Re: libclamav versus clamd
"Jason Haar" <[email protected]> Tue, 1 Jun 2004 04:05:35 +1200 (NZST)
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Message-ID | <[email protected]> |
Kurt Huwig said: >> So, in short: clamd must run as root, I'm afraid (with read/write >> permissions for everyone of the socket). POSIX ACLs may help here, but I >> never really played with attr, setfattr and alike. What's wrong with running clamd as root? I mean, assuming there are no exploitable holes in clamd, then what other problems are there? As far as I'm aware, clamd is merely asked to scan a file/dir for viruses and tell you the (effectively boolean) results - it doesn't return the contents of the files or anything. Assuming there is no local logins on a Samba server, and clamd is running over a socket instead of TCP, then there should be no way a remote user could exploit the situation to gain file details information they don't already have... How do Windows online virus scanners work - I bet they run with SYSTEM privileges... -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click