Re: antivirus for linux

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 06/17/04

  • Next message: Dennis Schut: "RE: antivirus for linux"
    Date: Thu, 17 Jun 2004 14:12:53 +0200
    To: security-basics@securityfocus.com
    
    

    On 2004-06-15 Bruno França dos Reis wrote:
    > I'm kinda new to linux, and getting more and more worried about
    > security. I was wondering: is it necessary for me to have an
    > anti-virus application? If so, is it a "live scanner", like the ones I
    > know for windows?

    Running a virus scanner is never necessary, though running one may be a
    Good Idea(tm), since it allows you to identify certain malware. However,
    keep in mind that any scanner is only as good as its signatures are. If
    you are using outdated signatures, then the scanner won't be very
    useful. Also keep in mind that a scanner may be fooled in some way or
    the other, e.g.:

    - compressed file in a compressed file in a ...
    - compression-algorithm unknown to the scanner
    - encrypted files
    - compressed large files may DoS the scanner

    > Do you recommend using an anti-virus software?

    If you are running on Linux only, you probably won't need AV software.
    If you have some Windows clients in your network, you would probably
    want a virus scanner to scan directories your Linux box shares over the
    network.

    > If so, which?

    I won't recommend any, but there are various AV products available for
    Linux, e.g.:

    - ClamAV [1]
    - F-Prot [2]
    - AntiVir [3]

    > Moreover, I have a linux firewall. Is there any way for me to detect
    > virus activity trying either to break into a computer (like Sasser or
    > others like it)

    Sasser and the like are not viruses but worms. A virus scanner won't
    help against those, because when the scanner detects them, the intrusion
    has already happened. I would recommend preventing infection by not
    providing the exploited services to the outside world rather than just
    detecting that you've been hosed. To be more precise, provide only
    services to the outside world that definitely must be accessible from
    there. Not to forget: keep your system patched.

    > or to detect incoming mail with virus? Note: my firewall isn't my mail
    > server. I was wondering if it could sniff connections to pop mail
    > servers and detect virus code.

    AMaViS [4] will allow you to scan mails.

    [1] http://www.clamav.net/
    [2] http://www.f-prot.com/products/home_use/linux/
    [3] http://www.antivir.de/en/
    [4] http://www.amavis.org/

    HTH

    Regards
    Ansgar Wiechers

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Dennis Schut: "RE: antivirus for linux"

    Relevant Pages

    • [Full-Disclosure] A real-life story (no analogies) Was: Anti-MS drivel
      ... with comparing linux and windows I found out I have something that I ... Scenario now forks in two branches: one for giving up old scanner ... Going for the flash card reader. ... Connecting it to my USB hub. ...
      (Full-Disclosure)
    • Re: Linux on Laptop?
      ... proprietary Linux C compiler outperforming gcc on many code ... There are a lot of "consumer level" scanners that SANE doesn't support ... When Joe User buys a Foobar 300 scanner for $49.99 at Wal-Mart, ... Three kinds of lies: ...
      (comp.os.linux.misc)
    • Re: Alternative to SANE (not supporting new scanners): TWAIN or Mac OS X binary compatibility?
      ... I have Linux only PCs ... > SANE project not only lack of support for it (in the mailing list they ... > said HP is not providing any useful info on this scanner, ...
      (comp.os.linux.hardware)
    • Re: Changing from MS
      ... Go to Packman and download the latest Sane and Xsane ... and especially LIBIEEE1284 library (if it runs off the parallel port). ... You cannot use the YAST hardware scanner to set it up. ... Linux is progressing at an even faster rate than Windows is, ...
      (alt.os.linux.suse)
    • Linux Scanner Website Project
      ... I have this great idea for a Linux project. ... You enclose the scanner in the acrylic to make it look like ... web server in order to minimize web attack. ... an IMAP/SMTP mail server, or a mail agent to send/receive ...
      (comp.os.linux.misc)