LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-13-2013, 03:55 AM   #1
jgujar
LQ Newbie
 
Registered: Jul 2013
Posts: 1

Rep: Reputation: Disabled
Does Linux server need an antivirus?


Hi Friends,

I always wonder whether a Linux server need an antivirus protection?

Or you need anti-spyware?

thanks,
Jagdish
 
Old 07-13-2013, 04:26 AM   #2
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Not really.

Linux has several partitioning schemes to isolate system files from the user - UID/GID/ACLs SELinux... and it is rather rigidly enforced.

There CAN be privilege escalation bugs, and/or vulnerable services, but they are rather quickly dealt with, with the result that any virus created for them get flushed out of general use.

Spyware usually requires the system administrator to install them - thus they don't usually work. User mode spyware (attacks on browsers) are possible, but here, they must be installed by the user. Such spyware is usually targeted at a specific browser, and don't work well if at all in multiple. Linux has many browsers, thus it is not that common attemped. Changes in browsers/updates also tend to flush these out as well.

The best current use of an anti-virus application is to scan files for Windows problems. Especially if the Linux server is providing files to Windows clients.

Email issues are usually handled by spam filtering - and that catches most things. Again, there are lots of different mail readers, so attacking one specific one is not all that useful. Regular patching/updates also tend to flush these out as well.

Since Linux doesn't run network based services by default, external attacks are also not seen by basic desktops.
 
Old 07-13-2013, 02:01 PM   #3
David Trest
Member
 
Registered: Jul 2013
Distribution: CentOS/RHEL, Backtrack, many more.
Posts: 58

Rep: Reputation: Disabled
There's no harm in installing an anti-virus package. It's a lower method of defense compared to Windows and Mac, since Linux is less targeted for viruses and has more of a problem with exploits and more.

But if you're using a platform that will go to an end-user, such as a mail server, an anti-virus package becomes very valuable since it enables you to scan the files and messages that will be sent to the end-user, providing another layer of defense.
 
Old 07-14-2013, 11:05 AM   #4
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,974

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
A server admin always uses as many best practices as they can. Installing apps like av and such are a basic part of security. That and many other admin tasks secure your system.
 
Old 07-14-2013, 11:11 AM   #5
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Quote:
Originally Posted by jefro View Post
A server admin always uses as many best practices as they can. Installing apps like av and such are a basic part of security. That and many other admin tasks secure your system.
first sentence is ok. Last sentence ok.

Anti-virus only works where a virus can thrive and the vendor is not responsive to bugs. Your second sentence is true for Windows, but nowhere else.

The only use an anti-virus has on UNIX/Linux is to try to protect the unprotectable - Windows.
 
Old 07-14-2013, 11:25 AM   #6
FortressMvelez
Member
 
Registered: May 2013
Location: Bronx, New York
Posts: 40

Rep: Reputation: Disabled
Hey,

You can use something like Maldet to run scans on your system to find anything that can cause issues with your server such as malicious scripts. Malicious scripts can assist in someone gaining access to your server or creating a spam headache. Maldet is free and easy to use. For more information, you can visit the following link:

http://www.rfxn.com/projects/linux-malware-detect/
 
Old 07-22-2013, 10:02 AM   #7
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Rep: Reputation: 78
in what context is the Q?

if its in-scope for PCI you need an AV product. today most products by the big vendors call their crud "anto-malware" and/or license you pieces of their anti-malware "suite", etc.

and for me personally, no scheme, be it partitioning or SElinux or the like is 100%, thus having extra layers is not a bad thing. you do however have to evaluate the cost model (how good is the product vs what it costs and how much effort to support it, etc?)

clamAV is free, but how good is it is a question that is full of metrics and when you squish all of those metrics up you get an appropriate answer for the system in question, etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
antivirus for linux mail server salimshahzad Linux - Newbie 2 11-02-2010 06:05 AM
Antivirus survey: Do you run an antivirus program on linux? atom Linux - General 29 09-03-2009 03:22 PM
Antivirus for windows files on linux server ? Which one ? zonemikel Linux - Server 5 05-24-2008 12:32 PM
I want to setup antivirus on my linux server cj_cheema Linux - Security 3 01-17-2007 06:46 AM
Centralizedd Linux Antivirus Server for Windows XP Clients Khawk Linux - Security 7 08-18-2005 12:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration