LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Closed Thread
  Search this Thread
Old 12-08-2005, 01:53 AM   #1
jomy
Member
 
Registered: Jul 2004
Location: UAE
Distribution: RedHat
Posts: 93

Rep: Reputation: 15
Virus Scanning Through HTTP web traffic with Dansguardian & ClamAV


Hi,


I'm trying to scan for viruses during http web traffic and viruses that comes through mail through my RHEL ES 3.

I installed Clamav from clamav-0.87.1.tar.gz . It was installed in /usr/local/etc . I also installed libesmtp. My mailserver is postfix. I added the necessary entries in Postfix and Mailscanner to scan for viruses through mail. It is working perfectly fine and I've no problem with that.

My problem starts when I try to scan http web traffic for viruses. Let me explain what I've done to scan for http web traffic:.

I installed Dansguardian with ClamAV plugin from Dansguardian-2.9.2.0.tar.gz. as my content scanner .I configured it with the command :

./configure –sysconfdir=/etc –enable-clamd=yes option.

Squid is my proxy server. Dansguardian uses port 8080 and squid is configured on port 3128. Client browsers are configured to access internet through port 8080 . ie, Client ==>DG==>Squid==>ISP. Upto this everything works fine. I can block certain sites, urls,extensions,mimetypes etc... through the files in /etc/dansguardin/lists. Internet browsing also works fine upto here.

Now I changed my /etc/dansguardin/dansguardian.conf to scan http web traffic for viruses. I uncommented the line :

contentscanner = '/etc/dansguardian/contentscanners/clamdscan.conf '

to enable content scanning on html pages for viruses.

And in /etc/dansguardian/contentscanners/clamdscan.conf ,

I changed the line ,

clamduds file = '/var/run/clamav/clamd.sock '

to

clamduds file = '/tmp/clamd '

( I assume this is correct . If I don't change that I get error)

I restarted dansguardian , and tried to access internet . But to whatever pages I'm trying to access , I get the “Access Denied” Message from Dansguardian with the Reason :


WARNING : Could Not Perform Virus Scan !

Categories

Content Scanning


I get the following message in /var/log/messages


ScanFile/Memory returned error : -1


The result I'm looking for is to get a Virus warning message when I try to execute or download a virus from HTML Pages

Waiting for your valued suggestions & solutions

Regards,

Jomy
 
Old 12-11-2005, 06:24 AM   #2
jomy
Member
 
Registered: Jul 2004
Location: UAE
Distribution: RedHat
Posts: 93

Original Poster
Rep: Reputation: 15
Suspecting problem with Socket

Hi,

I suspect this to be the problem with socket . I was using Local Unix Socket /tmp/clamd and I could see the following error in /tmp/clamd.log:

ERROR Connecting to Clamd Socket

Now I'm using TCP Socket instead of Local Socket and did the following changes in clamd.conf

TCPSocket 3310
TCPAddr 127.0.0.1

Now I find difficulty in configuring /usr/loca/etc/dansguardian/dansguardian/clamdscan.conf ( clamdscan is my content scanner) where there is an option like this.

# Edit this to match the Location of your Local Unix Socket
# clamdudsfile = '/var/run/clamav/clamd.sock'

Since I'm using TCP Socket instaed of Local Unix Socket , how can I configure my clamdscan.conf file so that it can be bound to TCPSocket 3310.

Your help is very much appreciated.

Jomy
 
Old 12-11-2005, 10:56 AM   #3
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
Please do not post the same thread in more than one forum. Picking the most relevant forum and posting it once there makes it easier for other members to help you and keeps the discussion all in one place.

http://www.linuxquestions.org/rules.php

Please continue here:
http://www.linuxquestions.org/questi...d.php?t=390094
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus Scanning through HTTP Web Traffic with Dansguardian & ClamAV jomy Linux - Security 3 12-14-2005 12:06 PM
Dansguardian with ClamAV jomy Linux - Networking 0 11-30-2005 12:28 AM
On-access virus scanning with Clamav Berhanie Linux - Software 0 05-19-2005 11:56 AM
email virus scanning & evolution tuxrules Slackware 2 05-10-2005 05:55 PM
Clamav scanning outgoing, but not incoming mail chaan Linux - Software 0 04-09-2004 01:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration