Home Samba File Sharing Users & Folders Protect your shares with ClamAV antivirus (scannedonly)

Protect your shares with ClamAV antivirus (scannedonly)

Print PDF

 This feature is available with artica 1.3.123102 version

samba-vscan, the popular samba antivirus hook  is no longer maintain.

We have decided to support "scannedonly" in order to perform antivirus scanning on the network shared folders.
"Scannedonly is a samba VFS module that ensures that only files that have been scanned for viruses are visible and accessible to the end user."

Certainly you need  to upgrade your Samba server with Setup Control Center if you want to use this feature.
With the new Artica 1.3.123102 version,  when upgrading Samba the artica-make process automatically install the associated scannedonly hook software.

The ScannedOnly row is added in the setup Center only if you need to re-install or to rebuild it after the first installation.

Installing ScannedOnly

ScannedOnly need to get Samba sources to be compiled.
Artica will store/keep Samba sources in /usr/local/share/artica/samba after upgrading samba. (Olders Artica versions will delete sources after installation.).
This is the main reason you need to upgrade your samba server.

Click on Install or Upgrade on the Samba Shares Engine row

 

You can perform the same operation in command line by using :

/usr/share/artica-postfix/bin/artica-make APP_SAMBA 

After the installation, you will see that scannedonly has been installed too.

note: You will see that ScannedOnly version is " not applicable". This is normal. Currently the main developer has not include the possibility to display the software version

 

Set your shared folders protected.

  • When sharing a folder trough Artica click on the "options" tab.
  • If ScannedOnly is installed, you will able to turn to green the "Clam Antivirus protection" circle.

Testing your protection

If the protection is active, you will see that your eicar files has been renamed to "VIRUS_found_in_....TXT"

Original detected files has been saved  into the /home/samba-virus directory.

On the syslog, 2 events should be displayed  when detecting viruses:

scannedonlyd_clamav[9393]: 0:0: WARNING: /tmp/eicarcom2.zip contains virus Eicar-Test-Signature!
scannedonlyd_clamav[9393]: 0: moving /tmp/eicarcom2.zip to /home/samba-virus/eicarcom2.zip

 

Last Updated on Thursday, 31 December 2009 02:00  

Newsflash

blackducksoftware.com has decided to put Artica in top 10 of Open Sources Rookies for 2008 years.
Artica start to be seen in the world....

More infos :

http://www.blackducksoftware.com/news/news/2009-01-21