Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: devel
Plz help me!!
 

Index | Next | Previous | View Flat


deeeps.inf at gmail

Feb 11, 2012, 8:16 AM


Views: 711
Permalink
Plz help me!! [In reply to]

Hi,

I am doing project on clamAV . I have chosen from

http://wiki.clamav.net/bin/view/Main/GoogleSummerOfCode2011
4. DOCX

Add support for parsing docx based MS Office files.

Main purpose is extracting embedded files. You will need to parse the XML,
locate the embedded data, then decode(base64/OLE?) / and decompress
(deflate?) it.

So I did analysis of how clamAV currently scanning a .DOCX file . From my
understanding it treats as a ZIP file and extracts to a temporary folder,
and scanning each xml file and inserted media files such pictures,video
etc.(If I am not correct, kindly explain me).

After that, I tried embedding a EICAR test virus in a picture file by using
Steghide tool. Then I scanned that picture file ,but clamav didnt recognize
it. Reason may be steghide encrypts the virus file.

So I like to know following things,

1. Why clamav didnt recognize encrypted virus?

2.Anyone help me to start my project?(Still now I gone through the source
code using gdb, so I have little knowledge about code)

Awaiting for response.

Regards,

Infant Deepak.
_______________________________________________
http://lurker.clamav.net/list/clamav-devel.html
Please submit your patches to our Bugzilla: http://bugs.clamav.net

Subject User Time
plz help me!! deeeps.inf at gmail Jan 31, 2012, 1:21 AM
    Re: plz help me!! tkojm at clamav Jan 31, 2012, 4:34 AM
        Re: plz help me!! chatsiri at chatsiri Jan 31, 2012, 6:52 PM
    Re: plz help me!! deeeps.inf at gmail Feb 1, 2012, 3:48 AM
    Plz help me!! deeeps.inf at gmail Feb 11, 2012, 8:16 AM
    Re: Plz help me!! edwin at clamav Feb 11, 2012, 8:21 AM
    Re: Plz help me!! insiderboy at gmail Feb 11, 2012, 8:34 AM
    Re: Plz help me!! clamav-devel at jubileegroup Feb 12, 2012, 3:11 AM

  Index | Next | Previous | View Flat
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.