mailing list