Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 4th, 2008, 09:53 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Gmail apparently using ClamAV

There were rumours here a while ago that GMail was using NOD32 as antivirus for scanning attachements for their free e-mail service.

Now apparently (with 99% certainty) they're using ClamAV.

And I'll tell you why... I've downloaded winrar 3.62 from official website (http://www.rarlab.com/rar/wrar362.exe) and wanted to attach it to my gmail account to send it. I was astonished to see a red label after that with the message: "Attachement can't be sent. It contains a virus".

I've scanned the file on virustotal.com and the only AV to detect it is ClamAV: Trojan.Agent-14588

The conclusion seems simple.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #2  
Old May 4th, 2008, 10:05 AM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: Gmail apparently using ClamAV

Actually a while back I was convinced they use Sophos....tried a few that only sophos detected and it wouldn't allow me to attach them.

I guess they can switch the engine used and we wouldn't notice..
  #3  
Old May 4th, 2008, 10:18 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,365
Default Re: Gmail apparently using ClamAV

They keep it hidden so it's harder to target it perfectly.
__________________
RejZoR's Little Secrets
  #4  
Old May 4th, 2008, 01:26 PM
tiagozt's Avatar
tiagozt tiagozt is offline
Frequent Poster
 
Join Date: Feb 2004
Posts: 331
Default Re: Gmail apparently using ClamAV

GMAIL blocks by extension (all *.EXE) too... but the advertisement is different... (illegal file attachment).
I still think they use Sophos...
__________________
Using:
F-Secure BETA Tester, Opera, Mozilla Thunderbird, FoxIT Reader (The best PDF Reader), GMAIL, utorrent, AIMP

I usually test a lot of AV softwares and my TOP3 are Avira, F-Secure and Kaspersky (not necessarially in that order).

"Everything you say can and WILL BE used against you."
  #5  
Old May 4th, 2008, 04:40 PM
jdenton's Avatar
jdenton jdenton is offline
Infrequent Poster
 
Join Date: Apr 2008
Posts: 47
Default Re: Gmail apparently using ClamAV

Or perhaps they use more than one.

Blocking exe's is one of the reasons I gave up on gmail. I then tried zipping up my files with a password, but gmail didn't allow that either. So it's goodbye gmail.
  #6  
Old May 4th, 2008, 05:33 PM
Macstorm's Avatar
Macstorm Macstorm is offline
Very Frequent Poster
 
Join Date: Mar 2005
Location: Sneffels volcano
Posts: 2,089
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by tiagozt
GMAIL blocks by extension (all *.EXE) too... but the advertisement is different... (illegal file attachment).
Well thats how i always thought it worked.
I never been able to attach any '.exe' file on Gmail.
__________________
Avira . G-Data.. F-Secure
  #7  
Old May 4th, 2008, 06:02 PM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by jdenton
Or perhaps they use more than one.

Blocking exe's is one of the reasons I gave up on gmail. I then tried zipping up my files with a password, but gmail didn't allow that either. So it's goodbye gmail.


I just rar them and encrypt the filename
  #8  
Old May 4th, 2008, 09:26 PM
kinwolf kinwolf is offline
Frequent Poster
 
Join Date: Oct 2006
Posts: 267
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by jdenton
Or perhaps they use more than one.

Blocking exe's is one of the reasons I gave up on gmail. I then tried zipping up my files with a password, but gmail didn't allow that either. So it's goodbye gmail.

Just zip them and rename the zip , it pass freely then. An encrypted zip still allows you to read the content, that's what GMail does, but if you rename the zip extension, it won't try.
  #9  
Old May 4th, 2008, 10:47 PM
Trespasser's Avatar
Trespasser Trespasser is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Clintwood, Virginia
Posts: 966
Default Re: Gmail apparently using ClamAV

I don't quite understand this...I send zip/rar files thru GMail all the time with no problems at all.

Later...
__________________
Ubuntu Precise (Cinnamon DE) 12.04 32bit on one laptop, Ubuntu Precise Gnome Fallback 12.04 32bit on another laptop, Ubuntu Precise (Cinnamon DE) 12.04 64bit on our main Desktop, and Xubuntu 12.04 64bit on our spare Desktop.


