HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.


All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: 18 Nov 2008 16:10 
Offline

Joined: 18 Nov 2008 15:26
Posts: 2
Hi,

I'm using HAVP as a parent proxy for squid. It's working great for most common cases.

I started my testes with simple virus files and everything was working nice.

Now I'm stuck with zip files. If I download one zip file with only the virus inside, HAVP detects it and it works as it should.

If I put more files inside the zip along with the exe virus, it does not detect anything.
I have tried configuring HAVP with clamav and with clamd, both have the same problem.

My system it's centos 5.2, and the versions of the software are:
- havp-0.89-2
- clamd-0.94-1.el5.rf
- clamav-0.94-1.el5.rf

LOGS:
==> /var/log/havp/access.log <==
18/11/2008 12:51:57 127.0.0.1 GET 200 http://xxx.xxx.xxx.xxx/test_virus.zip 260+7323474 OK

==> shell <==
# clamscan test_virus.zip
test_virus.zip: Worm.SomeFool.P FOUND

----------- SCAN SUMMARY -----------
Known viruses: 463741
Engine version: 0.94
Scanned directories: 0
Scanned files: 1
Infected files: 1
Data scanned: 14.79 MB
Time: 3.908 sec (0 m 3 s)

==> shell <==
# clamdscan test_virus.zip
//test_virus.zip: Worm.SomeFool.P FOUND

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 2.133 sec (0 m 2 s)

==> havp.conf <==
LOGLEVEL 1
PORT 8085
KEEPBACKBUFFER 100000
DISABLELOCKINGFOR ClamAV:BinHex ClamAV:PDF ClamAV:ZIP
ENABLECLAMLIB false
CLAMMAXSCANSIZE 100
CLAMMAXFILES 10000
CLAMMAXFILESIZE 50
CLAMMAXRECURSION 16
ENABLECLAMD true
CLAMDSOCKET /tmp/clamd.socket
ENABLEFPROT false
ENABLEAVG false
ENABLEAVESERVER false
ENABLESOPHIE false
ENABLETROPHIE false
ENABLENOD32 false
ENABLEAVAST false
ENABLEARCAVIR false
ENABLEDRWEB false

FILE: http://www.flyupload.com/get?fid=264461365

Can anyone help me out on this? Probably I'm doing something wrong.

Thanks very much,


Top
 Profile  
 
PostPosted: 18 Nov 2008 18:16 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
So what is your MAXSCANSIZE?

If it's 5MB and the virus is at end of the file, it is not detected.


Top
 Profile  
 
PostPosted: 18 Nov 2008 18:48 
Offline

Joined: 18 Nov 2008 15:26
Posts: 2
Ok,

First of all, thanks, that was the (stupid) problem, while reading the config file I have looked to the value and thought in 50MBytes.

# VALUE IN BYTES NOT KB OR MB!!!!
# 0 = No size limit
#
# Default:
# MAXSCANSIZE 5000000

This is 5MBytes.

Maybe you could change this value to kbytes, this value in bytes in now our days maybe it's a little low, and can induce someone easily in error. This is just my opinion.

It's working like a charm nothing to say.

Thanks very much for your help.


Top
 Profile  
 
PostPosted: 18 Nov 2008 18:51 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
I think kbytes would be even more misleading... it's either bytes or megabytes. But it works now and it's not possible to change to keep backwards compatibility.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group