This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
сервис_clamav [2020/08/28 17:22] val |
сервис_clamav [2020/11/12 11:45] val [API ядра FANOTIFY] |
||
---|---|---|---|
Line 42: | Line 42: | ||
$ cd /tmp | $ cd /tmp | ||
- | $ wget http://val.bmstu.ru/unix/virus.zip | + | $ wget http://gate.isp.un/unix/virus.zip |
$ clamdscan virus.zip | $ clamdscan virus.zip | ||
Line 49: | Line 49: | ||
==== API ядра FANOTIFY ==== | ==== API ядра FANOTIFY ==== | ||
+ | * !!! Проверяет только в момент чтения, НЕ записи! | ||
+ | * [[https://www.clamav.net/documents/on-access-scanning|On-Access Scanning]] | ||
* [[https://blog.clamav.net/2016/03/configuring-on-access-scanning-in-clamav.html|Configuring On-Access Scanning in ClamAV]] | * [[https://blog.clamav.net/2016/03/configuring-on-access-scanning-in-clamav.html|Configuring On-Access Scanning in ClamAV]] | ||
- | * Для ubuntu отключить [[Модуль AppArmor]] | + | * [[Модуль AppArmor]] |
<code> | <code> | ||
Line 58: | Line 60: | ||
</code><code> | </code><code> | ||
... | ... | ||
- | User root | + | OnAccessIncludePath /disk2 |
- | ScanOnAccess yes | + | |
- | OnAccessIncludePath /home | + | |
- | OnAccessExcludeUID 0 | + | |
OnAccessPrevention yes | OnAccessPrevention yes | ||
- | ... | + | OnAccessExcludeUname clamav |
+ | </code><code> | ||
+ | # clamonacc | ||
</code> | </code> | ||
===== Журнал ===== | ===== Журнал ===== | ||
<code> | <code> | ||
# tail -f /var/log/clamav/clamav.log | # tail -f /var/log/clamav/clamav.log | ||
- | |||
- | debian# cat /etc/logrotate.d/clamav-daemon | ||
</code> | </code> |