Re: libclamav versus clamd
"Larry M. Smith" <[email protected]> Mon, 31 May 2004 12:30:58 -0500
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Message-ID | <[email protected]> |
Jason Haar wrote: > Kurt Huwig said: > >>>So, in short: clamd must run as root, I'm afraid (with read/write >>>permissions for everyone of the socket). POSIX ACLs may help here, but I >>>never really played with attr, setfattr and alike. > > > What's wrong with running clamd as root? I mean, assuming there are no > exploitable holes in clamd, then what other problems are there? > "because as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns — the ones we don't know we don't know." File system AV solutions need to be able to read files... From a trust model standpoint; How much trust does one have over a process verses a user. How much trust does one have over known system processes verses user processes. How much trust does one have over the entire system. It could be that the AV solution has to run as root in order to do its job... Perhaps only a part of it has to run as a specific user and it should be broken down into small parts. > As far as I'm aware, clamd is merely asked to scan a file/dir for viruses > and tell you the (effectively boolean) results - it doesn't return the > contents of the files or anything. > How does the over all solution react?... Does the AV solution (not just the scanner engine, but additional scripts) attempt to delete, quarantine or attempt to repair the infection? > Assuming there is no local logins on a Samba server, and clamd is running > over a socket instead of TCP, then there should be no way a remote user > could exploit the situation to gain file details information they don't > already have... > These are a lot of assumptions... What happens when a remote user does happen to get non-privileged access to a shell on the host via some other exploit? Are there other holes on that system that allow this AB type user[1] greater privilege? > How do Windows online virus scanners work - I bet they run with SYSTEM > privileges... > Failed security models currently in use should not be used to justify the continued use of their practices. SgtChains [1] For these types of conversations I express users as two types... The "L" type, and the "AB" type. I.e. Lusers and ABusers. ------------------------------------------------------- This SF.Net email is sponsored by the new InstallShield X. From Windows to Linux, servers to mobile, InstallShield X is the one installation-authoring solution that does it all. Learn more and evaluate today! http://www.installshield.com/Dev2Dev/0504