OP#785 move to clamdscan command

This commit is contained in:
2026-09-22 12:52:19 +02:00
parent 7f20c0e45e
commit 0b24fcdb8e
2 changed files with 17 additions and 11 deletions

View File

@@ -16,6 +16,7 @@
"epel", "epel",
"excludepaths", "excludepaths",
"fanotify", "fanotify",
"fdpass",
"filesize", "filesize",
"freshclam", "freshclam",
"getsebool", "getsebool",
@@ -31,12 +32,14 @@
"logsyslog", "logsyslog",
"logtime", "logtime",
"logverbose", "logverbose",
"multiscan",
"mypass", "mypass",
"myproxy", "myproxy",
"myusername", "myusername",
"NOFILE", "NOFILE",
"normalisation", "normalisation",
"PCRE", "PCRE",
"pipefail",
"preludeanalyzername", "preludeanalyzername",
"preludeenable", "preludeenable",
"recieve", "recieve",

View File

@@ -1,23 +1,26 @@
#!/bin/bash #!/bin/bash
set -euo pipefail
# Set paths
SCAN_DIR="<%= @cv_scan_dir %>" SCAN_DIR="<%= @cv_scan_dir %>"
LOG_FILE="<%= @cv_logfile %>" LOG_FILE="<%= @cv_logfile %>"
TMP_ALERT="<%= @cv_alert_file %>" TMP_ALERT="<%= @cv_alert_file %>"
EMAIL="<%= @cv_alert_email %>" EMAIL="<%= @cv_alert_email %>"
# Run clamscan # Ensure the log directory exists
clamscan -r --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null mkdir -p "$(dirname "$LOG_FILE")"
# Check if infections were found # Preferred: clamdscan with multiscan + fdpass
if grep -q "Infected files: [^0]" "$LOG_FILE"; then clamdscan --multiscan --fdpass --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null || true
echo "ClamAV has found infected files on $(hostname)!" > "$TMP_ALERT"
echo "" >> "$TMP_ALERT" # Check for infections (same logic as before)
grep "FOUND" "$LOG_FILE" >> "$TMP_ALERT" if grep -q "Infected files: [^0]" "$LOG_FILE" 2>/dev/null; then
{
echo "ClamAV has found infected files on $(hostname)!"
echo ""
grep "FOUND" "$LOG_FILE" || true
} > "$TMP_ALERT"
# Send the alert email
mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT" mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT"
fi fi
# Clean up rm -f "$TMP_ALERT"
rm -f "$TMP_ALERT"