Home / Blogs

ClamAV and the Case of the Missing Mail

Neil Schwartzman

Some email discussion lists were all atwitter yesterday, as Sourcefire's open-source anti-virus engine ClamAV version 0.94.x reached its end-of-life.

Rather than simply phase this geriatric version out (it was at least one year old, revised to versions .95 and .96 since release, and announcements about the need to upgrade had been made for six months) the development team put to halt instances of V0.94 in production yesterday, April 15, 2010. This was to protect users from an issue that existed with the older version in terms of its inability to be updated with fresh virus signatures.

In other words, the ClamAV developers caused version .94 to stop working entirely, and, depending upon the implementation, that meant email to systems using ClamAV also stopped flowing.

Yikes. Several high-profile anti-spam services were hit with an unanticipated shutdown, for example, Roaring Penguin's CANIT, with large incursion into the educational market reported incidents of downed systems. Michelle Sullivan of GFI Mail Essentials' SORBS also noted the inbound servers for the blacklist took a hit.

The Twitterverse wasn't pleased either — numerous systems administrators have been tweeting their chagrin at the move.

Some sender-side mailing lists noted a 3-5% drop in email deliverability yesterday; that sounds very much on the high side, given such figures invariably change from list to list. No major ISPs and receiving sites are using ClamAV on their production mail servers, but nonetheless, the concern isn't so much about dropped mails. By now, email systems have been re-arranged or upgraded.

Rather it is the reliance upon out-dated systems and anti-virus software. With zero-day exploits and a constant flow of malware, the latest and greatest commercial anti-virus software packages are only able to flag, at best, half of the viruses live on the net; at least 50% go undetected. Out-of-date anti-virus software is generally less effective at catching malware, and out-of-date system software tends to be much more vulnerable to exploit.

There were no winners here, recipients didn't get mail, receiver systems dropped mail, senders failed to get through, two high-profile spam-filtering services were adversely affected, and Sourcefire took it on the chin.

By Neil Schwartzman, Executive Director, The Coalition Against unsolicited Commercial Email - CAUCE. More blog posts from Neil Schwartzman can also be read here.

Related topics: Cyberattack, Email, Malware, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

CANIT Update Neil Schwartzman  –  Apr 16, 2010 12:33 PM PDT

David Skoll of Roaring Penguin corrected me:

Hi Neil,

You wrote:

"Roaring Penguin's CANIT, with large incursion into the educational
market reported incidents of downed systems."

Actually, we reported no such thing.  We anticipated problems and
complained on the Clam mailing list; we never reported downed
systems.

Regards,

David.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

3 Questions to Ask Your DNS Host About DDoS

Neustar to Build Multiple Tbps DDoS Mitigation Platform

The Latest Internet Plague: Random Subdomain Attacks

Digging Deep Into DNS Data Discloses Damaging Domains

Non-English "IDN Email" Addresses Are Finally Working!

3 Questions to Ask Your DNS Host about Lowering DDoS Risks

4 Minutes Vs. 4 Hours: A Responder Explains Emergency DDoS Mitigation

Tips to Address New FFIEC DDoS Requirements

Smokescreening: Data Theft Makes DDoS More Dangerous

24 Million Home Routers Expose ISPs to Massive DNS-Based DDoS Attacks

What Does a DDoS Attack Look Like? (Watch First 3 Minutes of an Actual Attack)

Joining Forces to Advance Protection Against Growing Diversity of DDoS Attacks

Why Managed DNS Means Secure DNS

DDoS Attacks in the United Kingdom: 2012 Annual Trends and Impact Survey

A Look Inside Dyn's 1.2 Billion Monthly Email Delivery Statistics

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

How Neustar Technology Can Help Mitigate DDoS Attacks

Dyn to Host Email Analytics Webinar With Ongage

Reducing the Risks of BYOD with Nominum's Security Solution

Dyn Adds Claudia Santoro, Dave Connors and Andrew Sullivan to Technical Team

Sponsored Topics

Verisign

Security

Sponsored by
Verisign
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi
Afilias

DNS Security

Sponsored by
Afilias