store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 5:54 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 
Author Message
 Post subject: clamav shows your files with virus
Unread postPosted: Thu May 07, 2009 6:10 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Apr 23, 2009 12:08 pm
Posts: 218
i have setup for yum repository and installed your clamav as well as your mod_security. The mod_security rules were downloaded from delayed rules at:

http://downloads.prometheus-group.com/delayed/rules/

clamscan shows the domain-blacklist.txt file (mod_security rules) as well as an extended amount of the clamscan files themselves with viruses.

Is this clamscan functioning correctly? Downloaded through your repository system, are there issues or are 50+ files reported with virus correct? Are the mod_security rules safe?


Top
 Profile  
 
 Post subject: Re: clamav shows your files with virus
Unread postPosted: Thu May 07, 2009 10:46 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
The rules are safe, but you really should post the output of your clamscan. If you mean its showing things like this:

MBL_37439.UNOFFICIAL FOUND

Yes, thats normal - because those same rules are also replicated in the domain and mailware blacklists. The MBL is a malware blacklist and there is overlap between the two.

Or something like this:

PHP.ShellExec.Web-downloader.ASL.190703202513.UNOFFICIAL FOUND

Yes, thats also because the modsec rules and our clamav rules share the same base - its the same signatures in different formats.

Try running any antivirus product against its own files, you'll see the same things.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: clamav shows your files with virus
Unread postPosted: Fri May 08, 2009 12:44 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Apr 23, 2009 12:08 pm
Posts: 218
Okay, I am getting the similar response, and i have downloaded the files to my computer and ran the ESET virus scan on these files and they pass ok, so they should be all-right.

/etc/httpd/modsecurity.d/domain-blacklist.txt: MBL_37439.UNOFFICIAL FOUND
Thu May 7 14:12:43 2009 -> /etc/httpd/modsecurity.d/malware-blacklist-high.txt: MBL_62039.UNOFFICIAL FOUND
Thu May 7 14:12:43 2009 -> /etc/httpd/modsecurity.d/malware-blacklist.txt: MBL_102618.UNOFFICIAL FOUND
Thu May 7 14:12:43 2009 -> /etc/httpd/modsecurity.d/modsec-2.5-free-latest.tar.gz: MBL_62039.UNOFFICIAL FOUND
Thu May 7 14:12:44 2009 -> /etc/httpd/modsecurity.d/modsec/domain-blacklist.txt: MBL_37439.UNOFFICIAL FOUND
Thu May 7 14:12:44 2009 -> /etc/httpd/modsecurity.d/modsec/malware-blacklist-high.txt: MBL_62039.UNOFFICIAL FOUND
Thu May 7 14:12:44 2009 -> /etc/httpd/modsecurity.d/modsec/malware-blacklist.txt: MBL_102618.UNOFFICIAL FOUND

Thanks for the fine repository system and protection you offer. When i finally get this VPS squared away i shall look into the active subscription. I am new to webservers and such, and my hesitation is "do i really want to handle this stuff" or just have websites on shared hosting plans? Until i am fully committed, i will look to the mod_security delayed plan. Thanks.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group