OP#785 move to clamdscan command
This commit is contained in:
3
.vscode/settings.json
vendored
3
.vscode/settings.json
vendored
@@ -16,6 +16,7 @@
|
||||
"epel",
|
||||
"excludepaths",
|
||||
"fanotify",
|
||||
"fdpass",
|
||||
"filesize",
|
||||
"freshclam",
|
||||
"getsebool",
|
||||
@@ -31,12 +32,14 @@
|
||||
"logsyslog",
|
||||
"logtime",
|
||||
"logverbose",
|
||||
"multiscan",
|
||||
"mypass",
|
||||
"myproxy",
|
||||
"myusername",
|
||||
"NOFILE",
|
||||
"normalisation",
|
||||
"PCRE",
|
||||
"pipefail",
|
||||
"preludeanalyzername",
|
||||
"preludeenable",
|
||||
"recieve",
|
||||
|
||||
@@ -1,23 +1,26 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
# Set paths
|
||||
SCAN_DIR="<%= @cv_scan_dir %>"
|
||||
LOG_FILE="<%= @cv_logfile %>"
|
||||
TMP_ALERT="<%= @cv_alert_file %>"
|
||||
EMAIL="<%= @cv_alert_email %>"
|
||||
|
||||
# Run clamscan
|
||||
clamscan -r --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null
|
||||
# Ensure the log directory exists
|
||||
mkdir -p "$(dirname "$LOG_FILE")"
|
||||
|
||||
# Check if infections were found
|
||||
if grep -q "Infected files: [^0]" "$LOG_FILE"; then
|
||||
echo "ClamAV has found infected files on $(hostname)!" > "$TMP_ALERT"
|
||||
echo "" >> "$TMP_ALERT"
|
||||
grep "FOUND" "$LOG_FILE" >> "$TMP_ALERT"
|
||||
# Preferred: clamdscan with multiscan + fdpass
|
||||
clamdscan --multiscan --fdpass --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null || true
|
||||
|
||||
# Check for infections (same logic as before)
|
||||
if grep -q "Infected files: [^0]" "$LOG_FILE" 2>/dev/null; then
|
||||
{
|
||||
echo "ClamAV has found infected files on $(hostname)!"
|
||||
echo ""
|
||||
grep "FOUND" "$LOG_FILE" || true
|
||||
} > "$TMP_ALERT"
|
||||
|
||||
# Send the alert email
|
||||
mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT"
|
||||
fi
|
||||
|
||||
# Clean up
|
||||
rm -f "$TMP_ALERT"
|
||||
Reference in New Issue
Block a user