OP#785 move to clamdscan command
This commit is contained in:
3
.vscode/settings.json
vendored
3
.vscode/settings.json
vendored
@@ -16,6 +16,7 @@
|
|||||||
"epel",
|
"epel",
|
||||||
"excludepaths",
|
"excludepaths",
|
||||||
"fanotify",
|
"fanotify",
|
||||||
|
"fdpass",
|
||||||
"filesize",
|
"filesize",
|
||||||
"freshclam",
|
"freshclam",
|
||||||
"getsebool",
|
"getsebool",
|
||||||
@@ -31,12 +32,14 @@
|
|||||||
"logsyslog",
|
"logsyslog",
|
||||||
"logtime",
|
"logtime",
|
||||||
"logverbose",
|
"logverbose",
|
||||||
|
"multiscan",
|
||||||
"mypass",
|
"mypass",
|
||||||
"myproxy",
|
"myproxy",
|
||||||
"myusername",
|
"myusername",
|
||||||
"NOFILE",
|
"NOFILE",
|
||||||
"normalisation",
|
"normalisation",
|
||||||
"PCRE",
|
"PCRE",
|
||||||
|
"pipefail",
|
||||||
"preludeanalyzername",
|
"preludeanalyzername",
|
||||||
"preludeenable",
|
"preludeenable",
|
||||||
"recieve",
|
"recieve",
|
||||||
|
|||||||
@@ -1,23 +1,26 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
# Set paths
|
|
||||||
SCAN_DIR="<%= @cv_scan_dir %>"
|
SCAN_DIR="<%= @cv_scan_dir %>"
|
||||||
LOG_FILE="<%= @cv_logfile %>"
|
LOG_FILE="<%= @cv_logfile %>"
|
||||||
TMP_ALERT="<%= @cv_alert_file %>"
|
TMP_ALERT="<%= @cv_alert_file %>"
|
||||||
EMAIL="<%= @cv_alert_email %>"
|
EMAIL="<%= @cv_alert_email %>"
|
||||||
|
|
||||||
# Run clamscan
|
# Ensure the log directory exists
|
||||||
clamscan -r --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null
|
mkdir -p "$(dirname "$LOG_FILE")"
|
||||||
|
|
||||||
# Check if infections were found
|
# Preferred: clamdscan with multiscan + fdpass
|
||||||
if grep -q "Infected files: [^0]" "$LOG_FILE"; then
|
clamdscan --multiscan --fdpass --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null || true
|
||||||
echo "ClamAV has found infected files on $(hostname)!" > "$TMP_ALERT"
|
|
||||||
echo "" >> "$TMP_ALERT"
|
# Check for infections (same logic as before)
|
||||||
grep "FOUND" "$LOG_FILE" >> "$TMP_ALERT"
|
if grep -q "Infected files: [^0]" "$LOG_FILE" 2>/dev/null; then
|
||||||
|
{
|
||||||
|
echo "ClamAV has found infected files on $(hostname)!"
|
||||||
|
echo ""
|
||||||
|
grep "FOUND" "$LOG_FILE" || true
|
||||||
|
} > "$TMP_ALERT"
|
||||||
|
|
||||||
# Send the alert email
|
|
||||||
mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT"
|
mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Clean up
|
rm -f "$TMP_ALERT"
|
||||||
rm -f "$TMP_ALERT"
|
|
||||||
Reference in New Issue
Block a user