Re: libclamav versus clamd

Andreas <andreas-KCZ47A4bww4P48s/[email protected]> Mon, 31 May 2004 14:24:31 -0300
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
On Mon, May 31, 2004 at 07:15:35PM +0200, Pascal J.Bourguignon wrote:
> Andreas writes:
> > On Tue, Jun 01, 2004 at 04:05:35AM +1200, Jason Haar wrote:
> > > What's wrong with running clamd as root? I mean, assuming there are no
> > > exploitable holes in clamd, then what other problems are there?
> > 
> > Does it need to run as root?
> > If there is a security problem, then why make it a remote-root vulnerability?
> 
> If it has to scan ALL the files, yes, it has to be root.

No, one can use posix acls in order to give read access to the directories and
files it has to scan. It doesn't even have to have write access if one doesn't
use the quarantine option.

> If it has to scan only the files that belong to one user, 
> then it can run under that user's account.

But some setuid() capability would be needed, as it is a multiuser system.

> If it has to run under the accounts of each user in turn, then yes, 
> it has to be root, at least to setuid (the subprocess that is doing
> the actual scanning can be run under that user's account).

That's more or less how it works if compiled with the libclamav option, because
smbd is already running as the user. But this mode has its own drawbacks (see
my previous post).

> Note that the directory hierarchy may contain traps that prevent a
> user to access files that belong to him.  You need to be root to scan
> them!

If the user doesn't have read access to these files, then this same user
can't get infected via these files, right?

All in all, I think using clamd running as user "clamav" together with
posix acls for the filesystem are quite good. Could be better? Yes, perhaps
some improvements with the libclamav option regarding performance and
startup, but that will come at its time, this is just the first version
which has this support.



-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click