"I wish I knew as much as I think I do"...
  #10  
Old May 4th, 2008, 10:53 PM
kinwolf kinwolf is offline
Frequent Poster
 
Join Date: Oct 2006
Posts: 267
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by Trespasser
I don't quite understand this...I send zip/rar files thru GMail all the time with no problems at all.

Later...

Yeah, but you probably don't have any .exe files in those zip.
  #11  
Old May 4th, 2008, 11:39 PM
sir_carew's Avatar
sir_carew sir_carew is offline
Frequent Poster
 
Join Date: Sep 2003
Location: Santiago, Chile
Posts: 884
Default Re: Gmail apparently using ClamAV

You can send .exe compressed in rar format with password and no problem.
__________________
- ASUS M4A79 Deluxe
- ASUS HD 5770 CuCore
- AMD PHENOM II X4 965 @3.7 NB 2400
- 4GB DDR2 KINGSTON HYPER X 800 MHZ 5-5-5-15 T1
- SAMSUNG SSD 470 SERIES 64 GB
- SEAGATE SATAII 1 TB
  #12  
Old May 5th, 2008, 03:25 AM
ASpace
 
Posts: n/a
Default Re: Gmail apparently using ClamAV

@ pykko

I get this warning only:

Name:  gmail_warning.png
Views: 1042
Size:  5.1 KB


As already written , GMail will block all kind of executable files.

Currently , ClamAV is still the one to detect a trojan in WinRAR.

Quote:
AhnLab-V3 2008.5.3.0 2008.05.02 -
AntiVir 7.8.0.11 2008.05.02 -
Authentium 4.93.8 2008.05.05 -
Avast 4.8.1169.0 2008.05.04 -
AVG 7.5.0.516 2008.05.05 -
BitDefender 7.2 2008.05.05 -
CAT-QuickHeal 9.50 2008.05.03 -
ClamAV 0.92.1 2008.05.05 Trojan.Agent-14588
DrWeb 4.44.0.09170 2008.05.04 -
eSafe 7.0.15.0 2008.04.28 -
eTrust-Vet 31.3.5755 2008.05.03 -
Ewido 4.0 2008.05.04 -
F-Prot 4.4.2.54 2008.05.04 -
Fortinet 3.14.0.0 2008.05.04 -

...


With such strong rules , they don't even need antivirus but ...

Google have special contracts with Symantec and they uses Symantec AV on the machines used by their employees . Google offers Norton in their GooglePack . Why not use the same AV in their GMail ?
  #13  
Old May 5th, 2008, 04:03 AM
PiCo's Avatar
PiCo PiCo is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Athens, Greece
Posts: 352
Default Re: Gmail apparently using ClamAV

I attached the eicar string to one e-mail and got this from gmail:
Quote:
Technical details of permanent failure:
PERM_FAILURE: Gmail tried to deliver your message, but it was rejected by the recipient domain. The error that the other server returned was: 554 554 5.7.1 virus Eicar-Test-Signature detected by ClamAV - http://www.clamav.net. We recommend contacting the other email provider for further information about the cause of this error. Thanks for your continued support. (state 17)

edit://Actually this proves gmail is NOT using ClamAV. I sent the eicar virus to a gmail account and another account. The other account is using ClamAV and rejected the mail, gmail didn't reject it!

Last edited by PiCo : May 5th, 2008 at 04:11 AM.
  #14  
Old May 5th, 2008, 04:15 AM
ASpace
 
Posts: n/a
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by PiCo
The other account is using ClamAV and rejected the mail, gmail didn't reject it!

GMail placed it in its SPAM folder , this is where known infected stuff is placed
  #15  
Old May 5th, 2008, 04:23 AM
PiCo's Avatar
PiCo PiCo is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Athens, Greece
Posts: 352
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by HiTech_boy
GMail placed it in its SPAM folder , this is where known infected stuff is placed
No it came right in to my inblox. I can open it and view the eicar string.
  #16  
Old May 5th, 2008, 06:05 AM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: Gmail apparently using ClamAV

According to this:

http://semanticvoid.com/blog/2005/12...us-test-drive/

Gmail actually uses Symantec technology. Go figure.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #17  
Old May 5th, 2008, 10:07 AM
chrisretusn's Avatar
chrisretusn chrisretusn is offline
Very Frequent Poster
 
Join Date: Jun 2004
Location: Philippines
Posts: 1,023
Default Re: Gmail apparently using ClamAV

Make sense to me. Norton Security Scan is part of Google Pack.
__________________
FreeDOS, Haiku, PCLinuxOS, Slackware, Snow Leopard, Ubuntu, Ultimate Edition, Windows 7, Windows XP. (Primary OS, KDE)

Living in Paradise!!
  #18  
Old May 5th, 2008, 11:04 AM
ASpace
 
Posts: n/a
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by Firecat
Gmail actually uses Symantec technology. Go figure.

