LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-31-2016, 06:38 AM   #1
Nirmo
LQ Newbie
 
Registered: May 2016
Posts: 4

Rep: Reputation: Disabled
Clamav Onaccess with Protection pendrive


hi,
I have a problem with clamav Onaccess with mount pendrive and scan.

Clamav Onaccess effect on directories type /home . It's okay. But when I mount the memory stick to the directory /mnt Clamav Onaccess does not work. It does not detect the virus. After the restart clamd everything works .
My configuration:
System: Centos 7
kernel: 3.10.0-327.el7.x86_64
selinux disable
clamav 0.99.1
CONFIG_FANOTIFY=y
CONFIG_FANOTIFY_ACCESS_PERMISSIONS=y
Configuration onaccess:
ScanOnAccess yes
OnAccessIncludePath /home
OnAccessIncludePath /mnt
OnAccessPrevention yes
OnAccessExtraScanning yes

When you mount a USB stick with the virus Onaccess does not work. Why ?
 
Old 05-31-2016, 07:47 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
May I calmly suggest that "virus protection" software is highly overrated, and that the popular term, "virus," is a misnomer?

"Strictly IMHO," you actually expose your system to more "overall, albeit theoretical, vulnerability" by running a piece of software ... a scanner ... which you purposely "give access to everything, albeit for supposedly-sovereign purposes." Anything which a scanner can scan, a sabotaged scanner can modify.

IMHO, you should always remember that a computer system is "merely a machine ... not a biological organism." As a biological organism yourself, you can "catch" a dreadful illness merely by walking into the wrong elevator at the wrong time and breathing, unless your immune system fights it off. Computing machines are not that way.
 
Old 05-31-2016, 08:02 AM   #3
Nirmo
LQ Newbie
 
Registered: May 2016
Posts: 4

Original Poster
Rep: Reputation: Disabled
I did the test with Virus eicar test.

The system detects (clamav +Onaccess) this virus in catalogs and blocks when trying to open . Onaccess works. The problem is at the moment when the mount pendria with the test Virus.
mount /dev/sdc1 /mnt
Onaccess not see the virus . Allows its opening.
Maybe in a bad way I mount this device?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Clamav Onaccess with Protection pendrive Nirmo LinuxQuestions.org Member Intro 2 05-31-2016 08:24 AM
Pendrive Mahendran.Bhupathi Ubuntu 1 08-11-2012 08:41 AM
Mimedefang clamav vs clamav-milter digitolx Linux - Server 0 10-20-2010 03:45 PM
file-scan-clamav-1.8 or clamav-0.93.1 invader44 Linux - Newbie 1 12-29-2009 08:49 AM
How to install and configure grub on pendrive while os' are on the same pendrive? CeremCem DamnSmallLinux 0 11-07-2006 11:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration