Old 05-30-2009, 11:26 AM   #1 (permalink)
Master Untangler
 
Join Date: Feb 2009
Posts: 132
fslomka is on a distinguished road
Default Yamipod

I donīt know why but the Untangle Virus Blocker blocks Yamipod
Yamipod is something like Sharepod

http://www.yamipod.com/
http://www.getsharepod.com/
fslomka is offline  
Old 05-31-2009, 05:32 AM   #2 (permalink)
Newbie
 
Join Date: May 2009
Posts: 11
ag100 is on a distinguished road
Default

CalmAV may have a false detection for this one.. I'll submit this to the folks over there, for review.

ClamAV 0.94.1 2009.04.29 Trojan.Dropper-12634


I think what surprises me a bit more, is UT's response to downloading this.. I'm doing the 14 day trial of Kaspersky (and turned it off for this test), so this was just with UT's free virus blocker.

I downloaded the Yam-Win.zip file 3 times, during which, I never received a message stating that the file was blocked (as I typically would) until I viewed the event log, but in the end, had 3 files, all with different sizes, all ~400K less than what the zip file was supposed to be.

Does anyone know if that's normal behavior, when downloading larger files? (I'm still relatively new to UT).

Thanks,

-ag100
ag100 is offline  
Old 06-03-2009, 10:50 PM   #3 (permalink)
Master Untangler
 
Join Date: Feb 2009
Posts: 132
fslomka is on a distinguished road
Default

Is there any solution???
fslomka is offline  
Old 06-03-2009, 11:09 PM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
dmorris is on a distinguished road
Default

Quote:
Originally Posted by ag100 View Post
CalmAV may have a false detection for this one.. I'll submit this to the folks over there, for review.

ClamAV 0.94.1 2009.04.29 Trojan.Dropper-12634


I think what surprises me a bit more, is UT's response to downloading this.. I'm doing the 14 day trial of Kaspersky (and turned it off for this test), so this was just with UT's free virus blocker.

I downloaded the Yam-Win.zip file 3 times, during which, I never received a message stating that the file was blocked (as I typically would) until I viewed the event log, but in the end, had 3 files, all with different sizes, all ~400K less than what the zip file was supposed to be.

Does anyone know if that's normal behavior, when downloading larger files? (I'm still relatively new to UT).

Thanks,

-ag100
if its small it just buffers the whole file and scans it and then displays the block page.
if its large it trickles the file at a slower rate than the real download (called trickle rate). at some point the file is done on untangle and scanned and then if clean it delivers the rest of the file to the client (otherwise it doesnt)
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 06-04-2009, 04:51 AM   #5 (permalink)
Newbie
 
Join Date: May 2009
Posts: 11
ag100 is on a distinguished road
Default

Thanks dmorris... I'm wondering if there's a better way that would allow all or nothing to be delivered to the desktop, depending on the result of the scan. I can see it getting confusing for users to trying to execute partially delivered packages, etc.. I'll submit an RFE (if one alreadly isn't in), and see if anyone else finds that valuable.

fslomka - As of this morning, clamav still detects this as a trojan. Until they're able to reanalyze the sample and remove the detection (if appropriate), you won't be able to download this, without disabling a/v blocker.
ag100 is offline  
Old 06-04-2009, 11:43 AM   #6 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
dmorris is on a distinguished road
Default

Quote:
Originally Posted by ag100 View Post
Thanks dmorris... I'm wondering if there's a better way that would allow all or nothing to be delivered to the desktop, depending on the result of the scan. I can see it getting confusing for users to trying to execute partially delivered packages, etc.. I'll submit an RFE (if one alreadly isn't in), and see if anyone else finds that valuable.
for large files we can't deliver nothing as the client will time-out. if you want to change this you can change the trickle rate down to 1% which will make the download appear extremely slow but once you reach 1% you'll get the remaining 99% instantly.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 06-04-2009, 05:56 PM   #7 (permalink)
Newbie
 
Join Date: May 2009
Posts: 11
ag100 is on a distinguished road
Default

Thanks... I was thinking of something that would download the file to the Untangle box, scan it, then allow the desktop to pull it, but slowing the trickle down rate should do the trick, as well.

Also - Any idea if you can change the default behavior of the AV engine, to scan files and log events, without blocking? I know I'm in the minority, but that'd be very useful for me, at times.

Thanks again,

-ag100
ag100 is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:18 PM.


Đ 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0