I knew it
  #19  
Old May 5th, 2008, 02:07 PM
lordpake's Avatar
lordpake lordpake is offline
Frequent Poster
 
Join Date: Aug 2004
Location: Helsinki ~ European Union
Posts: 563
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by Firecat
According to this:

http://semanticvoid.com/blog/2005/12...us-test-drive/

Gmail actually uses Symantec technology. Go figure.

And even the URL tells that the post is 2+ years old So hardly valid information anymore.
  #20  
Old May 5th, 2008, 02:52 PM
tiagozt's Avatar
tiagozt tiagozt is offline
Frequent Poster
 
Join Date: Feb 2004
Posts: 331
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by jdenton
Or perhaps they use more than one.

Blocking exe's is one of the reasons I gave up on gmail. I then tried zipping up my files with a password, but gmail didn't allow that either. So it's goodbye gmail.

For me it's one of the reasons I use GMAIL. Despite spam protection, virus protection, big space, stability, POP3 access and other...



But to send samples by e-mail (actually it's not necessary because I send only to FS using website) I need to use other service that doesn't use AV.
__________________
Using:
F-Secure BETA Tester, Opera, Mozilla Thunderbird, FoxIT Reader (The best PDF Reader), GMAIL, utorrent, AIMP

I usually test a lot of AV softwares and my TOP3 are Avira, F-Secure and Kaspersky (not necessarially in that order).

"Everything you say can and WILL BE used against you."
  #21  
Old May 5th, 2008, 02:55 PM
tiagozt's Avatar
tiagozt tiagozt is offline
Frequent Poster
 
Join Date: Feb 2004
Posts: 331
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by HiTech_boy
@ pykko

Google have special contracts with Symantec and they uses Symantec AV on the machines used by their employees . Google offers Norton in their GooglePack . Why not use the same AV in their GMail ?

Because GMAIL offers a good AV protection for its users and not a "everything passes" AV like Symantec... :|
__________________
Using:
F-Secure BETA Tester, Opera, Mozilla Thunderbird, FoxIT Reader (The best PDF Reader), GMAIL, utorrent, AIMP

I usually test a lot of AV softwares and my TOP3 are Avira, F-Secure and Kaspersky (not necessarially in that order).

"Everything you say can and WILL BE used against you."
  #22  
Old May 9th, 2008, 09:48 AM
EsoxLucius's Avatar
EsoxLucius EsoxLucius is offline
Regular Poster
 
Join Date: Oct 2006
Location: Bucharest, Romania
Posts: 125
Default Re: Gmail apparently using ClamAV

What do you think about using their own sollution??
__________________
Protected by: BitDefender Antivirus and Firefox 3.0.10
  #23  
Old May 9th, 2008, 10:03 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: Gmail apparently using ClamAV

Quote:
Originally Posted by EsoxLucius
What do you think about using their own sollution??
Do they plan to launch a new AV ?
Hmm... and if it's their own solution it must be a good one. I don't think they "play" with a weak AV engine pretending to offer AV protection.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #24  
Old May 9th, 2008, 10:41 AM
emperordarius emperordarius is offline
Very Frequent Poster
 
Join Date: Apr 2008
Location: Who cares
Posts: 1,218
Default Re: Gmail apparently using ClamAV

Maybe using a multi engine av?
  #25  
Old May 9th, 2008, 10:48 AM
EsoxLucius's Avatar
EsoxLucius EsoxLucius is offline
Regular Poster
 
Join Date: Oct 2006
Location: Bucharest, Romania
Posts: 125
Default Re: Gmail apparently using ClamAV

I was trying to point out that google has the necessary resources to create it's own AV for email scaning. They could have also bought some parts from certain solutions and integrated them with other parts of their own engines.

Let's not forget that Google File System and other "home-brewed" parts of google.
__________________
Protected by: BitDefender Antivirus and Firefox 3.0.10
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:06 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums