LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Closed Thread
  Search this Thread
Old 09-28-2010, 08:35 AM   #1
winairmvs
Member
 
Registered: Aug 2009
Posts: 42

Rep: Reputation: 16
Convert kaspersky virus signature to clamav


I was curious if anyone has attempted or successfully converted a kaspersky virus signature file to clamav signature? During a trial period using kaspersky anti virus for our web server I successfully petitioned them to write signatures for some nasty php web-shell hacks, and now that the trial period has expired I don't have the ability to scan for the files anymore (I know I am cheap!). The first hurdle would be finding the correct file, as their signatures are all done in hexadecimal format, and my knowledge for searching through that type of file is very limited. Any thoughts are appreciated.

Thanks
 
Old 09-28-2010, 09:15 AM   #2
bomelia
Member
 
Registered: May 2004
Posts: 33

Rep: Reputation: 15
Quote:
Originally Posted by winairmvs View Post
I was curious if anyone has attempted or successfully converted a kaspersky virus signature file to clamav signature? During a trial period using kaspersky anti virus for our web server I successfully petitioned them to write signatures for some nasty php web-shell hacks, and now that the trial period has expired I don't have the ability to scan for the files anymore (I know I am cheap!). The first hurdle would be finding the correct file, as their signatures are all done in hexadecimal format, and my knowledge for searching through that type of file is very limited. Any thoughts are appreciated.

Thanks
Kaspersky supports Linux? Cool! Just buy it. They have great software (I only know them from the Windows world) and I lover their forum based support.

Mike
 
Old 09-28-2010, 09:52 AM   #3
winairmvs
Member
 
Registered: Aug 2009
Posts: 42

Original Poster
Rep: Reputation: 16
Quote:
Originally Posted by bomelia View Post
Kaspersky supports Linux? Cool! Just buy it. They have great software (I only know them from the Windows world) and I lover their forum based support.

Mike
I want to! The problem is that scanning our entire web root (over 700 web customers worth of data) with kaspersky takes well over 15 hours and is very resource intensive. The clamav scanner takes approximately 4 hours to complete and does not kill my web server. Kaspersky's documentation is a bit sparse in the linux realm, which always turns me off to a product.
 
Old 09-28-2010, 03:25 PM   #4
mostlyharmless
Senior Member
 
Registered: Jan 2008
Distribution: Arch/Manjaro, might try Slackware again
Posts: 1,851
Blog Entries: 14

Rep: Reputation: 284Reputation: 284Reputation: 284
Quote:
I successfully petitioned them to write signatures for some nasty php web-shell hacks, and now that the trial period has expired I don't have the ability to scan for the files anymore (I know I am cheap!).
Not to rain on your parade, but if you succeeded in converting the data you would (1) possibly be violating your use agreement (2) dissuade them from offering linux products in the future (3) discourage other companies from participating in linux programs.

I'm not sure if this thread violates LQ rules.
 
Old 09-28-2010, 03:53 PM   #5
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
I don't think that it is a good idea to let your customers be unprotected to save money and ressources. If I were your customer and this would come to my knowledge, I would already leave to a different hoster.
 
Old 09-29-2010, 08:13 AM   #6
winairmvs
Member
 
Registered: Aug 2009
Posts: 42

Original Poster
Rep: Reputation: 16
Good point that there could be a product violation of some kind in using their code, I had not thought of that. Kaspersky it is!

(Tobi relax my friend, if you didn't read my posts entirely I was not planning on leaving anyone unprotected.)
 
Old 09-29-2010, 09:34 AM   #7
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
Quote:
Originally Posted by winairmvs View Post
and now that the trial period has expired I don't have the ability to scan for the files anymore
Doesn't this mean, that they are unprotected?
 
Old 10-11-2010, 09:53 PM   #8
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Just to keep everyone on the right side of the copyrights, I'm going to go ahead and close this thread. I know no malicious intent was implied in asking, but I don't want to tempt anyone.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
can clamav clean virus ...... neelendhar Linux - Software 1 10-31-2007 09:06 AM
ClamAV - Virus?!? RySk8er30 Mandriva 7 12-18-2006 11:47 AM
LXer: Kaspersky Labs' slated for Linux virus FUD LXer Syndicated Linux News 0 04-19-2006 09:54 AM
warning: clamav-0.87.1-1.1.fc2.rf.i386.rpm: V3 DSA signature: NOKEY, key ID 6b8d79e6 Niceman2005 Linux - Software 4 03-07-2006 05:28 AM
Kaspersky Anti-Virus for Linux File Server: Can't find license manager azmadar Linux - Security 1 12-02-2004 08:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 06:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration