+ Responder ao Tópico



  1. #1
    silmar
    Visitante

    Padrão Antivirus clamav.

    Pessoal eu estou meio que perdido .. he he ..
    eu fui atraz de como instalar o clamav num FC4.
    E tentei com um rpm e deu erros depois desinstalei, e fui atras de como instalar via binario
    até blz .. peguei o binario .. mas nos exemplos todos falam do clamav-0.70.tar.gz e eu pegeui o mais novo clamav-0.88.tar.gz e nesse tem umas coisas diferente.
    Como no /etc nos exemplo falam do clamav.conf .. e no atual nao é clamav e sim clamd.conf

    sabe ae eeu tentei fazer como tem aee na net mas nao funcou ..
    por exemplo quero virar ele no meu samba e no meu postfix ..
    fui por esse exemplo
    http://www.unitednerds.org/thefallen...Clamav-gsoares
    mas nao vira no postfix nas linhas do smtp.
    e ele não sobe ...


    alguem aee sabe uma receita de como desisntalar esse atualk e como instalar o atual ...

    desde ja obr...


  2. #2

    Padrão Re: Antivirus clamav.

    A unica diferença e o nome do arquivo que muda de clamav.conf para clamd.conf, no mais vc configura igual como ta no material !!!

    E o freshclam tambem parece que muda alguma coisa, mas quando vc tentar atualizar o anti-virus ele mostra a localizaçao do arquivo.

    Abraçao

  3. #3
    silmar
    Visitante

    Padrão Re: Antivirus clamav.

    =============================================================================
    Installing:
    clamav-devel i386 0.88.3-1.fc4 extras 179 k
    clamav-exim i386 0.86.2-5.fc4 extras 19 k
    clamav-milter i386 0.88.3-1.fc4 extras 72 k
    Updating:
    clamav-data i386 0.88.3-1.fc4 extras 5.1 M
    clamav-update i386 0.88.3-1.fc4 extras 40 k
    Installing for dependencies:
    exim i386 4.62-1.fc4 extras 1.8 M

    Transaction Summary
    =============================================================================
    Install 4 Package(s)
    Update 2 Package(s)
    Remove 0 Package(s)
    Total download size: 7.3 M
    Is this ok [y/N]: y
    Downloading Packages:
    (1/6): clamav-milter-0.88 100% |=========================| 72 kB 00:02
    (2/6): clamav-update-0.88 100% |=========================| 40 kB 00:01
    (3/6): clamav-exim-0.86.2 100% |=========================| 19 kB 00:00
    (4/6): clamav-devel-0.88. 100% |=========================| 179 kB 00:08
    (5/6): exim-4.62-1.fc4.i3 100% |=========================| 1.8 MB 01:03
    (6/6): clamav-data-0.88.3 100% |=========================| 5.1 MB 03:03
    Running Transaction Test
    Finished Transaction Test
    Transaction Test Succeeded
    Running Transaction
    Updating : clamav-data ######################### [1/8]
    Installing: exim ######################### [2/8]
    Installing: clamav-milter ######################### [3/8]
    Updating : clamav-update ######################### [4/8]
    Installing: clamav-exim ######################### [5/8]
    Installing: clamav-devel ######################### [6/8]
    Cleanup : clamav-update ######################### [7/8]
    Cleanup : clamav-data ######################### [8/8]

    Installed: clamav-devel.i386 0:0.88.3-1.fc4 clamav-exim.i386 0:0.86.2-5.fc4 clamav-milter.i386 0:0.88.3-1.fc4
    Dependency Installed: exim.i386 0:4.62-1.fc4
    Updated: clamav-data.i386 0:0.88.3-1.fc4 clamav-update.i386 0:0.88.3-1.fc4
    Complete!
    [root@srvcemay ~]# freshclam
    ERROR: Please edit the example config file /etc/freshclam.conf.
    ERROR: Please edit the example config file /etc/clamd.conf.
    ERROR: Can't parse the config file /etc/clamd.conf
    [root@srvcemay ~]#


    olha só como esta tudo atualizado eu acho he he .. mnas ele da esse erro do freshclam


    o meu freshclam.conf .. não mexi em nada mas só no do clam.dconf

    ##
    ## Example config file for the Clam AV daemon
    ## Please read the clamd.conf(5) manual before editing this file.
    ##


    # Comment or remove the line below.
    Example

    # Uncomment this option to enable logging.
    # LogFile must be writable for the user running daemon.
    # A full path is required.
    # Default: disabled
    #LogFile /var/log/clamd.<SERVICE>
    LogFile /var/log/clamd.<SERVICE>

