Re: libclamav versus clamd

"Jason Haar" <[email protected]> Tue, 1 Jun 2004 04:05:35 +1200 (NZST)
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
Kurt Huwig said:
>> So, in short: clamd must run as root, I'm afraid (with read/write
>> permissions for everyone of the socket). POSIX ACLs may help here, but I
>> never really played with attr, setfattr and alike.

What's wrong with running clamd as root? I mean, assuming there are no
exploitable holes in clamd, then what other problems are there?

As far as I'm aware, clamd is merely asked to scan a file/dir for viruses
and tell you the (effectively boolean) results - it doesn't return the
contents of the files or anything.

Assuming there is no local logins on a Samba server, and clamd is running
over a socket instead of TCP, then there should be no way a remote user
could exploit the situation to gain file details information they don't
already have...

How do Windows online virus scanners work - I bet they run with SYSTEM
privileges...

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1



-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click