LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-06-2010, 10:22 PM   #1
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Rep: Reputation: 147Reputation: 147
ClamAV hangs on reaching virtual devices?


I'm noodling around with Ubuntu 10.4.1, latest updates and kernel (2.6.32.24?).

Anyway, I run ClamAv as root and it goes fine through almost all of my system (huge amount of it), including several virtual devices, where it hangs on pan0, which has some association with my network (eth0 would be for wired connection, and wlan0 for wireless, and pan0 is listed also, but I'm not at that machine right now, so I can't tell why it shows up. wlan0 is what I use to connect to the internet).

Is there an issue for clamAV with virtual devices? Any workaround? I had to terminate the scan after it stayed hung for over 5 minutes on pan0.

Thanks.
 
Old 09-07-2010, 10:43 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
I don't know if there's issues with ClamAV and device files as I notified BitDefender of the same about two years ago. Maybe it depends on your engine version because for any /dev/* entry my ClamAV returns "ERROR: Not supported file type".
 
Old 09-07-2010, 12:19 PM   #3
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Original Poster
Rep: Reputation: 147Reputation: 147
Quote:
Originally Posted by unSpawn View Post
I don't know if there's issues with ClamAV and device files as I notified BitDefender of the same about two years ago. Maybe it depends on your engine version because for any /dev/* entry my ClamAV returns "ERROR: Not supported file type".
I downloaded, installed, and ran, ClamAV yesterday (6 Sept.), so I'm thinking it should be the latest engine version available. It ran fine, and even handled several virtual devices, hanging only on pan0.

Is there any particular argument syntax I should pass to ClamAV at the command line when starting it so that it will bypass /dev in its entirety?

Thanks
 
Old 09-07-2010, 01:49 PM   #4
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Quote:
Originally Posted by moxieman99 View Post
I downloaded, installed, and ran, ClamAV yesterday (6 Sept.), so I'm thinking it should be the latest engine version available. It ran fine, and even handled several virtual devices, hanging only on pan0.

Is there any particular argument syntax I should pass to ClamAV at the command line when starting it so that it will bypass /dev in its entirety?

Thanks
--exclude=/dev ?
 
Old 09-07-2010, 04:01 PM   #5
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Original Poster
Rep: Reputation: 147Reputation: 147
Quote:
Originally Posted by nomb View Post
--exclude=/dev ?
I'll check it out this evening. Thanks.
 
Old 09-07-2010, 05:23 PM   #6
joec@home
Member
 
Registered: Sep 2009
Location: Galveston Tx
Posts: 291

Rep: Reputation: 70
Quote:
Originally Posted by nomb View Post
--exclude=/dev ?
While I do not know the correct answer to this problem, I have seen hackers create directories in /dev/ to hide back doors running on the server. Though I would say it is very rare and not something a kid using pre-made scripts would know how to do.
 
Old 09-09-2010, 10:01 AM   #7
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Original Poster
Rep: Reputation: 147Reputation: 147
Found out that Pan0 is my bluetooth service, and by stopping the service i should eliminate that particular hang. I have found other hangs, in /sys/devices/virtual, so I will probably have to exclude the entire folder.

ClamAV has never given me such trouble before.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
When I run clamav, it just waits, no message (even with -v ), avsan hangs loading db lumix Linux - Software 1 05-13-2008 11:17 PM
LXer: ASSP With Embedded ClamAV Integrated Into Postfix With Virtual Users And Domain LXer Syndicated Linux News 0 09-06-2007 10:00 PM
LXer: Using DSPAM & ClamAV With Postfix (Virtual Users) On Debian Etch LXer Syndicated Linux News 0 08-16-2007 09:20 PM
LXer: Virtual Users With Postfix, PostfixAdmin, Courier, Mailscanner, ClamAV On CentOS LXer Syndicated Linux News 0 02-04-2007 02:21 PM
PC hangs on startup with USB devices connected davee Linux - Hardware 5 09-12-2003 11:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration