HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.
It is currently 22 Jun 2014 09:52

All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: 22 Dec 2008 10:19 
Offline

Joined: 22 Dec 2008 10:00
Posts: 3
Hi

Please tell me if i am using HAVP in a way where it should not be used, but i am currently experimenting a reverse-proxy configuration, in the scheme browser->squid->havp->tomcat_java_app

To achieve that, i set HAVP in "transparent" mode, and put the tomcat web site as its parent.

I saw somewhere in the forum people wondering why we should need virus scanning at upload, well... this is exactly one case: prevent users from uploading viruses on the website (here a java/tomcat powered community web site).

So, if there are no way, nor plans to add scanning at upload, is there any trick or alternative have the file scanned before it is submitted to the parent ?

Note that i also tried using c-icap+clamav with squid3, and there also appeared no scan at upload. Furthermore, it appeared to me as being very unreliable, as one page of ten would always seem unreachable and report an error, despites squid alone would work great without c-icap+clamav.


Top
 Profile  
 
PostPosted: 22 Dec 2008 11:23 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Searching uploaded files from POST requests requires some parsing. As you may have noticed from the announcement, there aren't any developers to do new features currently.

No way to scan in the web server itself after upload? That would be the safest way.


Top
 Profile  
 
PostPosted: 27 Dec 2008 22:19 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
A good way, to do so is for example dazuko (on-access scanning) for that directory, where uploads are stored. Dazuko is rejecting the file, if there is any virus!
But don't use dazuko for the whole web folder! It slow down your requests rapidly!


Top
 Profile  
 
PostPosted: 28 Dec 2008 11:40 
Offline

Joined: 22 Dec 2008 10:00
Posts: 3
Ah,
i did not think about this, as the configuration file indicates that Dazuko is beta and not ready for production use. I may give it a try, then


Top
 Profile  
 
PostPosted: 31 Dec 2008 11:28 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
Are you using the newest kernel version (2.6.28)?
I installed all versions and can say, it's stable and no problems coming up!
If you compile every new kernel versions, it's a little bit more work.
But i can't believe this on a web server. The earlier versions of dazuko are stable.

wish you all a happy new year ...


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group