    # By default the log file is locked for writing - the lock protects against
    # running clamd multiple times (if want to run another clamd, please
    # copy the configuration file, change the LogFile variable, and run
    # the daemon with --config-file option).
    # This option disables log file locking.
    # Default: disabled
    #LogFileUnlock

    # Maximal size of the log file.
    # Value of 0 disables the limit.
    # You may use 'M' or 'm' for megabytes (1M = 1m = 1048576 bytes)
    # and 'K' or 'k' for kilobytes (1K = 1k = 1024 bytes). To specify the size
    # in bytes just don't use modifiers.
    # Default: 1M
    #LogFileMaxSize 2M

    # Log time with each message.
    # Default: disabled
    LogTime

    # Also log clean files. Useful in debugging but drastically increases the
    # log size.
    # Default: disabled
    #LogClean

    # Use system logger (can work together with LogFile).
    # Default: disabled
    LogSyslog

    # Specify the type of syslog messages - please refer to 'man syslog'
    # for facility names.
    # Default: LOG_LOCAL6
    #LogFacility LOG_MAIL

    # Enable verbose logging.
    # Default: disabled
    #LogVerbose

    # This option allows you to save a process identifier of the listening
    # daemon (main thread).
    # Default: disabled
    PidFile /var/run/clamd.<SERVICE>/clamd.pid

    # Optional path to the global temporary directory.
    # Default: system specific (usually /tmp or /var/tmp).
    #TemporaryDirectory /var/tmp

    # Path to the database directory.
    # Default: hardcoded (depends on installation options)
    #DatabaseDirectory /var/lib/clamav

    # The daemon works in a local OR a network mode. Due to security reasons we
    # recommend the local mode.

    # Path to a local socket file the daemon will listen on.
    # Default: disabled
    LocalSocket /var/run/clamd.<SERVICE>/clamd.sock

    # Remove stale socket after unclean shutdown.
    # Default: disabled
    FixStaleSocket

    # TCP port address.
    # Default: disabled
    #TCPSocket 3310

    # TCP address.
    # By default we bind to INADDR_ANY, probably not wise.
    # Enable the following to provide some degree of protection
    # from the outside world.
    # Default: disabled
    #TCPAddr 127.0.0.1

    # Maximum length the queue of pending connections may grow to.
    # Default: 15
    #MaxConnectionQueueLength 30

    # Clamd uses FTP-like protocol to receive data from remote clients.
    # If you are using clamav-milter to balance load between remote clamd daemons
    # on firewall servers you may need to tune the options below.

    # Close the connection when the data size limit is exceeded.
    # The value should match your MTA's limit for a maximal attachment size.
    # Default: 10M
    #StreamMaxLength 20M

    # Limit port range.
    # Default: 1024
    #StreamMinPort 30000
    # Default: 2048
    #StreamMaxPort 32000

    # Maximal number of threads running at the same time.
    # Default: 10
    MaxThreads 50

    # Waiting for data from a client socket will timeout after this time (seconds).
    # Value of 0 disables the timeout.
    # Default: 120
    #ReadTimeout 300

    # Waiting for a new job will timeout after this time (seconds).
    # Default: 30
    #IdleTimeout 60

    # Maximal depth directories are scanned at.
    # Default: 15
    MaxDirectoryRecursion 15
    # Follow directory symlinks.
    # Default: disabled
    #FollowDirectorySymlinks

    # Follow regular file symlinks.
    # Default: disabled
    FollowFileSymlinks

    # Perform internal sanity check (database integrity and freshness).
    # Default: 1800 (30 min)
    SelfCheck 600

    # Execute a command when virus is found. In the command string %v will
    # be replaced by a virus name.
    # Default: disabled
    #VirusEvent /usr/local/bin/send_sms 123456789 "VIRUS ALERT: %v"

    # Run as a selected user (clamd must be started by root).
    # Default: disabled
    User clamav #<USER>

    # Initialize supplementary group access (clamd must be started by root).
    # Default: disabled
    #AllowSupplementaryGroups

    # Stop daemon when libclamav reports out of memory condition.
    #ExitOnOOM

    # Don't fork into background.
    # Default: disabled
    #Foreground

    # Enable debug messages in libclamav.
    # Default: disabled
    #Debug

    # Do not remove temporary files (for debug purposes).
    # Default: disabled
    #LeaveTemporaryFiles
    # By default clamd uses scan options recommended by libclamav. This option
    # disables recommended options and allows you to enable selected ones below.
    # DO NOT TOUCH IT unless you know what you are doing.
    # Default: disabled
    #DisableDefaultScanOptions

