Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Software > Calibre > Library Management

Notices

Reply
 
Thread Tools Search this Thread
Old 08-24-2015, 04:12 PM   #1
mikebw
Member
mikebw began at the beginning.
 
Posts: 22
Karma: 10
Join Date: Nov 2014
Device: none
E-mailing generated EPUB files triggers ClamAV virus detector

Running 64-bit Calibre 2.35 on Windows 8 to download and generate EPUB files, I configured auto-send to e-mail through my own Debian Linux mail server running Exim 4.80-7+deb7u1 with ClamAV 0.98.7+dfsg-0+deb7u1 that checks every message via clamd.

When trying to send The New York Times EPUB -- and I should clarify that this is just that publication, not other publications -- Exim reports (user names and e-mail addresses obscured):

Code:
SMTPDataError: (550, 'This message was detected as possible malware (PUA.Phishing.Bank)')
 
Called with args: (u'C:\\Users\\XXXXX\\AppData\\Local\\Temp\\calibre_as5cqv\\hkmrldcaltmpfmt.epub', u'New York Times.epub', u'XXXXX@XXXXX', u'News: New York Times', u'Attached is the New York Times periodical downloaded by calibre.') {u'abort': <threading._Event object at 0x0000000009A4E940>, u'log': <calibre.utils.logging.GUILog object at 0x0000000009A4E7F0>, u'notifications': <Queue.Queue instance at 0x0000000009B96CC8>}
If I manually upload the file in question to the Debian Linux server and run clamscan over it, there is no detection:

Code:
$ clamscan hkmrldcaltmpfmt.epub
hkmrldcaltmpfmt.epub: OK

----------- SCAN SUMMARY -----------
Known viruses: 3960851
Engine version: 0.98.7
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 26.60 MB
Data read: 11.53 MB (ratio 2.31:1)
Time: 14.897 sec (0 m 14 s)
So my inference is that the Base64 encoding of the EPUB must be what is triggering the (I assume) false positive, but I have no idea how to capture that.

Has anyone else seen this? Does anyone have suggestions on further diagnosis?
mikebw is offline   Reply With Quote
Old 08-24-2015, 11:07 PM   #2
kovidgoyal
creator of calibre
kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.
 
kovidgoyal's Avatar
 
Posts: 45,345
Karma: 27182818
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
I highly doubt clamav would not decode attachments before scanning them. More likely it has additional checks when running in the exim context, one of which is trigerring.
kovidgoyal is offline   Reply With Quote
Advert
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Content embp files and highlights for user-generated eBooks RMOP Amazon Kindle 3 02-20-2014 10:25 AM
What triggers epub split? DMee Conversion 8 07-31-2012 10:22 AM
Covers in ePub files generated by Calibre daviddem Calibre 14 06-30-2011 09:18 PM
Kindle generated apnx files Cassandra Devices 3 05-11-2011 04:54 PM
e-mailing mobitext files wz2b Amazon Kindle 2 03-10-2009 12:37 AM


All times are GMT -4. The time now is 07:13 AM.


MobileRead.com is a privately owned, operated and funded community.