    ##
    ## Executable files
    ##

    # PE stands for Portable Executable - it's an executable file format used
    # in all 32-bit versions of Windows operating systems. This option allows
    # ClamAV to perform a deeper analysis of executable files and it's also
    # required for decompression of popular executable packers such as UPX, FSG,
    # and Petite.
    # Default: enabled
    #ScanPE

    # With this option clamav will try to detect broken executables and mark
    # them as Broken.Executable
    # Default: disabled
    #DetectBrokenExecutables


    ##
    ## Documents
    ##

    # This option enables scanning of Microsoft Office document macros.
    # Default: enabled
    #ScanOLE2

    ##
    ## Mail files
    ##

    # Enable internal e-mail scanner.
    # Default: enabled
    ScanMail

    # If an email contains URLs ClamAV can download and scan them.
    # WARNING: This option may open your system to a DoS attack.
    # Never use it on loaded servers.
    # Default: disabled
    #MailFollowURLs


    ##
    ## HTML
    ##

    # Perform HTML normalisation and decryption of MS Script Encoder code.
    # Default: enabled
    #ScanHTML


    ##
    ## Archives
    ##

    # ClamAV can scan within archives and compressed files.
    # Default: enabled
    ScanArchive

    # Due to license issues libclamav does not support RAR 3.0 archives (only the
    # old 2.0 format is supported). Because some users report stability problems
    # with unrarlib it's disabled by default and you must uncomment the directive
    # below to enable RAR 2.0 support.
    # Default: disabled
    #ScanRAR

    # The options below protect your system against Denial of Service attacks
    # using archive bombs.

    # Files in archives larger than this limit won't be scanned.
    # Value of 0 disables the limit.
    # Default: 10M
    ArchiveMaxFileSize 15M

    # Nested archives are scanned recursively, e.g. if a Zip archive contains a RAR
    # file, all files within it will also be scanned. This options specifies how
    # deep the process should be continued.
    # Value of 0 disables the limit.
    # Default: 8
    ArchiveMaxRecursion 9

    # Number of files to be scanned within an archive.
    # Value of 0 disables the limit.
    # Default: 1000
    ArchiveMaxFiles 1000

    # If a file in an archive is compressed more than ArchiveMaxCompressionRatio
    # times it will be marked as a virus (Oversized.ArchiveType, e.g. Oversized.Zip)
    # Value of 0 disables the limit.
    # Default: 250
    #ArchiveMaxCompressionRatio 300

    # Use slower but memory efficient decompression algorithm.
    # only affects the bzip2 decompressor.
    # Default: disabled
    #ArchiveLimitMemoryUsage

    # Mark encrypted archives as viruses (Encrypted.Zip, Encrypted.RAR).
    # Default: disabled
    #ArchiveBlockEncrypted

    # Mark archives as viruses (e.g. RAR.ExceededFileSize, Zip.ExceededFilesLimit)
    # if ArchiveMaxFiles, ArchiveMaxFileSize, or ArchiveMaxRecursion limit is
    # reached.
    # Default: disabled
    #ArchiveBlockMax


    ##
    ## Clamuko settings
    ## WARNING: This is experimental software. It is very likely it will hang
    ## up your system!!!
    ##

    # Enable Clamuko. Dazuko (/dev/dazuko) must be configured and running.
    # Default: disabled
    #ClamukoScanOnAccess
    # Set access mask for Clamuko.
    # Default: disabled
    #ClamukoScanOnOpen
    #ClamukoScanOnClose
    #ClamukoScanOnExec

    # Set the include paths (all files in them will be scanned). You can have
    # multiple ClamukoIncludePath directives but each directory must be added
    # in a seperate line.
    # Default: disabled
    #ClamukoIncludePath /home
    #ClamukoIncludePath /students

    # Set the exclude paths. All subdirectories are also excluded.
    # Default: disabled
    #ClamukoExcludePath /home/guru

    # Don't scan files larger than ClamukoMaxFileSize
    # Value of 0 disables the limit.
    # Default: 5M
    #ClamukoMaxFileSize 10M


  4. #4
    silmar
    Visitante

    Padrão Re: Antivirus clamav.

    ahuuhauhauhauha
    sabem o que eu esqueci ... de comentar a linha Exemplo...
    nossa
    que mancada feia ..
    agora estou implantando num FC2 o mesmo antivirus

  5. #5
    silmar
    Visitante

    Padrão Re: Antivirus clamav.

    Mas agora falta colocar o postfix em conjunto com ele .. e eu ainda nao consegui ...

    com aquele exemplo alguem tem outro exemplo ou se pode me dar uma força .. pra colocar ele e o spam ..

  6. #6

    Padrão Re: Antivirus clamav.

    Perguntei ao google e ele me respondeu isso: http://www.linux.com/article.pl?sid=06/02/28/1515201

    :-D